Thomson Reuters logo
Thomson ReutersPosted 1 week ago

Lead Security Engineer

HybridBengaluru, Karnataka, India

Full TimeSenior LevelBachelors DegreeEnterprise

Job Summary

Lead security controls across application, cloud, and infrastructure layers, including operating systems, container orchestration, CI/CD pipelines, and network boundaries. Set technical direction for the security backlog, prioritize remediation by risk using CISA guidance and industry best practices, and champion AI-augmented tooling like SAST and SCA. Design new processes for patching cycles and image refreshes, then review fixes, mentor engineers, and coordinate standards across global regions. Build runbooks, metrics, and escalation paths to ensure security is repeatable and auditable.

Required Qualifications

  • 8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security
  • time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers
  • bachelor's degree in Computer Science, Information Security, or a related field
  • equivalent practical experience
  • deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers
  • working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown
  • breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls
  • multi-cloud experience across two or more of AWS, Azure, GCP, and OCI
  • on-premises infrastructure experience
  • track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows
  • proactive mindset for identifying and closing security gaps through automation and tooling
  • experience with AI-assisted or automated security tooling
  • strong judgment on balancing risk reduction against operational and customer impact
  • excellent written and verbal communication
  • comfortable operating across security, engineering, and business audiences
  • ability to convey complex security concepts to technical and non-technical stakeholders
  • enthusiasm for collaborating with cross-functional teams to build secure, reliable systems that scale globally

Desired Qualifications

  • all four of AWS, Azure, GCP, and OCI
  • experience with AI-assisted or automated security tooling is an advantage

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce