Lead Security Engineer
Thomson Reuters™ is investing in a dedicated security engineering capability and seeks a hands-on technical lead to help build and shape it. You will design how we secure our estate end-to-end, setting technical direction across application, cloud, and infrastructure layers that span on-premises data centers and major clouds. This is a senior individual-contributor role where you guide the work of engineers without line-management responsibility, focusing on both process design and hands-on execution.
About the Role
- Act as the technical lead for security across application, cloud, and infrastructure, owning the shape and quality of the security backlog and serving as the point of escalation for complex security and remediation work.
- Design and build security controls across operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries to defend against sophisticated adversaries and insider threats.
- Design new security processes and ways of working, revamping patching cycles and golden-image/base-image refreshes across cloud and on-prem to enable speed without sacrificing safety.
- Identify opportunities to improve security and remediation processes, propose better approaches, and turn them into adopted standards.
- Set the technical approach for application and open-source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine-identity management.
- Prioritize by risk using industry best practices such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown) and champion adoption of AI-augmented security tooling, including SAST and SCA.
- Raise the technical bar by reviewing fixes, mentoring engineers, and coordinating with the wider security team across regions to align standards and priorities.
- Own clear reporting and metrics, and build runbooks, standards, and escalation paths to make security a repeatable, auditable capability.
Requirements
- 8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the work of other engineers.
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
- Deep understanding of security principles, common vulnerabilities, and best practices across application, cloud, and infrastructure layers.
- Working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
- Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls.
- Multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on-premises infrastructure.
- Track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, with a proactive mindset for identifying and closing security gaps through automation and tooling.
- Experience with AI-assisted or automated security tooling is an advantage.
- Strong judgment on balancing risk reduction against operational and customer impact.
- Excellent written and verbal communication, comfortable operating across security, engineering, and business audiences, and able to convey complex security concepts to technical and non-technical stakeholders.
- Enthusiasm for collaborating with cross-functional teams to build secure, reliable systems that scale globally.
Benefits
- Hybrid Work Model: Flexible hybrid working environment with work-from-anywhere options for up to 8 weeks per year.
- Flexibility & Work-Life Balance: Supportive policies including flexible work arrangements, two company-wide Mental Health Days off, and resources for mental, physical, and financial wellbeing.
- Career Development and Growth: Culture of continuous learning with skills-first programming and tools to grow, lead, and thrive in an AI-enabled future.
- Industry Competitive Benefits: Comprehensive plans including flexible vacation, retirement savings with company match, tuition reimbursement, employee incentive programs, and access to the Headspace app.
- Culture: Globally recognized for inclusion, belonging, flexibility, and work-life balance, guided by values such as obsessing over customers and acting fast to learn.
- Social Impact: Two paid volunteer days off annually, opportunities for pro-bono consulting, and involvement in Environmental, Social, and Governance (ESG) initiatives.
- Additional Benefits: Optional hospital, accident, and sickness insurance; life and AD&D insurance; Flexible Spending and Health Savings Accounts; fitness reimbursement; Employee Assistance Program; Group Legal and Identity Theft Protection; 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and Employee Stock Purchase Plan.
Pay
The base compensation range for this role is $118,400 USD - $219,800 USD, positioned within the range based on knowledge, skills, experience, and internal equity. This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.