
AI Security Associate Architect
Thomson Reuters22 hours ago
Toronto, CanadaStaff+
Responsibilities
- Assess evolving threats, technologies, security frameworks, and regulatory requirements and translate them into actionable guidance.
- Develop repeatable security assessment frameworks, requirements, reference architectures, secure design patterns, and cloud guardrails.
- Lead architecture reviews, threat modeling, risk assessments, and security trade-off decisions for systems, integrations, migrations, and emerging technologies.
- Review multi-cloud platforms, modern application stacks, container platforms, and AI and agentic systems.
- Track security findings, align stakeholders on risks and controls, and support implementation of prioritized engineering actions.
- Mentor engineers, build cross-functional relationships, and improve architecture review methods and security knowledge bases.
Requirements
- Bachelor’s degree in computer science or equivalent practical experience.
- 10+ years of hands-on experience in security architecture, software engineering, application security, or cloud security.
- Strong knowledge of cryptography, key management, authentication and authorization, identity federation, network and operating system security, data protection, and detection and response.
- Hands-on experience with at least one major cloud provider, including identity and access management, networking, and shared platform services.
- Experience leading security architecture reviews, threat modeling, and risk assessments across multiple products or platforms.
- Experience designing secure applications, APIs, and container platforms, including knowledge of Kubernetes and secure CI/CD practices.
- Working knowledge of AI and agentic system security, including prompt injection, model and data integrity, and controls for agent and tool use.
- Preferred qualifications include relevant certifications such as CISSP, CCSP, CISM, GIAC, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
- Preferred experience includes enterprise-scale multi-cloud security, AI and generative AI security, model governance, data protection, secure tool integration, and scaling security architecture standards.
Benefits
- Hybrid work model for office-based roles.
- Flexible work arrangements, including work from anywhere for up to 8 weeks per year.
- Career development, continuous learning, and skills development programs.
- Comprehensive benefits including flexible vacation, two company-wide Mental Health Days, Headspace access, retirement savings, tuition reimbursement, incentive programs, and wellbeing resources.
- Two paid volunteer days annually and opportunities for pro-bono consulting and ESG initiatives.
Tech Stack
Categories
About Thomson Reuters
Thomson Reuters builds research platforms, workflow software, and data services for legal, tax and accounting, compliance, and government professionals, and operates the Reuters global news service. Flagship products include Westlaw for legal research and ONESOURCE and Checkpoint for tax and accounting, sold primarily via subscriptions and enterprise licenses. A public company headquartered in Toronto, it was formed in 2008 by combining Thomson Corporation and Reuters Group and is listed on the TSX and Nasdaq as TRI.