Senior Cyber Security Engineer

The Financial Times

Greater London

Hybrid

GBP 62,000 - 88,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical cover
Generous annual leave

Job summary

The Financial Times is seeking a Senior Cyber Security Engineer to mature our application and cloud security across a cloud-native, AWS-hosted estate. The role focuses half on application security and half on cloud security, working closely with product, platform, and engineering teams to make secure delivery easier by default.

Candidates will drive practical security improvements, build automation, and contribute to secure architecture decisions.

Qualifications

  • Strong practical experience in application security and cloud security.
  • Hands-on AWS security experience with misconfiguration remediation.
  • Experience improving vulnerability management across engineering teams.
  • Experience in improving cloud/IaC misconfiguration management at scale.
  • Experience integrating/tuning security tooling in CI/CD workflows.
  • Experience running threat-modelling sessions that influence design decisions.
  • Ability to write Python scripts to automate security workflows.
  • Strong communication and collaboration skills to influence engineers and leaders.

Responsibilities

  • Tune and evolve SAST, SCA, secret scanning to be actionable with low noise.
  • Improve AWS and IaC guardrails by reducing misconfigurations at scale.
  • Drive vulnerability management across findings, prioritisation and remediation.
  • Support secure architecture decisions with input into design reviews and AWS decisions.
  • Embed security into design, delivery and operations with engineering teams.
  • Mentor security engineers and potentially line-manage team members.

Skills

Strong communication
Threat modelling
Automation scripting
Security in CI/CD
Security tooling
Interpersonal influence

Tools

AWS
Python
SAST
Software composition analysis
Terraform
CloudFormation
Splunk
GitHub

Job description

Salary: £62,000 - 88,000 per year

Requirements:
  • Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
  • Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
  • Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.
  • Experience with leveraging AI for AppSec and CloudSec is desirable.
  • AWS Certified Security – Speciality or equivalent practical AWS security experience is desirable.
  • Terraform or CloudFormation expertise is desirable.
  • Incident-management or incident-response experience is desirable.
  • Experience with Splunk or similar logging/SIEM platforms is desirable.
  • Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction is desirable.
  • Experience mentoring or line-managing security engineers is desirable.
Responsibilities:
  • Improve application security guardrails by tuning and evolving SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
  • Improve cloud and IaC security guardrails by helping identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
  • Drive vulnerability management by improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
  • Drive cloud misconfiguration management by helping teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
  • Run practical threat modelling sessions for new products, features, services and architectural changes.
  • Build automation and tooling by creating or improving scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
  • Support secure architecture decisions by providing application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
  • Partner with engineering teams to embed security into design, delivery and operational practices.
  • Support incidents and lessons learned by providing application and cloud security expertise during incidents and feeding lessons learned back into patterns, tooling and guidance.
  • Mentor others by coaching security engineers and engineering teams on practical security approaches, and potentially line-managing one or two security engineers depending on team structure.
Technologies:
  • AI
  • AWS
  • CI/CD
  • Cloud
  • Support
  • Python
  • Security
  • Splunk
  • Terraform
  • GitHub

More:

We are the Financial Times, one of the worlds leading news organisations, globally recognised for our authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. Our culture is warm and collaborative, and we offer opportunities to grow, learn new skills and build a career with no fixed path. This Senior Cyber Security Engineer role focuses on maturing application and cloud security across our cloud-native, AWS-hosted technology estate, with a balanced 50/50 focus across application security and cloud security. We work closely with product, platform and engineering teams to make secure delivery easier by default. We offer best-in-class benefits that vary by location, including generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We currently operate a hybrid model requiring staff to work onsite 50% of the time, subject to role requirements and regular review. We are committed to diversity, equity and inclusion, and we are a disability confident employer and Valuable 500 signatory.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer
Senior Cyber Security Engineer

Aboutus Ft • Greater London

Hybrid
GBP 90,000 - 130,000
Generous annual leave
Medical cover
Parental leave
Cloud Security Engineer - Manchester Science Park
Cloud Security Engineer - Manchester Science Park

Hackajob Ltd • Manchester

Hybrid
GBP 86,000 - 105,000
Hybrid working
Private medical and dental insurance
Pension scheme
+2
Senior Technical Security Consultant
Senior Technical Security Consultant

Accenture • Greater London

Hybrid
GBP 50,000 - 75,000
30 days vacation per year
Private medical insurance
3 extra days of leave for charitable工作
Senior Cloud Security Engineer (AWS)
Senior Cloud Security Engineer (AWS)

FORT • Manchester

Hybrid
GBP 85,000 - 120,000
Security Infrastructure Engineer
Security Infrastructure Engineer

Standard 8 Recruitment Ltd • Guildford

On-site
GBP 55,000 - 60,000
Senior Security Engineer AWS Security
Senior Security Engineer AWS Security

AmazonWebServices • Greater London

On-site
GBP 63,000 - 103,000
Application Security Engineer
Application Security Engineer

Hargreaves Lansdown • West of England

Hybrid
GBP 62,000 - 90,000
Hybrid working (2 days in Bristol)
Discretionary annual bonus
Pension contributions up to 11%
+4
Senior Cyber Security Consultant
Senior Cyber Security Consultant

F5 Consultants • West of England

Hybrid
GBP 38,000 - 78,000
Private medical insurance
Pension
Training and development
+3
Senior Security Engineer
Senior Security Engineer

Eligo Recruitment • Greater London

On-site
GBP 56,000 - 96,000
Cloud Security Engineer
Cloud Security Engineer

Vix Technology • Manchester

On-site
GBP 65,000 - 85,000
Learning and development opportunities
Private healthcare
Cycle to work schemes