Level

Thomson Reuters

Senior Software Engineer II (Security)

AI in this role

As a Senior Software Engineer II, you will focus on designing and developing our next generation of Software Supply Chain Security capabilities. This role will help establish secure-by-default frameworks, libraries, and automation that improve how product teams generate SBOMs, capture software supply chain provenance, sign and verify artifacts, and adopt trusted build and release patterns across their S-SDLCs. The work will span IDE plugins, Continuous Integration (CI) libraries, secure defaults, secrets management helpers, and our single pane of glass product security application that product teams can easily consume.

About the role: 

As a Senior Software Engineer, your Job roles include below:

  • Develop our SecDevOps machinery that provides teams with secure defaults that powers our frictionless vision of product security. 
  • Work on sets of secure libraries, CI templates, IDE plugins to further adoption of security. 
  • Develop our single pane of glass application, providing insights and self-service to our product teams. 
  • Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, build provenance, artifact signing, signature verification, and trusted release workflows.
  • Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
  • Work with our application security and cloud native security teams to develop supply chain security toolchain. 
  • Partner with application security, cloud native security, platform engineering, and compliance teams to mature SSCS/SSCP practices aligned to industry approaches such as SLSA, Sigstore/Cosign, SPDX, CycloneDX, and in-toto attestations.
  • Write all needed unit, integration, regression, security tests to consistently deliver quality and security. 
  • Provide expert technical security advice to management. 
  • Participate in developing software development guidelines and documentation. 

  About You:

You are a fit for the role if you meet the below qualifications: 

  • 6+years as a software developer in Golang (backend) and JavaScript (frontend – mainly VueJS) along with a solid understanding of whatever the language's frameworks/ecosystem is. You can take on any programming assignments autonomously and deliver. 
  • Expert in developing robust, scalable and well documented REST APIs. Exposure to GraphQL a plus. 
  • Working proficiency in building (secure) CI/CD pipelines with GitHub Actions.
  • Well-versed in automation workflows and scalability
  • Working proficiency leveraging and operating the AWS services such as (but not limited to) IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, and EC2. 
  • Working proficiency building infrastructure as code with Terraform. 
  • All things as-code mindset to expand to adjacent security teams. 
  • Familiarity with software supply chain security concepts such as SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
  • In-depth understanding of software development methodologies. 
  • Understanding and experience in dealing with secrets management (e.g Conjur/Vault) and other Privileged Access Management workflows a plus. 
  • Familiarity with secrets detection automation, including detection, triage, remediation workflows, and integration into developer and CI/CD tooling.
  • Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows.
  • Background in security engineering, application security, DevSecOps, platform security, or product security automation strongly preferred.
  • Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement is a plus.
  • Hands-on security engineering or application security experience a plus. 
  • Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate 
  • Bachelor’s degree in Computer Science preferred 

  

#LI-VGA1

What’s in it For You?

  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.

  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.

  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.

  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.

  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.

  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.

  • Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.

Learn more on how to protect yourself from fraudulent job postings here.

More information about Thomson Reuters can be found on thomsonreuters.com.

How we rate this

Senior Software Engineer II (Security) at Thomson Reuters rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Get new software engineer jobs by email

One email a week with the new software engineer jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Software Engineering roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Thomson Reuters

More software engineer jobs

Related searches

Same AI level