Qualifications
Responsibilities
Benefits
Job Description
As a Security Associate Architect, you will join Thomson Reuters' Security Architecture team to embed security across our products, platforms, and enterprise systems. You will work with business and technical teams to make secure-by-design architectures and secure-by-default configurations practical, consistent, and scalable.
In this role, you will provide technical leadership across the organization or within a business unit, partnering with information security and risk management, platform engineering, service management, commercial engineering and product engineering teams.
Through these activities, you will become a trusted technical advisor, build relationships across teams, mentor engineers, and improve our architecture review methods and knowledge base. You will expand your expertise across our diverse technology landscape while helping teams adopt secure solutions that protect our customers.
Key Responsibilities
Clarify technology risks by assessing evolving threats and technologies, and translate industry best practices, security frameworks, and applicable regulatory requirements into actionable guidance.
Establish repeatable assessment frameworks and security requirements that help teams identify risks, select controls, and demonstrate measurable outcomes through consistent governance.
Work with domain architects and engineering teams to define reference architectures and secure design patterns, guide reference implementations, and support adoption across shared services and cloud landing zones to drive standardization and organizational alignment.
Assess risks, recommend controls, and document architectural decisions and trade-offs when teams need to deviate from a standard.
Lead architecture reviews and threat modelling for new systems, integrations, migrations, and emerging technologies.
Review multi-cloud platforms, modern application stacks, and AI and agentic systems.
Track findings and help translate them into practical recommendations, align stakeholders on security trade-offs, and support through implementation.
Ensure reference architectures, implementations and guardrails are continuously updated as new valid use cases are identified and reviewed.
Build relationships across teams, mentor engineers, and improve architecture review methods and knowledge base.
Required Qualifications
Bachelor's degree in computer science, or equivalent practical experience.
10+ years of hands-on experience in security architecture, software engineering, application security, or cloud security.
Exceptional written and verbal communication skills, with the ability to explain complex security concepts and build alignment across technical and business stakeholders.
Passionate about security, with the curiosity to explore unfamiliar technologies and translate ideas into practical solutions.
Strong analytical skills and sound judgment when balancing security risks, engineering constraints, and business needs.
Passionate about sharing knowledge across teams, the broader security community and to mentoring others.
Strong understanding of cryptography concepts and key management, authentication and authorization, identity federation, network and operating system security, data protection, and detection and response at the system level, network layer or application layer.
Hands-on experience and deep understanding of at least one major cloud provider (AWS, Azure, or GCP), including identity and access management, networking, and shared platform services.
Experience leading security architecture reviews, threat modelling, and risk assessments across multiple products or platforms, and translating findings into prioritized engineering actions.
Ability to develop security requirements, reusable design patterns, and reference architectures, and guide their adoption.
Experience translating security frameworks, standards, and applicable regulatory requirements into controls, assessment methods, and practical engineering guidance.
Experience designing and implementing secure applications, APIs, and container platforms, with knowledge of Kubernetes and secure CI/CD practices.
Ability to read and discuss infrastructure configurations, validate design assumptions, and guide secure implementation.
Working knowledge of AI and agentic system security, including prompt injection, model and data integrity, and controls for agent and tool use.
Preferred Qualifications
Relevant industry certifications such as CISSP, CCSP, CISM, GIAC, AWS Certified Security 6 Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
Experience designing and securing enterprise-scale multi-cloud environments across AWS, Azure, and/or GCP.
Experience with security architecture for AI, generative AI, large language models, or agentic systems, including model governance, data protection, and secure tool integration.
Experience developing and scaling security architecture standards, cloud guardrails, reusable design patterns, and reference implementations across enterprise engineering teams.
#LI-LP2
This posting is for proactive recruitment purposes and may be used to fill current openings or future vacancies within our organization.
What’s in it For You?
Our use of AI within the recruitment process Thomson Reuters utilizes Artificial Intelligence (AI) to support parts of our global recruitment process. Unless you opt-out, our AI system will assess the information provided by you and compare it to the requirements listed for the role, and present the result to our recruitment personnel for further review. The AI system acts as a supporting tool, but there is always a human making the decision if you will be considered for the role
About Thomson Reuters
Similar Jobs




More Jobs at Thomson Reuters




More Information Technology Jobs