Developer-First Cyber Security Engineer for Secure Apps

Company: The Financial Times
Apply for the Developer-First Cyber Security Engineer for Secure Apps
Location: London
Job Description:

Requirements

  • You do not need to be a deep AWS or cloud security specialist, but some exposure to AWS, cloud security or infrastructure-as-code security would be useful
  • ,

  • We’re looking for someone with practical AppSec experience who wants to grow their impact – someone who enjoys working with engineers, improving tooling and helping security become part of normal delivery rather than a last-minute checkpoint
  • ,

  • Application security experience: practical experience identifying, explaining and helping remediate application security risks in modern engineering environments
  • ,

  • Developer-friendly security mindset: you enjoy working with engineers, explaining risks clearly and helping teams adopt secure practices without unnecessary friction
  • ,

  • Vulnerability management experience: experience triaging and tracking application vulnerabilities from sources such as SAST, dependency scanning, secret scanning, penetration tests, bug bounty reports or third-party advisories
  • ,

  • CI/CD and code security awareness: familiarity with security tooling in development workflows, such as SAST, software composition analysis, secret scanning or repository security controls
  • ,

  • Threat modelling awareness: experience participating in, supporting or facilitating lightweight threat-modelling sessions for applications, services or new features
  • ,

  • Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce manual effort, improve visibility or make security workflows easier
  • ,

  • Cloud security awareness: Some exposure to AWS, cloud security or infrastructure-as-code security would be useful, but is not essential
  • ,

  • Growth mindset: willingness to keep developing across application security, cloud security, secure development and modern engineering practices
  • ,

  • Practical experience in application security
  • ,

  • Experience working with software engineers to explain and remediate security issues
  • ,

  • Familiarity with common web application security risks and secure coding practices
  • ,

  • Experience with vulnerability triage, prioritisation and remediation tracking
  • ,

  • Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning or similar
  • ,

  • Experience participating in or supporting threat-modelling activities
  • ,

  • Ability to write scripts or small tools, ideally in Python, to automate tasks or improve visibility
  • ,

  • Strong communication and collaboration skills
  • ,

  • Familiarity with Agile or Scrum ways of working
  • ,

  • (Desirable) Exposure to AWS security, cloud security or infrastructure-as-code security
  • ,

  • (Desirable) Experience with Terraform or CloudFormation
  • ,

  • (Desirable) Experience with container or Kubernetes security
  • ,

  • (Desirable) Experience with bug bounty, penetration testing or security testing programmes
  • ,

  • (Desirable) Experience with Splunk or similar logging/SIEM platforms
  • ,

  • (Desirable) Exposure to AI security, such as LLM-enabled applications, AI-assisted development workflows or prompt/data leakage risks
  • ,

  • (Desirable) Experience building dashboards, metrics or reports to support vulnerability management
  • ,

  • (Desirable) Relevant security certifications or training, such as AWS security training, secure coding training, GIAC, ISC2, CREST or equivalent practical experience

What the job involves

  • We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-native technology estate. This is a hands-on role focused on making secure engineering easier for product, platform and software engineering teams
  • ,

  • Application security experience is essential for this role. You’ll help improve developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories and engineering workflows
  • ,

  • This includes working with SAST, software composition analysis, secret scanning, vulnerability management and secure coding guidance so that security findings are clear, actionable and owned by the right teams
  • ,

  • You’ll work closely with engineers to support practical threat modelling, triage application vulnerabilities, improve security playbooks and help teams remediate issues in a pragmatic way

#J-18808-Ljbffr…

Posted: May 28th, 2026