Thomson Reuters

Senior Security Engineer

Thomson Reuters$94K — $176K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of security, software, or DevSecOps engineering experience
  • Bachelor's degree in Computer Science, Information Security, or related field
  • Multi-cloud experience with AWS, Azure, GCP, and OCI
  • Strong understanding of security principles and vulnerabilities
  • Hands-on experience with SAST/SCA tooling and application remediation
  • Track record of optimizing engineering processes and reducing cycle times
  • Comfort with AI-assisted tooling and vulnerability prioritization

Responsibilities

  • Secure and harden applications and infrastructure across stacks
  • Optimize security processes to reduce cycle time and friction
  • Implement and tune security controls for operating systems and cloud configurations
  • Scale AI-augmented tooling for enhanced vulnerability management
  • Package reusable patterns and tools for junior engineers
  • Mentor junior engineers through technical reviews
  • Collaborate with application teams to ensure safe changes across platforms

Benefits

  • Hybrid work model with flexible arrangements
  • Work-life balance support through Flex My Way policies
  • Career development programs focused on skill enhancement
  • Comprehensive employee benefits including mental health support
  • Culture prioritizing inclusion, belonging, and teamwork
  • Opportunities for community involvement and social impact initiatives
  • Real-world impact by supporting justice and transparency initiatives
Full Job Description

The Opportunity

Service Management & Transformation

Do you like securing systems at scale, and improving the way the work gets done so it scales further? Thomson Reuters™ is investing in a dedicated security engineering capability, and we are looking for a senior engineer to help drive it. This role sits on our Service Management & Transformation team.

As a Senior Security Engineer, you will secure and harden our application, cloud, and infrastructure estate, which spans on-premises datacentersand major clouds, and improve andoptimizehow that work gets done. You will implement security controls across patching, hardening, network isolation, identity, and secrets management, rework patchingcyclesand golden-image refreshes so the team moves fast, scale AI-augmented tooling, and package repeatable execution so more junior engineers can pick it up.

About the Role

In this opportunity as Senior Security Engineer, you will:

  • Secure and harden the estate hands-on across the full stack: application and open-source dependency fixes, infrastructure patching, cloudconfigurationand guardrails, WAF, network isolation, and secrets and machine-identity management.

  • Improve andoptimizehow security gets done, reworking patching cycles and golden-image refreshes, cutting cycle time, and removing friction so the team moves faster.

  • Implement and tune security controls across operating systems, containers, CI/CD pipelines, cloud configuration, and network boundaries to defend against sophisticated adversaries and insider threats.

  • Scale adoption of AI-augmented SAST and SCA tooling, expanding coverage, reviewing generated pull requests, andvalidatingfixes, prioritizing by risk in line with CISA guidance and measuring mean time to remediate, throughput, and burndown against SLA.

  • Package reusable patterns, tooling, and runbooks so routine work can be executed by more junior engineers, and mentor them with technical review of their fixes.

  • Partner with application and platform teams to land andvalidatechanges safely, and coordinate with the wider team across regions to keep progress continuous across time zones.

  • Feedaccuratesecurity metrics and status into program reporting.

About You

You'rea fit for the role of Senior Security Engineer if your background includes:

  • 5+ years of security, software, orDevSecOpsengineering experience, comfortable securing and hardening across application, infrastructure, and cloud, plus abachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).

  • Multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage), alongside on-premises infrastructure.

  • A solid understanding of security principles and common vulnerabilities, with hands-on work across patching, hardening, cloud configuration, network isolation, and identity and access controls.

  • Hands-on experience with SAST/SCA tooling and remediating application and open-source dependency vulnerabilities, plus infrastructure patching.

  • A track recordof improving andoptimizingengineering processes, reducing cycle time in patching, releases, or security work, rather than only executing it.

  • Familiarity with vulnerability prioritization (CVSS/EPSS, CISA KEV) and SLA-driven burndown, plus comfort with AI-assisted tooling and reviewing its output critically.

  • Clear communication, some experience mentoring engineers, and strong ownership of security outcomes.

#LI-LB1


Whats in it For You?

  • Hybrid Work Model: We adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrows challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact:We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match. In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave. These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws. Finally, Thomson Reuters offers the following additional benefits: optional hospital, accident and sickness insurance paid 100% by the employee; optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement; access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.

Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position. The base compensation range varies across locations. For any eligible US locations, unless otherwise noted, the base compensation range for this role is $94,900 USD - $176,300 USD. Base pay is positioned within the range based on several factors including an individuals knowledge, skills and experience with consideration given to internal equity. Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs. This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.

About Thomson Reuters

Thomson Reuters Corporation is a Canadian multinational media conglomerate. The company was founded in Toronto, Ontario, Canada, where it is headquartered at 333 Bay Street. Thomson Reuters provides professionals with the intelligence, technology, and human expertise they need to find trusted answers in the financial and risk, legal, tax and accounting, and media markets. The company is dual-listed on the New York Stock Exchange and the Toronto Stock Exchange. In 2019, the company reported revenues of $5.9 billion and net income of $1.3 billion.
Learn more about Thomson Reuters
Size
24,400 employees
Market Cap
$53.8 billion
Industry
Founded
2008
5 Year Trend
-10.7%
NASDAQ

Similar Jobs

More Jobs at Thomson Reuters

More Information Technology Jobs

Find similar Senior Security Engineer jobs: