Cyber Security Engineer
Core
Improve application security across the FT's cloud-native technology estate by making secure engineering easier for product, platform, and software engineering teams.
Role type
Application Security Engineer (AppSec)
Builds
Developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories, and engineering workflows.
Domain
Financial media / Cloud-native software engineering
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security risk identification and remediation, Vulnerability triage and prioritization, CI/CD and code security tooling, Threat modelling, Python scripting for automation, Secure coding practices
Preferred skills
AWS security, Infrastructure-as-code security (Terraform/CloudFormation), Container/Kubernetes security, Bug bounty or penetration testing, SIEM platforms (Splunk), AI security (LLM/prompt risks)
Technologies
GitHub, SAST, Software Composition Analysis, Secret scanning, Python, AWS, Terraform, CloudFormation, Kubernetes, Splunk
Responsibilities
Work with engineers to explain and remediate security issues, Triage and track application vulnerabilities from various sources, Participate in threat-modelling activities, Write scripts or small tools to automate security tasks, Improve security playbooks and tooling
Seniority
Mid-level, hands-on IC