About the Role
We are seeking a Senior Cyber Security Engineer to enhance application and cloud security within the FT’s cloud-native, AWS-hosted technology environment. This role involves a balanced focus on application and cloud security, collaborating with product, platform, and engineering teams to simplify secure delivery.
Responsibilities
- Improve application security guardrails
- Tune and evolve SAST, software composition analysis, secret scanning and related controls
- Improve cloud and IaC security guardrails
- Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale
- Drive vulnerability management
- Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated
- Drive cloud misconfiguration management
- Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows
- Run practical threat modelling
- Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes
- Build automation and tooling
- Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand
- Support secure architecture decisions
- Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes
- Partner with engineering teams
- Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices
- Support incidents and lessons learned
- Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance
- Mentor others
- Coach security engineers and engineering teams on practical security approaches
- Depending on team structure, this may include line management of one or two security engineers
Requirements
- Strong practical experience in application security and cloud security, ideally with a balanced focus across both
- Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches
- Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction
- Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way
- Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning
- Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions
- Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility
- Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping
- Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment
- Familiarity with Agile or Scrum ways of working
- Experience with leveraging AI for AppSec and CloudSec (Desirable)
- AWS Certified Security – Speciality or equivalent practical AWS security experience (Desirable)
- Terraform or CloudFormation expertise (Desirable)
- Incident-management or incident-response experience (Desirable)
- Experience with Splunk or similar logging/SIEM platforms (Desirable)
- Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction (Desirable)
- Experience mentoring or line-managing security engineers (Desirable)
Skills
- Application Security
- Cloud Security
- AWS
- SAST
- Software Composition Analysis
- Secret Scanning
- IaC Scanning
- Vulnerability Management
- Cloud Misconfiguration Management
- Threat Modelling
- CI/CD
- Python
- Agile
- Scrum
- AI Security
- Terraform
- CloudFormation
- Incident Management
- Incident Response
- Splunk
- SIEM
- Security Metrics
- Dashboards
- Reporting
Location
- Remote
- Hybrid
Work Type
- Hybrid
Experience Level
- Senior
- Line Management (potential)
Education Level
- AWS Certified Security – Speciality (Desirable)
Benefits
- Generous annual leave
- Medical cover
- Inclusive parental leave packages
- Subsidised gym memberships
- Opportunities to give back to the community
About the Company
- The Financial Times is a leading global news organisation known for its authority, integrity, and accuracy.
- The FT's mission is to deliver quality information and services worldwide.
- The company fosters a culture of curiosity and rewards ambitious thinking.
- Employees have the opportunity to reach millions, create impactful work, and deliver impartial journalism.
- The FT offers a warm, collaborative culture with a diverse community of experts supporting growth and career aspirations.
- The company provides opportunities that challenge and inspire, allowing for career exploration and skill development.
Equal Opportunity
- We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued.
- A supportive workplace is one where employees feel they can be themselves and operate to their full potential.
- We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.
- We are a disability confident employer and Valuable 500 signatory.
- Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview.
