Senior Cyber Security Engineer

via Greenhouse
Posted 29 Jul 2026
Apply on aboutus.ft.com →

<p></p>
<p style="margin-top: 0pt; margin-bottom: 5pt; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-weight: bold; font-size: 12pt; font-family: arial, helvetica, sans-serif;">About us</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-style: italic; font-size: 12pt; font-family: arial, helvetica, sans-serif;">Build a newsworthy career at the FT.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">&nbsp;&nbsp;</span></p>
<p style="margin-top: 0pt; margin-bottom: 5pt; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-weight: bold; font-size: 12pt; font-family: arial, helvetica, sans-serif;">Our commitment to diversity, equity and inclusion</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style=" font-size: 12pt; font-family: arial, helvetica, sans-serif;">We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt;">&nbsp;</p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"></span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>About the role:</strong></span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.</span></p>
<h4><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>What you’ll bring to the role</strong></span></h4>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Application and cloud security experience:</strong>&nbsp;practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Developer-friendly security mindset:</strong>&nbsp;you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Vulnerability management at scale:</strong>&nbsp;experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Cloud misconfiguration &amp; vulnerability management:</strong>&nbsp;experience identifying and reducing infrastructure-as-code and AWS vulnerabilities &amp; misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Threat modelling:</strong>&nbsp;confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>CI/CD and code security:</strong>&nbsp;hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Automation mindset:</strong>&nbsp;ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Security leadership:</strong>&nbsp;ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>AI security awareness:</strong>&nbsp;experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.</span></p>
<h4><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Key Responsibilities</strong></span></h4>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Improve application security guardrails</strong><strong><br></strong>Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Improve cloud and IaC security guardrails</strong><strong><br></strong>Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Drive vulnerability management</strong><strong><br></strong>Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Drive cloud misconfiguration management</strong><strong><br></strong>Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Run practical threat modelling</strong><strong><br></strong>Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Build automation and tooling</strong><strong><br></strong>Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Support secure architecture decisions</strong><strong><br></strong>Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Partner with engineering teams</strong><strong><br></strong>Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Support incidents and lessons learned</strong><strong><br></strong>Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Mentor others</strong><strong><br></strong>Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.</span></p>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Required Experience,&nbsp;</strong><strong>Essential:&nbsp;</strong></span></p>
<ul>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Strong practical experience in application security and cloud security, ideally with a balanced focus across both.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Familiarity with Agile or Scrum ways of working.</span></li>
</ul>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><strong>Desirable</strong></span></p>
<ul>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience with leveraging AI for AppSec and CloudSec.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">AWS Certified Security – Speciality or equivalent practical AWS security experience.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Terraform or CloudFormation expertise.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Incident-management or incident-response experience.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience with Splunk or similar logging/SIEM platforms.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction.</span></li>
<li style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">Experience mentoring or line-managing security engineers.</span></li>
</ul>
<p><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"></span></p>
<p style="margin-top: 10pt; margin-bottom: 0pt; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-weight: bold; font-size: 12pt; font-family: arial, helvetica, sans-serif;">Accessibility</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: #222222;"><span style=" font-size: 12pt; font-family: arial, helvetica, sans-serif;">We are a disability confident employer and Valuable 500 signatory.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="color: #222222; ">Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements or have any questions, email </span><a href="https://mail.google.com/mail/?view=cm&amp;fs=1&amp;tf=1&amp;to=talent@ft.com"><span>talent@ft.com</span></a><span style="color: #222222; "> and a member of our team will be happy to help.</span></span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: black;"><span style="font-weight: bold; font-size: 12pt; font-family: arial, helvetica, sans-serif;">Further information</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: #222222;"><span style=" font-size: 12pt; font-family: arial, helvetica, sans-serif;">At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: #222222;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: #222222;"><span style=" font-size: 12pt; font-family: arial, helvetica, sans-serif;">Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.</span></p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt; color: #222222;">&nbsp;</p>
<p style="margin: 0in; font-family: Arial; font-size: 11.0pt;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="color: #222222; ">Please beware of fraudulent job postings and offers claiming to be from the Financial Times. All legitimate opportunities will direct you to apply through the official Financial Times careers site, and the FT will never ask for financial information, payments, or referrals to third parties during the hiring process. If you have any concerns about the legitimacy of a job posting or suspect any scam activity, please contact </span><a href="mailto:talent@ft.com"><span>talent@ft.com</span></a><span style="color: #222222; ">.&nbsp;</span></span></p>
<p style="margin-top: 0pt; margin-bottom: 10pt; font-family: Arial; font-size: 11.0pt;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><span style="color: #222222; ">Interested in the FT but don’t see the right role yet? Join our </span><a href="https://aboutus.ft.com/careers/stay-connected"><span>Talent Community</span></a><span style="color: #222222; "> to receive exclusive updates, featured jobs, and insights into working at the FT.</span></span></p>
<p></p>

More roles at Aboutus Ft

Listing found on aboutus.ft.com via Greenhouse. Always apply through the employer’s own posting.

Website developed by CyberMat on the Typomania Core
Part of the Half Baked Ideas network: Half Baked Ideas · Local Journal · CamVino · DyadStats
7,656 visitors · 41,549 page views · last 30 days