
Senior Software Engineer II (Security)
Thomson Reuters12 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Develop secure-by-default software supply chain security frameworks, libraries, automation, CI templates, and IDE plugins.
- Build a product security application that provides insights and self-service capabilities to product teams.
- Lead initiatives involving SBOM generation and consumption, build provenance, artifact signing, signature verification, trusted builds, and release governance.
- Design automation and policy-driven controls for proving what was built, its origin, and whether it can be trusted before deployment.
- Develop and operate security tooling involving secrets detection, dependency governance, container image trust, vulnerability management, and policy-as-code enforcement.
- Write unit, integration, regression, and security tests and contribute to software development guidelines and documentation.
- Provide expert technical security advice to management and collaborate with application security, cloud-native security, platform engineering, and compliance teams.
Requirements
- At least 6 years of software development experience using Golang for backend development and JavaScript, primarily VueJS, for frontend development.
- Ability to independently take on programming assignments and deliver solutions using the relevant language ecosystems and frameworks.
- Expertise developing robust, scalable, and well-documented REST APIs; GraphQL experience is a plus.
- Working proficiency building secure CI/CD pipelines with GitHub Actions and developing scalable automation workflows.
- Working proficiency operating AWS services including IAM, SQS, S3, Lambda, DynamoDB, RDS, EKS, and EC2.
- Working proficiency building infrastructure as code with Terraform.
- Familiarity with software supply chain security concepts including SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
- Experience or familiarity with secrets management, such as Conjur or Vault, secrets detection automation, and privileged access management workflows.
- Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows.
- Background in security engineering, application security, DevSecOps, platform security, or product security automation is strongly preferred.
- Hands-on experience implementing secure CI/CD guardrails, dependency governance, container image trust, vulnerability management, policy-as-code enforcement, or application security is a plus.
- Deep understanding of OWASP Top 10 vulnerabilities and their mitigation.
- A bachelor’s degree in Computer Science is preferred.
Benefits
- Flexible hybrid work model with two to three office days per week depending on the role.
- Work-from-anywhere flexibility for up to 8 weeks per year and supportive work-life balance policies.
- Career development, continuous learning, skills development, and Grow My Way programming.
- Comprehensive benefits including flexible vacation, two company-wide Mental Health Days, Headspace access, retirement savings, tuition reimbursement, employee incentive programs, and wellbeing resources.
- Two paid volunteer days annually and opportunities for pro-bono consulting and ESG projects.
Tech Stack
About Thomson Reuters
Thomson Reuters builds research platforms, workflow software, and data services for legal, tax and accounting, compliance, and government professionals, and operates the Reuters global news service. Flagship products include Westlaw for legal research and ONESOURCE and Checkpoint for tax and accounting, sold primarily via subscriptions and enterprise licenses. A public company headquartered in Toronto, it was formed in 2008 by combining Thomson Corporation and Reuters Group and is listed on the TSX and Nasdaq as TRI.