Lead Security Engineer
Thomson Reuters™ is investing in a dedicated security engineering capability and seeks a hands-on technical lead to help build and shape it. You will design how we secure our estate end-to-end, setting the technical direction across application, cloud, and infrastructure layers that span on-premises data centers and major clouds. This is a senior individual-contributor role where you guide the work of engineers without line-management responsibility, focusing on both process design and hands-on execution.
About the Role
- Act as the technical lead for security across application, cloud, and infrastructure, owning the shape and quality of the security backlog and serving as the point of escalation for complex security and remediation work.
- Design and build security controls across operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries to defend against sophisticated adversaries and insider threats.
- Revamp patching cycles, golden-image, and base-image refreshes across cloud and on-prem to enable fast, safe operations.
- Identify security and remediation process improvements, propose better approaches, and turn them into adopted standards.
- Set the technical approach for application and open-source dependency fixes, infrastructure patching, cloud configuration, WAF, network isolation, and secrets/machine-identity management.
- Prioritize by risk using industry best practices such as CISA KEV, CVSS/EPSS, and SLA-driven burndown; champion AI-augmented security tooling like SAST and SCA.
- Raise the technical bar by reviewing fixes, mentoring engineers, and coordinating with global security teams to align standards and priorities.
- Own clear reporting, metrics, runbooks, standards, and escalation paths to make security a repeatable, auditable capability.
Requirements
- 8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction.
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience).
- Deep understanding of security principles, common vulnerabilities, and best practices across application, cloud, and infrastructure layers.
- Working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
- Breadth across the security stack: application/dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity/access controls.
- Multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on-premises infrastructure.
- Track record of designing and improving technical processes (e.g., patching cycles, image/GAMI refreshes, remediation workflows) with a proactive mindset for closing security gaps through automation.
- Experience with AI-assisted or automated security tooling is an advantage.
- Strong judgment in balancing risk reduction against operational and customer impact.
- Excellent written and verbal communication, comfortable conveying complex security concepts to technical and non-technical stakeholders.
- Enthusiasm for collaborating with cross-functional teams to build secure, reliable, globally scalable systems.
Benefits
- Hybrid Work Model: Flexible hybrid working environment with work-from-anywhere options for up to 8 weeks per year.
- Flexibility & Work-Life Balance: Supportive policies including flexible work arrangements, two company-wide Mental Health Days off, and resources for personal/professional responsibilities.
- Career Development: Culture of continuous learning with skills-first programming and tools to grow in an AI-enabled future.
- Competitive Benefits: Comprehensive plans including flexible vacation, retirement savings with company match, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
- Additional Benefits: Optional hospital/accident/sickness insurance, life/AD&D insurance, Flexible Spending/Health Savings Accounts, fitness reimbursement, Employee Assistance Program, Group Legal/Identity Theft Protection, 529 Plan, commuter benefits, Adoption & Surrogacy Assistance, and Employee Stock Purchase Plan.
- Culture: Globally recognized for inclusion, belonging, flexibility, and work-life balance; values-driven environment.
- Social Impact: Two paid volunteer days off annually and opportunities for pro-bono consulting and ESG initiatives.
Pay
The base compensation range for this role is $118,400 USD – $219,800 USD, positioned within the range based on knowledge, skills, experience, and internal equity. This role may also be eligible for an Annual Bonus based on enterprise and individual performance.