368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$20k – $45k per year (Estimated)
Location
In office (Manila)
Seniority
Senior
Overview
Company
Impact
Profile match
The Financial Times is a leading international news organization renowned for its authoritative reporting on global business, finance, economics, and geopolitical affairs. Best known for its signature salmon-pink newsprint and digital platform, the outlet provides in-depth analysis, market data, and investigative journalism to a executive and financial audience worldwide. Operating under Nikkei Inc., it serves over one million paying subscribers with reliable intelligence and editorial insights that shape global market conversations.

About us

The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide.

At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world.

In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing.

Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere.

Build a newsworthy career at the FT.

  

Our commitment to diversity, equity and inclusion

We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.

About the role:

We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default.

You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.

Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks.

Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.

What you’ll bring to the role

Application and cloud security experience:  practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.

Developer-friendly security mindset:  you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.

Vulnerability management at scale:  experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.

Cloud misconfiguration & vulnerability management:  experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.

Threat modelling:  confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.

CI/CD and code security:  hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.

Automation mindset:  ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.

Security leadership:  ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management.

AI security awareness:  experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.

Key Responsibilities

Improve application security guardrails

Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.

Improve cloud and IaC security guardrails

Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.

Drive vulnerability management

Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.

Drive cloud misconfiguration management

Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.

Run practical threat modelling

Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes.

Build automation and tooling

Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.

Support secure architecture decisions

Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.

Partner with engineering teams

Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.

Support incidents and lessons learned

Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance.

Mentor others

Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.

Required Experience, Essential: 

  • Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
  • Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
  • Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.

Desirable

  • Experience with leveraging AI for AppSec and CloudSec.
  • AWS Certified Security - Speciality or equivalent practical AWS security experience.
  • Terraform or CloudFormation expertise.
  • Incident-management or incident-response experience.
  • Experience with Splunk or similar logging/SIEM platforms.
  • Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction.
  • Experience mentoring or line-managing security engineers.

Accessibility

We are a disability confident employer and Valuable 500 signatory.

Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements or have any questions, email [email protected] and a member of our team will be happy to help.

Further information

At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications.

Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.

Please beware of fraudulent job postings and offers claiming to be from the Financial Times. All legitimate opportunities will direct you to apply through the official Financial Times careers site, and the FT will never ask for financial information, payments, or referrals to third parties during the hiring process. If you have any concerns about the legitimacy of a job posting or suspect any scam activity, please contact [email protected]

Interested in the FT but don’t see the right role yet? Join our Talent Community to receive exclusive updates, featured jobs, and insights into working at the FT.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Manila
$230k – $260k per year • Equity • Remote • Internship • Bachelor's Degree
Python
DevOps
Amazon EKS
AWS
Azure
CI/CD
GCP
Helm
Kubernetes
Terraform
Cybersecurity
FedRAMP
Orca Security
Apply
$22k – $52k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
DevOps
AWS
Azure
GCP
Analytics
Power BI
Tableau
ETL/ELT
Apply
Team Lead DevOps 1 day ago
$23k – $62k per year (Estimated) • Remote • 5+ years exp • Moscow
Bash
Python
Erlang
Erlang
EMQX
Databases
Apache Kafka
ClickHouse
PostgreSQL
RabbitMQ
Redis
Redpanda
Trino
DevOps
Ansible
AWS
AWX
FinOps
HAProxy
Hetzner
Kubernetes
SLI/SLO/SLA
Terraform
Yandex Cloud
Amazon S3
Apply
$123k – $251k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Dallas • Denver • Birmingham
Java
SQL
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
MySQL
Redis
DevOps
CI/CD
Dynatrace
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Apply
$120k – $250k per year • Equity 0.2–1% • In office • Full-Time • Master's Degree • Seattle
Python
AI/ML
Diffusion Models
Fine-tuning
PyTorch
Self-Supervised Learning
Apply
$85k – $176k per year (Estimated) • Remote/Hybrid • London
AI/ML
ChatGPT
Gemini
Design
Figma
Management
Confluence
Google Workspace
Jira
Monday.com
Slack
Zapier
Apply
$81k – $176k per year (Estimated) • Remote/Hybrid • Contractor • London
Design
Figma
Apply
$79k – $180k per year (Estimated) • Remote/Hybrid • London
Python
DevOps
AWS
CI/CD
CloudFormation
Splunk
Terraform
GitHub
Apply
$77k – $157k per year (Estimated) • Remote/Hybrid • London
Python
AI/ML
LLM
LLM Guardrails
DevOps
AWS
CI/CD
CloudFormation
Kubernetes
Splunk
Terraform
GitHub
Apply
Head of Projects 19 days ago
Remote/Hybrid • Sofia
Apply
$17k – $42k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Manila
Management
ServiceNow
Marketing
HubSpot
Salesforce
Zendesk
Apply
$17k – $42k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Manila
SQL
Apply
Remote • 2+ years exp • Manila
DevOps
Amazon EC2
AWS
AWS Lambda
CloudFormation
Terraform
Apply
$15k – $41k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Node JS
Python
TypeScript
JavaScript
Databases
Google BigQuery
AI/ML
Gemini
Model Context Protocol
Prompt Engineering
A2A
AI Agents
DevOps
CI/CD
GCP
Git
Apply
$28k – $59k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Manila
Analytics
Power BI
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.