Thomson Reuters

Lead Security Engineer

Thomson Reuters
Apply
5 days ago
Bengaluru, IndiaStaff+

Responsibilities

  • Set technical direction and own the security backlog across application, cloud, infrastructure, and network security.
  • Design and build controls for operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries.
  • Improve patching cycles, golden-image and base-image refreshes, remediation workflows, and security processes across cloud and on-premises environments.
  • Define approaches for dependency fixes, infrastructure patching, cloud guardrails, WAF, network isolation, secrets management, and machine identity.
  • Prioritize vulnerabilities using CISA guidance, CISA KEV, CVSS/EPSS, and SLA-driven burndown.
  • Champion AI-augmented, SAST, SCA, automated security tooling, and other remediation improvements.
  • Review security fixes, mentor engineers, coordinate with global security teams, and align standards across regions.
  • Create reporting, metrics, runbooks, standards, and escalation paths for an auditable security capability.

Requirements

  • 8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security.
  • Experience serving as a technical lead or senior individual contributor who sets direction and guides other engineers' technical work.
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • Deep understanding of security principles, common vulnerabilities, and best practices across application, cloud, and infrastructure layers.
  • Working knowledge of vulnerability-management prioritization, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
  • Experience across at least two of AWS, Azure, GCP, and OCI, together with on-premises infrastructure; experience with all four clouds is advantageous.
  • Track record of designing and improving patching, image refresh, remediation, automation, or security-tooling processes rather than only executing them.
  • Experience with AI-assisted or automated security tooling is advantageous.
  • Strong judgment balancing risk reduction with operational and customer impact, plus strong written and verbal communication across technical and non-technical audiences.

Benefits

  • Flexible hybrid work model with office attendance typically 2–3 days per week for office-based roles.
  • Flexible work arrangements, including work from anywhere for up to 8 weeks per year.
  • Career development, continuous learning, Grow My Way programming, and skills-focused growth opportunities.
  • Comprehensive benefits including flexible vacation, two company-wide Mental Health Days, Headspace access, retirement savings, tuition reimbursement, incentive programs, and wellbeing resources.
  • Two paid volunteer days annually and opportunities for pro-bono consulting and ESG initiatives.
Thomson Reuters

About Thomson Reuters

10,000+ employees

Thomson Reuters (TSX/NDAQ: TRI) informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news. For more information on Thomson Reuters, visit tr.com and for the latest world news, reuters.com.

Contact me