Cyber Security Engineer
Job description
About the role
The Financial Times seeks a Cyber Security Engineer who owns the design and execution of application security initiatives across the FT's global technology landscape. This role is responsible for embedding security directly into the developer lifecycle, ensuring that secure practices are intuitive and integrated rather than obstructive. You will own the implementation of security controls that enable speed without sacrificing protection, translating complex risks into clear guidance for engineering teams. The position requires hands-on collaboration with product and platform engineers to build security capabilities that are both robust and practical. You will drive measurable improvements in the security posture of applications by owning the full lifecycle of vulnerability management and secure delivery. This role is critical in establishing a culture where security is an enabler of delivery, not a final checkpoint. You will be a key partner in modern engineering workflows, ensuring that security tooling and guidance are adopted effectively across the FT.
Key facts
What you'll do
Implement and evolve security controls across GitHub-based CI/CD pipelines to ensure secure software delivery practices are automated and consistent.
Champion application security by developing and maintaining guardrails that make secure coding the default and easiest choice for engineering teams.
Triage and prioritize vulnerabilities from SAST, software composition analysis, secret scanning, penetration tests, and third-party advisories to drive timely remediation.
Facilitate and support lightweight threat modeling sessions for applications, services, and new features to identify risks early in the development lifecycle.
Improve security visibility by creating and maintaining dashboards, metrics, and reports that track vulnerability management and security posture.
Automate repetitive security tasks and workflows by writing scripts and small tools, primarily in Python, to increase efficiency and reduce manual overhead.
Collaborate closely with engineers to explain security findings, provide clear remediation guidance, and ensure issues are owned and resolved appropriately.
Contribute to the development and maintenance of security playbooks and secure coding guidance that evolve with emerging threats and technologies.
Assess and provide guidance on cloud security risks, with a focus on AWS, infrastructure-as-code security, and container or Kubernetes security where applicable.
Partner with the broader security community to align application security practices with organizational standards and emerging best practices.
Requirements
You possess practical experience in application security and have a proven track record of identifying, explaining, and helping remediate application security risks in modern engineering environments.
You have demonstrated experience working directly with software engineers to explain security issues and support the remediation of vulnerabilities in production and pre-production systems.
You are familiar with common web application security risks and established secure coding practices, allowing you to advise teams on how to avoid introducing vulnerabilities.
You have hands-on experience with vulnerability triage, prioritization, and remediation tracking, ensuring that findings are addressed based on risk and impact.
You have used or interpreted findings from security tools such as SAST, software composition analysis, secret scanning, or similar technologies to drive remediation efforts.
You have participated in or supported threat-modelling activities, understanding how to facilitate sessions that help teams design security into their applications.
You have the ability to write scripts or small tools, ideally in Python, to automate manual tasks, improve visibility into security processes, or enhance security workflows.
You communicate effectively and collaborate well with cross-functional teams, ensuring that security guidance is understood and actionable for engineers.
You are experienced with Agile or Scrum ways of working, thriving in an environment where security practices must integrate smoothly with iterative delivery cycles.
Nice to have
Exposure to AWS security, cloud security, or infrastructure-as-code security that provides context for securing modern distributed systems.
Experience with Terraform or CloudFormation to understand how infrastructure definitions can be secured and validated.
Experience with container or Kubernetes security to support the secure deployment and operation of containerized applications.
Experience with bug bounty, penetration testing, or security testing programmes that provide real-world insight into attacker techniques.
Experience with Splunk or similar logging and SIEM platforms to understand how application telemetry supports security monitoring.
Exposure to AI security, including LLM-enabled applications, AI-assisted development workflows, or prompt and data leakage risks in modern systems.
Experience building dashboards, metrics, or reports that provide actionable insight into vulnerability management and security trends.
Relevant security certifications or training such as AWS security training, secure coding training, GIAC, ISC2, CREST, or equivalent practical experience that enhances your ability to perform the role.
Practical notes
Hybrid model requiring 50% onsite presence in the office, subject to role requirements and regular review.
Flexible working requests will be considered, though not all patterns are suitable for every role.
The organization reserves discretion on reasonable notice to change working patterns either generally or for specific individuals or teams.
About benefits
The Financial Times offers generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships, and opportunities to give back to the community. Full details of these benefits are available at the FT careers benefits page. The role operates within a hybrid framework designed to support collaboration, protect culture, and enable peer learning while maintaining flexibility.