Senior Product Security Engineer

Thomson Reuters

Hybrid
Secure software development lifecycle implementation
Threat modeling and secure code reviews
Cloud environment security (aws, azure, gcp)
The role focuses on embedding continuous security into engineering processes through the Secure Software Development Lifecycle

Job Summary

  • The role focuses on embedding continuous security into engineering processes through the Secure Software Development Lifecycle.
  • Candidates will lead threat modeling sessions and secure code reviews for diverse technology stacks including AI-based systems.
  • The company offers a hybrid work model, flexible vacation policies, and comprehensive mental health and retirement benefits.

Matching Summary

The role focuses on embedding continuous security into engineering processes through the Secure Software Development Lifecycle.

Skills & Requirements

Must-have

  • Secure Software Development Lifecycle implementation
  • Threat modeling and secure code reviews
  • Cloud environment security (AWS, Azure, GCP)
  • Application security principles and vulnerabilities
  • Python, GoLang, or Java programming proficiency

Nice-to-have

  • Experience with AI-based systems and LLMs
  • Infrastructure as Code (Terraform, CDK)
  • Container orchestration (Kubernetes, ECS)
  • Open-source security project contributions
  • Security research and conference presentations

Key Requirements

  • Bachelor's degree in computer science or equivalent
  • Experience with SAST, SCA, DAST, and fuzzers
  • Knowledge of OWASP, NIST, and CIS Benchmarks
  • Proficiency in writing code, tests, and API integrations

Work Rights

Not specified

Tailored Resume

Cover Letter