
Principal Software Engineer, Security & Compliance
Thomson Reuters2 days ago
Zug, SwitzerlandStaff+
Responsibilities
- Own and evolve compliance architecture and technical controls for SOC 2 Type II, ISO 27001/42001, HIPAA, and FedRAMP Moderate/High requirements.
- Build compliance-as-code capabilities, including automated evidence collection, continuous control monitoring, and policy-as-code.
- Design encryption, key management, data residency, tenant isolation, and audit logging for large-scale systems handling sensitive legal documents and AI interactions.
- Translate regulatory, contractual, customer, and government requirements into engineering roadmaps with Security, Legal, Privacy, and Product teams.
- Mentor staff and senior engineers and promote secure-by-design development, threat modeling, and incident response practices.
- Establish SLOs, observability, and incident response practices for compliance-critical systems.
- Build dashboards, alerting, and control-testing tooling to provide real-time visibility into the control environment.
Requirements
- Bachelor's degree in Computer Science, Computer Engineering, a related field, or equivalent experience.
- Hands-on experience building or operating production systems that achieved and maintained SOC 2 Type II, ISO 27001 and/or ISO 42001, and HIPAA compliance.
- Experience supporting a FedRAMP authorization process, including SSP development, control implementation, 3PAO assessments, or continuous monitoring.
- Deep backend engineering expertise with Python, Java, Go, or similar technologies and production experience on a major cloud provider, preferably AWS.
- Working knowledge of NIST 800-53, NIST CSF, or CIS Benchmarks and the ability to map implementations to control requirements.
- Hands-on identity and access management experience covering SSO, SAML, OIDC, OAuth 2.0, RBAC/ABAC, encryption, key management, and audit logging.
- Track record owning complex compliance or security initiatives through architecture, execution, audit readiness, and long-term operation.
- Strong communication and cross-functional partnership skills with auditors, security, legal, product, and engineering teams.
- Preferred experience achieving or maintaining a FedRAMP ATO with JAB or agency sponsorship and working directly with 3PAOs and federal security teams.
- Preferred experience with Vanta, Drata, OneTrust, comparable GRC platforms, or custom evidence-collection pipelines.
- Preferred experience handling sensitive data in legal, healthcare, financial services, or government environments.
- Relevant certifications such as CISSP, CISM, CCSP, or similar are preferred.
- Preferred experience building security and compliance controls for AI/LLM systems, including model access controls, prompt and response data handling, and safeguards for sensitive content.
Benefits
- Flexible hybrid work model for office-based roles.
- Work-from-anywhere flexibility for up to 8 weeks per year and supportive work-life policies.
- Career development, continuous learning, Grow My Way programming, and skills-first development support.
- Comprehensive benefits including flexible vacation, two company-wide Mental Health Days, Headspace access, retirement savings, tuition reimbursement, incentive programs, and wellbeing resources.
- Two paid volunteer days annually and opportunities for pro-bono consulting and ESG initiatives.
About Thomson Reuters
Thomson Reuters builds research platforms, workflow software, and data services for legal, tax and accounting, compliance, and government professionals, and operates the Reuters global news service. Flagship products include Westlaw for legal research and ONESOURCE and Checkpoint for tax and accounting, sold primarily via subscriptions and enterprise licenses. A public company headquartered in Toronto, it was formed in 2008 by combining Thomson Corporation and Reuters Group and is listed on the TSX and Nasdaq as TRI.