×
Register Here to Apply for Jobs or Post Jobs. X

Lead Security Engineer

Job in Eagan, Dakota County, Minnesota, USA
Listing for: Thomson Reuters
Full Time position
Listed on 2026-08-29
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 118000 - 220000 USD Yearly USD 118000.00 220000.00 YEAR
Job Description & How to Apply Below

The Opportunity

Do you want to set the technical direction for how a global business secures its infrastructure at scale? Thomson Reuters™ is investing in a dedicated security engineering capability, and we are looking for a hands‑on technical lead to help build and shape it.

You will design how we secure our estate end to end, not just work through a backlog. This role sits on our Service Management & Transformation team.

As the Lead Security Engineer, you will be the technical lead for security across our application, cloud, and infrastructure estate, which spans on‑premises data centers and major clouds. This is a senior individual‑contributor role: you set the technical direction and guide the work of the engineers around you, but you are not their line manager. It is as much a process‑design role as a hands‑on one.

You will design new security controls and ways of working across patching, hardening, network isolation, identity, and secrets management, revamping patching cycles and golden‑image refreshes so the team can move fast without sacrificing safety, and you will partner across Information Security, Platform Engineering, and application teams to raise our overall security posture.

About

The Role
  • Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line-management responsibility.
  • Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
  • Design new security processes and ways of working, revamping patching cycles and golden‑image and base‑image refreshes across cloud and on‑prem, so the team can move fast without sacrificing safety.
  • Come to the table with ideas: identify where security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
  • Set the technical approach across the full security scope: application and open‑source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine‑identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA‑driven burndown), and champion adoption of AI‑augmented security tooling, including SAST and SCA.
  • Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
  • Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About You
  • 8+ years of hands‑on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers, plus a bachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
  • A deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers.
  • A working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA‑driven burndown.
  • Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls, with multi‑cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on‑premises infrastructure.
  • A track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, rather than only executing them, with a proactive mindset for identifying and closing security gaps through automation and tooling; experience with…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary