ForgeApply · Job listing
Lead Security Engineer
Thomson Reuters
See all 109 open roles at Thomson Reuters →
Tailor your resume for this Thomson Reuters job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Thomson Reuters's site. Free trial, no card required.
About this role
The Opportunity
Do you want to set the technical direction for how a global business secures its infrastructure at scale? Thomson Reuters™ is investing in a dedicated security engineering capability, and we are looking for a hands-on technical lead to help build and shape it. You will design how we secure our estate end to end, not just work through a backlog. This role sits on our Service Management & Transformation team.
As the Lead Security Engineer, you will be the technical lead for security across our application, cloud, and infrastructure estate, which spans on-premises data centers and major clouds. This is a senior individual-contributor role: you set the technical direction and guide the work of the engineers around you, but you are not their line manager. It is as much a process-design role as a hands-on one. You will design new security controls and ways of working across patching, hardening, network isolation, identity, and secrets management, revamping patching cycles and golden-image refreshes so the team can move fast without sacrificing safety, and you will partner across Information Security, Platform Engineering, and application teams to raise our overall security posture.
About the Role
In this opportunity as Lead Security Engineer, you will:
• Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line-management responsibility.
• Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
• Design new security processes and ways of working, revamping patching cycles and golden-image and base-image refreshes across cloud and on-prem, so the team can move fast without sacrificing safety.
• Come to the table with ideas: identify where security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
• Set the technical approach across the full security scope: application and open-source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine-identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and SCA.
• Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
• Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About You
You're a fit for the role of Lead Security Engineer if your background includes:
• 8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers, plus a bachelor's degree in Computer Science , Information Security, or a related field (or equivalent practical experience).
• A deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers.
• A working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
• Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls, with multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on-premises infrastructure.
• A track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, rather than only executing them, with a proactive mindset for identifying and closing security gaps through automation and tooling; experience with AI-assisted or automated security tooling is an advantage.
• Strong judgment on balancing risk reduction against operational and customer impact.
• Excellent written and verbal communication, comfortable operating across security, engineering, and business audiences and able to convey complex security concepts to technical and non-technical stakeholders, with enthusiasm for collaborating with cross-functional teams to build secure, reliable systems that scale globally.
#LI-LB1
What’s in it For You? • Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected. • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance. • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future. • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days
Tailor your resume for this Thomson Reuters role before you apply.
Tailor my resume for this jobSimilar jobs
- Lead Security Engineer — Circles · Remote
- Lead Security Engineer — Suno · Boston
- Lead Security Engineer — Gnw · Remote
- Lead Security Engineer — Ardentmc · Rockville, MD
- Lead Security Engineer — Hinge Health · New York
- Lead Security Engineer — Duettoresearch · United States
- Lead Security & Infrastructure Engineer — Anodize · San Francisco or Los Altos, CA
- Lead Security and Infrastructure Engineer — Latamcent · Tampa, Florida
More like this: Security & Cybersecurity Jobs · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview