Qualifications
Responsibilities
Benefits
The Opportunity
Service Management & Transformation
Do you like securing systems at scale, and improving the way the work gets done so it scales further? Thomson Reuters™ is investing in a dedicated security engineering capability, and we are looking for a senior engineer to help drive it. This role sits on our Service Management & Transformation team.
As a Senior Security Engineer, you will secure and harden our application, cloud, and infrastructure estate, which spans on-premises datacentersand major clouds, and improve andoptimizehow that work gets done. You will implement security controls across patching, hardening, network isolation, identity, and secrets management, rework patchingcyclesand golden-image refreshes so the team moves fast, scale AI-augmented tooling, and package repeatable execution so more junior engineers can pick it up.
About the Role
In this opportunity as Senior Security Engineer, you will:
Secure and harden the estate hands-on across the full stack: application and open-source dependency fixes, infrastructure patching, cloudconfigurationand guardrails, WAF, network isolation, and secrets and machine-identity management.
Improve andoptimizehow security gets done, reworking patching cycles and golden-image refreshes, cutting cycle time, and removing friction so the team moves faster.
Implement and tune security controls across operating systems, containers, CI/CD pipelines, cloud configuration, and network boundaries to defend against sophisticated adversaries and insider threats.
Scale adoption of AI-augmented SAST and SCA tooling, expanding coverage, reviewing generated pull requests, andvalidatingfixes, prioritizing by risk in line with CISA guidance and measuring mean time to remediate, throughput, and burndown against SLA.
Package reusable patterns, tooling, and runbooks so routine work can be executed by more junior engineers, and mentor them with technical review of their fixes.
Partner with application and platform teams to land andvalidatechanges safely, and coordinate with the wider team across regions to keep progress continuous across time zones.
Feedaccuratesecurity metrics and status into program reporting.
About You
You'rea fit for the role of Senior Security Engineer if your background includes:
5+ years of security, software, orDevSecOpsengineering experience, comfortable securing and hardening across application, infrastructure, and cloud, plus abachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
Multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage), alongside on-premises infrastructure.
A solid understanding of security principles and common vulnerabilities, with hands-on work across patching, hardening, cloud configuration, network isolation, and identity and access controls.
Hands-on experience with SAST/SCA tooling and remediating application and open-source dependency vulnerabilities, plus infrastructure patching.
A track recordof improving andoptimizingengineering processes, reducing cycle time in patching, releases, or security work, rather than only executing it.
Familiarity with vulnerability prioritization (CVSS/EPSS, CISA KEV) and SLA-driven burndown, plus comfort with AI-assisted tooling and reviewing its output critically.
Clear communication, some experience mentoring engineers, and strong ownership of security outcomes.
#LI-LB1
Whats in it For You?
About Thomson Reuters
Similar Jobs
More Jobs at Thomson Reuters




More Information Technology Jobs