Security Engineer
Thomson Reuters · Eagan, MN · 2 days ago
Hybrid$71k/yrFull-time
Thomson Reuters is building a dedicated security engineering capability. This role sits on the Service Management & Transformation team, executing security work across the full application, cloud, and infrastructure estate, which spans on-premises data centers and major clouds.
Responsibilities
- Execute security work across the full stack: apply patches, upgrade application and open-source dependencies, harden cloud and operating-system configuration, and implement guardrails, WAF, and network-isolation changes.
- Work the pull requests generated by AI-augmented SAST and SCA tooling, confirm fixes hold, and coordinate regression testing with application teams.
- Support patching cycles and golden-image refreshes, and help remove unused and outdated software from server estates.
- Implement the controls and follow the runbooks, standards, and risk-based prioritization (in line with CISA guidance) set by the senior engineer and technical lead.
- Track status accurately from assignment through verified fix, and flag blockers early.
- Partner with application and platform teams to schedule and validate changes safely, and coordinate with the wider team across regions.
- Grow your skills across application, infrastructure, and cloud security with support from senior engineers.
Requirements
- 3+ years of experience in security engineering, software development, systems administration, or DevSecOps, with a desire to specialize in security.
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
- Hands-on exposure to some of the following: patching, hardening, cloud configuration, network or identity controls, or scripting and automation.
- Exposure to one or more of AWS, Azure, GCP, and OCI, and to on-premises infrastructure.
- A basic understanding of security principles and common vulnerabilities, and of risk-based prioritization (CVSS and similar), with willingness to learn CISA KEV/EPSS in practice.
- Comfort working to defined processes, runbooks, and controls, and asking for review on complex work.
- A collaborative approach and strong ownership of the work you ship.
- Clear communication and attention to detail.
Benefits
- Hybrid Work Model: Flexible hybrid working environment for office-based roles.
- Flexibility & Work-Life Balance: "Flex My Way" policies, including work from anywhere for up to 8 weeks per year, and two company-wide Mental Health Days off.
- Career Development and Growth: Culture of continuous learning, skills-first approach, and "Grow My Way" programming.
- Industry Competitive Benefits:
- Comprehensive benefit plans: health, dental, vision, disability, and life insurance.
- Retirement savings with company match (401k).
- Paid time off: vacation, sick and safe leave, holidays, parental leave, sabbatical leave.
- Tuition reimbursement and employee incentive programs.
- Resources for mental, physical, and financial wellbeing (e.g., Headspace app).
- Optional insurance: hospital, accident, sickness, life, AD&D, identity theft protection.
- Flexible Spending and Health Savings Accounts.
- Fitness reimbursement and Employee Assistance Program.
- Group Legal and commuter benefits.
- Adoption & Surrogacy Assistance.
- Access to 529 Plan and Employee Stock Purchase Plan.
- Culture: Globally recognized for inclusion, belonging, flexibility, and work-life balance. Values: customer obsession, competitiveness, challenging thinking, agility, and collaboration.
- Social Impact: Two paid volunteer days off annually, pro-bono consulting projects, and ESG initiatives through the Social Impact Institute.
- Making a Real-World Impact: Contribute to products that help uphold the rule of law, turn the wheels of commerce, and provide trusted information globally.
Pay
The base compensation range for this role is $70,800 USD - $131,400 USD, positioned within the range based on knowledge, skills, experience, and internal equity. This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.