Senior Cyber Security Engineer at Financial Times

Sofia, Sofia City Province, Bulgaria

Financial Times Logo
Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Media, TechnologyIndustries

Requirements

  • Security advocate: enjoy pairing with developers, explaining risks in plain language, and nudging teams toward secure-by-default habits
  • Programme builder: experience maturing an AppSec programme, including writing playbooks, tracking metrics, and iterating on policy
  • Threat-modelling & testing skills: comfortable running STRIDE sessions and interpreting pentest results to drive fixes
  • Pipeline security know-how: hands-on knowledge of security tooling in CI/CD (SAST, SCA, secret scanning, DAST)
  • Cloud & IaC awareness: solid grasp of AWS security fundamentals and ability to spot common misconfigurations in Terraform/CloudFormation
  • Scripting for automation: ability to write practical Python utilities to reduce toil and surface real risk
  • Strong communication and collaboration skills (Essential)
  • Proficiency in a scripting language, such as Python (Essential)
  • Hands-on AWS security experience and IaC best practices (Essential)
  • Experience integrating security tooling into CI/CD workflows (Essential)
  • Demonstrated delivery of threat-modelling sessions and application pentests (Essential)
  • Familiarity with Agile/Scrum ways of working (Essential)
  • AWS Certified Security – Specialty (Desirable)
  • Terraform expertise (Desirable)
  • Incident-management experience (Desirable)
  • Knowledge of container/Kubernetes security (Desirable)
  • Experience with Splunk (Desirable)

Responsibilities

  • Build & maintain security tooling: write robust, well-tested solutions that developers and the wider business can use
  • Embed controls in CI/CD: keep SAST/SCA and secrets-scanning checks green and tuned for low noise
  • Evangelise & educate: run threat-model workshops, brown-bag sessions, and maintain up-to-date guidance docs
  • Track & triage vulnerabilities: own the backlog from security tooling findings, bug-bounty reports, and third-party advisories through to closure
  • Harden cloud & IaC: review AWS designs, set guardrails, and champion secure Terraform/CloudFormation patterns
  • Incident support: provide application-layer expertise during security incidents and feed lessons learned back into tooling
  • Security mentorship and leadership: coach 1–2 security engineers if needed, and mentor engineers across the wider org on secure practices, threat modeling, and security-first thinking
  • Collaborate on architecture: contribute security input to design reviews and larger technical decisions across the FT

Skills

Key technologies and capabilities for this role

AWSGitHubSASTSCASecret ScanningDASTIaCSTRIDEThreat ModelingPentestingCI/CD

Questions & Answers

Common questions about this position

What is the salary for this Senior Cyber Security Engineer role?

This information is not specified in the job description.

Is this position remote or does it require office work?

This information is not specified in the job description.

What key skills are required for this role?

Required skills include being a security advocate who pairs with developers, experience maturing an AppSec programme, threat-modelling with STRIDE and pentest interpretation, CI/CD security tooling like SAST/SCA/secret scanning/DAST, AWS security fundamentals and IaC familiarity, plus Python scripting for automation.

What is the company culture like at Financial Times?

The Product & Tech team is 500-people strong, diverse, dedicated, dynamic, friendly, and forward-thinking, with entrepreneurial spirit, intelligence, and opportunity at every turn.

What makes a strong candidate for this position?

A strong candidate is a senior-level engineer with hands-on experience maturing AppSec programmes, expertise in CI/CD security tools, AWS and IaC security, threat modeling, and Python scripting, plus the ability to mentor junior engineers.

Financial Times

Global provider of financial news and analysis

About Financial Times

The Financial Times provides authoritative news and analysis focused on the financial sector, catering to both individuals and businesses. Its primary offerings include a range of subscription plans for print and digital content, ensuring access to high-quality journalism. The company employs over 2,900 staff, including 700 journalists across 40 countries, which allows for extensive global coverage. In addition to standard news reporting, the Financial Times offers specialized services like the FT Climate Capital Hub for discussions on climate change and the ETF Hub for detailed information on Exchange-Traded Funds. This combination of diverse content and services, along with revenue from subscriptions and advertising, sets the Financial Times apart from competitors. The goal of the Financial Times is to provide reliable information and analysis that empowers its readers to make informed decisions in the financial landscape.

London, United KingdomHeadquarters
1888Year Founded
ACQUISITIONCompany Stage
Social Impact, Financial ServicesIndustries
1,001-5,000Employees

Benefits

Health Insurance
Paid Vacation
Parental Leave
Hybrid Work Options
Flexible Work Hours

Risks

Venture arm may divert focus from core news reporting.
Adani Group's accusations could harm FT's reputation and credibility.
Subscription app may struggle with user adoption and competition.

Differentiation

FT's Climate Capital Hub focuses on climate change, a critical global issue.
The ETF Hub collaboration provides specialized financial data for investors.
FT employs 700 journalists in 40 countries, ensuring comprehensive global coverage.

Upsides

FT's venture arm can diversify revenue and foster innovation.
The subscription app targets international readers, expanding global reach.
Demand for data journalism boosts FT's investigative reporting capabilities.

Land your dream remote job 3x faster with AI