Thomson Reuters logo
Thomson ReutersPosted 1 week ago

Senior Security Engineer

HybridBengaluru, Karnataka, India

Full TimeSenior LevelBachelors DegreeEnterprise

Job Summary

Secure and harden the estate hands-on across the full stack, including application and open-source dependency fixes, infrastructure patching, cloud configuration, WAF, network isolation, and secrets management. Improve security processes by reworking patching cycles and golden-image refreshes to cut cycle time and remove friction. Implement and tune security controls across operating systems, containers, CI/CD pipelines, and network boundaries to defend against sophisticated adversaries. Scale AI-augmented SAST and SCA tooling, reviewing generated pull requests and validating fixes against CISA guidance while measuring remediation throughput and burndown. Package reusable patterns and runbooks to enable junior engineers to execute routine work, and mentor them through technical reviews. Partner with application and platform teams to land changes safely and coordinate progress across time zones. Feed accurate security metrics into program reporting.

Required Qualifications

  • 5+ years of security, software, or DevSecOps engineering experience
  • comfortable securing and hardening across application, infrastructure, and cloud
  • a bachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience)
  • Multi-cloud experience across two or more of AWS, Azure, GCP, and OCI
  • on-premises infrastructure
  • A solid understanding of security principles and common vulnerabilities
  • hands-on work across patching, hardening, cloud configuration, network isolation, and identity and access controls
  • Hands-on experience with SAST/SCA tooling
  • remediating application and open-source dependency vulnerabilities
  • infrastructure patching
  • A track record of improving and optimizing engineering processes
  • reducing cycle time in patching, releases, or security work
  • Familiarity with vulnerability prioritization (CVSS/EPSS, CISA KEV)
  • SLA-driven burndown
  • comfort with AI-assisted tooling
  • reviewing its output critically
  • Clear communication
  • some experience mentoring engineers
  • strong ownership of security outcomes

Desired Qualifications

  • all four an advantage

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce