Senior Cyber Security Engineer
Job description
About the role
The Senior Cyber Security Engineer will own the design, implementation, and continuous improvement of security controls across the Financial Times cloud-native technology estate. This role balances application security and cloud security to enable secure and efficient delivery of services. You will translate complex security risks into clear, actionable guidance for product and engineering teams. Success in this position will be measured by reduced friction for developers, measurable improvements in security posture, and increased automation of security tasks. You will be a hands-on technical leader who drives tangible security outcomes through collaboration and pragmatic engineering solutions.
What you'll do
Refine and tune SAST, software composition analysis, secret scanning, and IaC scanning workflows to ensure findings are actionable, accurate, and integrated smoothly into CI/CD pipelines. Design, implement, and operate pragmatic guardrails across GitHub-based CI/CD pipelines, AWS environments, and infrastructure-as-code workflows to prevent misconfigurations before deployment. Lead practical threat-modelling sessions for new products, features, and architectural changes to identify risks early and guide secure design decisions. Review application and cloud designs, offering security guidance that balances risk management with delivery speed and developer experience. Own and evolve vulnerability management processes, including prioritization, assignment, tracking, and remediation of application vulnerabilities, dependency risks, bug bounty findings, penetration test findings, and third-party advisories. Drive improvements in AWS misconfiguration detection and remediation by building scalable detection, alerting, and governance mechanisms. Create and maintain automation, scripts, dashboards, and tooling that reduce manual security toil and provide clear visibility into security and compliance posture. Provide application and cloud security expertise during incident response, ensuring that findings feed back into controls, playbooks, and architectural improvements. Mentor security engineers and collaborate with engineering leadership to elevate security practices across multiple teams. Partner closely with product, platform, and software engineering teams to embed security into delivery practices without introducing unnecessary friction.
Requirements
Demonstrated, hands-on experience in both application security and cloud security within cloud-native and AWS-hosted environments. Practical experience securing CI/CD pipelines and implementing security controls within GitHub workflows and infrastructure-as-code pipelines. Strong background in identifying, prioritizing, and remediating application vulnerabilities, dependency risks, bug bounty findings, and penetration test findings at scale. Proven ability to improve cloud infrastructure security by reducing misconfigurations through guardrails, tooling, and clear remediation workflows. Hands-on familiarity with SAST, software composition analysis, secret scanning, IaC scanning, and related security tooling. Experience running lightweight, effective threat-modelling sessions that influence engineering decisions and reduce risk. Ability to write scripts, preferably in Python, to automate security tasks, improve visibility, and simplify complex risk data. Track record of collaborating with engineering teams to drive secure delivery and measurable security outcomes. Capacity to mentor peers and line-manage security engineers where team structure requires, while continuing to contribute technically.
Nice to have
Only items explicitly indicated as preferred in the source material are included; no additional preferences are added.
Key facts
Your future at the FT
At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you're given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you'll connect with a diverse community of experts who support your growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you'll discover new skills and forge a career that can take you anywhere.
About us
The Financial Times is one of world's leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide.
Our commitment to diversity, equity and inclusion
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.