Thomson Reuters logo
Thomson ReutersPosted 3 weeks ago

Senior Software Engineer II (Security)

HybridBengaluru, Karnataka, India

Full TimeSenior LevelEnterprise

Job Summary

Design and develop next-generation Software Supply Chain Security capabilities, including secure-by-default frameworks, libraries, and automation for SBOM generation, artifact signing, and provenance capture. Build IDE plugins, CI/CD templates, and a single pane of glass application to enable trusted build and release patterns across product teams. Develop SecDevOps machinery and policy-driven controls that help teams prove build integrity before deployment. Partner with application security, cloud native, and compliance teams to mature practices aligned with SLSA, Sigstore, and SPDX standards. Write comprehensive unit, integration, and regression tests to ensure quality and security. Provide expert technical security advice to management and contribute to software development guidelines.

Required Qualifications

  • 6+ years as a software developer in Golang (backend) and JavaScript (frontend – mainly VueJS)
  • Solid understanding of whatever the language's frameworks/ecosystem is
  • Ability to take on any programming assignments autonomously and deliver
  • Expertise in developing robust, scalable and well documented REST APIs
  • Working proficiency in building (secure) CI/CD pipelines with GitHub Actions
  • Working proficiency leveraging and operating the AWS services such as (but not limited to) IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, and EC2
  • Working proficiency building infrastructure as code with Terraform
  • All things as-code mindset
  • Familiarity with software supply chain security concepts such as SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance
  • In-depth understanding of software development methodologies
  • Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement
  • Hands-on security engineering or application security experience
  • Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate
  • Bachelor's degree in Computer Science

Desired Qualifications

  • Exposure to GraphQL
  • Understanding and experience in dealing with secrets management (e.g Conjur/Vault) and other Privileged Access Management workflows
  • Familiarity with secrets detection automation, including detection, triage, remediation workflows, and integration into developer and CI/CD tooling
  • Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows
  • Background in security engineering, application security, DevSecOps, platform security, or product security automation
  • Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement is a plus
  • Hands-on security engineering or application security experience a plus
  • Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce