About the Role
We are looking for a Cyber Security Engineer to enhance application security across the FT’s cloud-native technology estate. This hands-on role focuses on simplifying secure engineering for product, platform, and software engineering teams by improving developer-friendly security guardrails within CI/CD pipelines, repositories, and workflows.
Responsibilities
- Improve developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories, and engineering workflows.
- Work with SAST, software composition analysis, secret scanning, vulnerability management, and secure coding guidance.
- Ensure security findings are clear, actionable, and owned by the appropriate teams.
- Support practical threat modelling with engineers.
- Triage application vulnerabilities.
- Improve security playbooks.
- Assist teams in pragmatically remediating security issues.
Requirements
- Practical application security experience.
- Experience identifying, explaining, and helping remediate application security risks in modern engineering environments.
- A developer-friendly security mindset, enjoying collaboration with engineers and clear risk communication.
- Experience triaging and tracking application vulnerabilities from various sources.
- Familiarity with security tooling in development workflows (SAST, software composition analysis, secret scanning, repository security controls).
- Experience participating in, supporting, or facilitating lightweight threat-modelling sessions.
- Ability to write scripts or small tools, ideally in Python, for automation or visibility improvement.
- Willingness to continuously develop skills in application security, cloud security, secure development, and modern engineering practices.
- Experience working with software engineers to explain and remediate security issues.
- Familiarity with common web application security risks and secure coding practices.
- Experience with vulnerability triage, prioritization, and remediation tracking.
- Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning, or similar.
- Experience participating in or supporting threat-modelling activities.
- Strong communication and collaboration skills.
- Familiarity with Agile or Scrum ways of working.
Skills
- Application Security
- SAST
- Software Composition Analysis
- Secret Scanning
- Vulnerability Management
- Secure Coding
- Threat Modelling
- CI/CD Security
- Python Scripting
- Automation
- AWS Security (exposure)
- Cloud Security (exposure)
- Infrastructure-as-Code Security (exposure)
- Terraform (desirable)
- CloudFormation (desirable)
- Container Security (desirable)
- Kubernetes Security (desirable)
- Bug Bounty Programs (desirable)
- Penetration Testing (desirable)
- Security Testing (desirable)
- Splunk (desirable)
- SIEM Platforms (desirable)
- AI Security (desirable)
- LLM Security (desirable)
- Prompt Engineering Security (desirable)
- Data Leakage Security (desirable)
- Dashboarding
- Metrics Reporting
- Security Certifications (desirable)
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- Mid-level
Benefits
- Generous annual leave
- Medical cover
- Inclusive parental leave packages
- Subsidised gym memberships
- Opportunities to give back to the community
About the Company
- The Financial Times is a leading global news organisation known for its authority, integrity, and accuracy.
- The company's mission is to deliver quality information and services worldwide.
- FT fosters a culture of curiosity and rewards ambitious thinking.
- The company offers opportunities to reach millions, create impactful work, and deliver impartial journalism.
- FT provides a warm, collaborative culture with a diverse community of experts supporting growth and wellbeing.
- The company embraces innovation and the use of technology, including AI tools in the application process.
Equal Opportunity
- We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued.
- A supportive workplace is one where employees feel they can be themselves and operate to their full potential.
- We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.
- We are a disability confident employer and Valuable 500 signatory.
- Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview.
