JOBSEARCHER

Lead Security Engineer

Overview You will set the technical direction for securing Thomson Reuters’ global estate, spanning on-prem and multiple clouds. As a senior IC, you shape security strategy, design new controls, and elevate the security posture across platforms. You’ll collaborate with Security, Platform Engineering, and application teams to drive scalable, auditable security programs and runbooks. This role combines hands-on work with process design to enable safe, rapid delivery at scale. A strong hook is the opportunity to steer security across a diverse, global tech footprint. Compensation / Benefitshybrid work modelflexible work arrangements including work from anywhere up to 8 weeks/yeartuition reimbursement401k with company matchmental health days and Headspace benefitsvolunteer days and ESG initiatives ResponsibilitiesAct as the technical lead for security across application, cloud, and infrastructure; set direction and own the security backlog end-to-endDesign and implement security controls across OS, container orchestration, CI/CD, cloud configuration, and network boundariesRevamp patching cycles and image refresh processes for cloud and on-prem environmentsIdentify and formalize improved security and remediation approaches into team standardsDefine the technical approach for application, infrastructure, and identity security; prioritize by risk and advocate AI-augmented toolingMentor engineers, coordinate with regional security teams to align standards across time zonesOwn reporting, metrics, runbooks, standards, and escalation paths to make security repeatable and auditable Key requirements8+ years in security engineering, vulnerability management, or cloud/infrastructure security with senior IC or lead experienceDeep understanding of security principles across application, cloud, and infrastructure layersExperience with vulnerability management at scale and prioritization (CVSS/EPSS, CISA KEV, SLA-driven burndowns)Broad security knowledge: app/dep vulnerabilities, patching, guardrails, WAF, network isolation, IAMMulti-cloud experience (AWS, Azure, GCP, OCI) and on-prem knowledgeTrack record of designing/improving processes (patching, image refreshes) and automation/tooling; AI-assisted tooling is a plusStrong communication skills across technical and non-technical stakeholdersStrong judgment balancing risk and operational impactExcellent written and verbal communicationCross-functional collaborationSecurity architecture across OS, containers, CI/CD, cloud configurationsVulnerability management at scale (risk-based prioritization)WAF, network isolation, identity and access controls