Thomson reuters
Security Engineer
Overview
As a Security Engineer within the Service Management & Transformation Team, you will play a hands-on role in implementing and maintaining security controls across applications, cloud platforms, and infrastructure environments spanning on-premises data centers and major cloud providers.
About Thomson reuters
Thomson Reuters informs the way forward by bringing together information, technology, and human expertise to help professionals make better decisions and uphold the rule of law.
Requirements & Eligibility
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent practical experience.
- Minimum 3 years of experience in Security Engineering, Software Development, Systems Administration, DevSecOps, or a related technical discipline.
- Hands-on experience with security patching and vulnerability remediation, system and cloud configuration hardening, identity and access management controls, network security controls, and scripting and automation.
- Experience working with at least one major cloud platform such as AWS, Azure, GCP, or OCI.
- Fundamental understanding of cybersecurity principles, security controls, and common vulnerabilities.
- Knowledge of vulnerability severity and risk assessment methodologies such as CVSS.
Key Responsibilities
- Execute security remediation activities across applications, cloud environments, and infrastructure platforms.
- Apply security patches, upgrade application and open-source dependencies, and remediate vulnerabilities identified through security assessments.
- Implement operating system and cloud hardening standards, security guardrails, web application firewall (WAF) rules, and network isolation controls.
- Review, validate, and implement pull requests generated through AI-powered SAST (Static Application Security Testing) and SCA (Software Composition Analysis) tools.
- Coordinate with application teams to perform regression testing and validate successful remediation of security issues.
- Support enterprise patching cycles, golden image refreshes, and software lifecycle management initiatives.
- Remove outdated, unsupported, and unused software from server and infrastructure environments.
- Follow established security runbooks, processes, standards, and risk-based prioritization frameworks.
Disclaimer: Trace Hiring is an independent job board. We are not directly affiliated with Thomson reuters. Please verify all details on the official company application portal.