
Financial Times · London; Sofia
ABOUT US The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to...
The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and
accuracy, with a mission to deliver quality information and services worldwide. At the FT, curiosity thrives and ambitious
thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism
in a polarised world. In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your
growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you.
With no fixed path, you’ll discover new skills and forge a career that can take you anywhere. Build a newsworthy career at the FT.
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A
supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to
removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.
We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-native technology estate.
This is a hands-on role focused on making secure engineering easier for product, platform and software engineering teams.
Application security experience is essential for this role. You’ll help improve developer-friendly security guardrails across
GitHub-based CI/CD pipelines, application repositories and engineering workflows. This includes working with SAST, software
composition analysis, secret scanning, vulnerability management and secure coding guidance so that security findings are clear,
actionable and owned by the right teams.
You’ll work closely with engineers to support practical threat modelling, triage application vulnerabilities, improve security
playbooks and help teams remediate issues in a pragmatic way. You do not need to be a deep AWS or cloud security specialist, but
some exposure to AWS, cloud security or infrastructure-as-code security would be useful.
We’re looking for someone with practical AppSec experience who wants to grow their impact - someone who enjoys working with
engineers, improving tooling and helping security become part of normal delivery rather than a last-minute checkpoint.
Application security experience: practical experience identifying, explaining and helping remediate application security risks in
modern engineering environments.
Developer-friendly security mindset: you enjoy working with engineers, explaining risks clearly and helping teams adopt secure
practices without unnecessary friction.
Vulnerability management experience: experience triaging and tracking application vulnerabilities from sources such as SAST,
dependency scanning, secret scanning, penetration tests, bug bounty reports or third-party advisories.
CI/CD and code security awareness: familiarity with security tooling in development workflows, such as SAST, software composition
analysis, secret scanning or repository security controls.
Threat modelling awareness: experience participating in, supporting or facilitating lightweight threat-modelling sessions for
applications, services or new features.
Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce manual effort, improve visibility or
make security workflows easier.
Cloud security awareness: Some exposure to AWS, cloud security or infrastructure-as-code security would be useful, but is not
essential.
Growth mindset: willingness to keep developing across application security, cloud security, secure development and modern
engineering practices.
equivalent practical experience.
Our benefits vary by location but we are committed to providing best-in-class perks across all our offices. These include generous
annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the
community. Full details of our benefits are available here.
We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements & regular
review. While flexible working requests will be considered, not all patterns are suitable for all roles. We believe this balanced
approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger
relationships and team cohesion, and supporting peer learning. We reserve discretion on reasonable notice to change this approach
either generally or for specific individuals or teams.
We are a disability confident employer and Valuable 500 signatory.
Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you
to attend an interview. If you would like to discuss your requirements or have any questions, email talent@ft.com and a member of
our team will be happy to help.
Further information
At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their
job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all
information provided is authentic and accurately represents your skills, experience, and qualifications.
Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent
hiring process for all.
ABOUT US The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere. Build a newsworthy career at the FT. OUR COMMITMENT TO DIVERSITY, EQUITY AND INCLUSION We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups. THE ROLE OVERVIEW We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default. You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams. Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks. Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work. WHAT YOU’LL BRING TO THE ROLE Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments. Developer-friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction. Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams. Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths. Threat modelling: confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction. CI/CD and code security: hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning. Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk. Security leadership: ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management. AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential. KEY RESPONSIBILITIES Improve application security guardrails Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams. Improve cloud and IaC security guardrails Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale. Drive vulnerability management Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated. Drive cloud misconfiguration management Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows. Run practical threat modelling Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes. Build automation and tooling Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand. Support secure architecture decisions Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes. Partner with engineering teams Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices. Support incidents and lessons learned Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance. Mentor others Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers. Required Experience, Essential: * Strong practical experience in application security and cloud security, ideally with a balanced focus across both. * Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches. * Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction. * Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way. * Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning. * Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions. * Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility. * Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping. * Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment. * Familiarity with Agile or Scrum ways of working. Desirable * Experience with leveraging AI for AppSec and CloudSec. * AWS Certified Security – Speciality or equivalent practical AWS security experience. * Terraform or CloudFormation expertise. * Incident-management or incident-response experience. * Experience with Splunk or similar logging/SIEM platforms. * Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction. * Experience mentoring or line-managing security engineers. WHAT’S IN IT FOR YOU? Our benefits vary by location but we are committed to providing best-in-class perks across all our offices. These include generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. Full details of our benefits are available here. We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements & regular review. While flexible working requests will be considered, not all patterns are suitable for all roles. We believe this balanced approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger relationships and team cohesion, and supporting peer learning. We reserve discretion on reasonable notice to change this approach either generally or for specific individuals or teams. Accessibility We are a disability confident employer and Valuable 500 signatory. Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements or have any questions, email talent@ft.com and a member of our team will be happy to help. Further information At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications. Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.
About the job Are you a skilled Cyber Security Engineer with a talent for finding gaps in the most secure systems? We’re looking for someone to perform in-depth penetration testing across various technologies, including Windows and Linux environments, Citrix Workspaces, Cloud infrastructures, and APIs. You will use the latest tools and techniques to uncover vulnerabilities and work alongside our development and security teams to address and fix them. If you're ready to tackle complex security challenges, we want to hear from you! The ideal profile The perfect candidate is a highly skilled and detail-oriented Cyber Security Engineer with genuine hands-on experience in penetration testing and vulnerability analysis. You have excellent written and verbal communication skills and are a strong problem-solver. You thrive both working independently and collaborating within a team, always ready to tackle challenges with analytical precision. Qualifications: You have a strong understanding of network protocols, both Windows and Linux operating systems, application architectures and Red Hat In-depth knowledge of common vulnerabilities and exploits (CVEs) Proficiency in using various penetration testing tools such as Metasploit, Nmap, Burp Suite and/or Nessus Additional skills: Experience with cloud security, particularly AWS. Knowledge of scripting languages (e.g., Python, PowerShell). Familiarity with source code review techniques. Understanding of frameworks like ISO 27001, NIST, CIS Security certifications such as OSCP, CEH, PEN TEST+
At a glance: * Location: Cambridge * In‑office expectation: 2 days per week initially then once per week * Employment type: Permanent * Salary: £60,000 - £70,000 * Why this role exists: Security at Redgate is a hands‑on engineering discipline. This role exists to design, build, and operate security controls that protect our people, products, and customers. About Redgate Redgate brings together people who want to do their best work in an environment built on trust, accountability, and collaboration. We build solutions that help data professionals securely manage the data and databases that their organizations depend on - a space that's only becoming more critical as systems scale, data regulations increase, and AI adoption accelerates. AI at Redgate By 2028, Redgate will operate as an expert-plus-agent company — domain experts amplified by AI, delivering customer value at a pace our peers can't match. AI handles the heavy lifting. Our people control the judgement. Everyone at Redgate works with Claude, giving you access to the best AI tools from day one Why join our security team? * Broad, meaningful scope - Working across our cloud & physical infrastructure, alongside our development teams and ISO27001-aligned information security group, you'll be working to bring on new vendors, assess risk, and fix vulnerabilities. * Genuinely modern challenges - From AI governance and shadow IT to supply chain risk and secure-by-design engineering, tackle relevant problems across a fast-moving global software business. * A team that grows you - Work in a hands-on team tackling a diverse set of challenges, developing your career and investing in your future About the role As a Cyber Security Engineer at Redgate, you’ll: * Design, build, and operate security controls across infrastructure and applications * Investigate issues hands‑on, sometimes outside office hours, when things genuinely matter * Work closely with engineers and business teams to enable secure delivery * Work alongside our commercial teams to give our customers the confidence to securely deploy our products What makes you a great fit * Hands‑on security engineering or security operations experience * Strong IAM knowledge at protocol level (OAuth 2.0, SAML, OIDC) - you’ve debugged implementations, not just read about it * Experience with Infrastructure as Code (ideally Terraform) and use of automation * Familiarity with secure SDLC practices, version control, and peer review * Experience conducting vendor security reviews and third‑party risk assessments * Practical vulnerability management experience – you're used to judging the real-world risks, not just looking at baseline CVSS scores * Incident response experience, including investigation, remediation, and root cause analysis Working knowledge of Microsoft Sentinel, Defender, and KQL * A background in sys admin or engineering that gives you intuition for how systems actually fail * A mindset that security exists to enable the business * Comfortable using AI tools as part of your daily work * Strong communication skills with both technical and non‑technical audiences What we offer * Salary range: £60,000 - £70,000 * Hybrid working: home and Cambridge office * Monthly wellbeing allowance and generous paid time off * Genuine investment in learning, development, and career progression * Private health insurance * Link to full benefits page here What happens next? * Your application will be reviewed by a person – we don’t use AI or automated tools to assess applications. Every profile is read by one of our Talent Partners. * You’ll hear back within a few days – whether it’s a next step or a no, we aim to respond promptly so you’re not left wondering. * Our interview process is straightforward and consistent – you’ll find more detail on our typical hiring process below, so you know what’s coming and why. Belonging at Redgate We believe that people do their best work in an environment built on respect, fairness, and trust — and that diverse perspectives lead to better outcomes. Redgate is an equal opportunity employer, and we make hiring decisions based on skill, potential, and alignment with our values. You can read more about how we approach belonging and inclusion at Redgate on our Belonging at Redgate page here.