Security architect securing Thomson Reuters’ legal, tax, compliance, government, and media technology platforms. Leading architecture reviews, cloud security, threat modelling, and AI system risk controls.
Responsibilities
Embed security across Thomson Reuters' products, platforms, and enterprise systems
Provide technical leadership across the organization or within a business unit
Partner with information security and risk management, platform engineering, service management, commercial engineering, and product engineering teams
Assess evolving threats and technologies and translate best practices, security frameworks, and regulatory requirements into actionable guidance
Establish repeatable assessment frameworks and security requirements
Define reference architectures and secure design patterns with domain architects and engineering teams
Guide reference implementations and support adoption across shared services and cloud landing zones
Assess risks, recommend controls, and document architectural decisions and trade-offs
Lead architecture reviews and threat modelling for new systems, integrations, migrations, and emerging technologies
Review multi-cloud platforms, modern application stacks, and AI and agentic systems
Track findings, translate them into practical recommendations, align stakeholders on security trade-offs, and support implementation
Continuously update reference architectures, implementations, and guardrails
Build relationships across teams, mentor engineers, and improve architecture review methods and knowledge base
Requirements
Bachelor's degree in computer science, or equivalent practical experience
10+ years of hands-on experience in security architecture, software engineering, application security, or cloud security
Exceptional written and verbal communication skills
Strong analytical skills and sound judgment balancing security risks, engineering constraints, and business needs
Strong understanding of cryptography concepts and key management, authentication and authorization, identity federation, network and operating system security, data protection, and detection and response
Hands-on experience and deep understanding of at least one major cloud provider (AWS, Azure, or GCP), including identity and access management, networking, and shared platform services
Experience leading security architecture reviews, threat modelling, and risk assessments across multiple products or platforms
Ability to develop security requirements, reusable design patterns, and reference architectures
Experience translating security frameworks, standards, and applicable regulatory requirements into controls, assessment methods, and practical engineering guidance
Experience designing and implementing secure applications, APIs, and container platforms
Knowledge of Kubernetes and secure CI/CD practices
Ability to read and discuss infrastructure configurations, validate design assumptions, and guide secure implementation
Working knowledge of AI and agentic system security, including prompt injection, model and data integrity, and controls for agent and tool use
Relevant industry certifications such as CISSP, CCSP, CISM, GIAC, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer are preferred
Experience designing and securing enterprise-scale multi-cloud environments across AWS, Azure, and/or GCP is preferred
Experience with security architecture for AI, generative AI, large language models, or agentic systems is preferred
Experience developing and scaling security architecture standards, cloud guardrails, reusable design patterns, and reference implementations is preferred
Benefits
Flexible hybrid working environment
Flexible work arrangements, including work from anywhere for up to 8 weeks per year
Continuous learning and skills development through Grow My Way programming
Flexible vacation
Two company-wide Mental Health Days off
Access to the Headspace app
Retirement savings
Tuition reimbursement
Employee incentive programs
Resources for mental, physical, and financial wellbeing
Two paid volunteer days off annually
Opportunities for pro-bono consulting projects and ESG initiatives
Annual Bonus based on a combination of enterprise and individual performance may be available
Reasonable accommodations for qualified individuals with disabilities and sincerely held religious beliefs
Product Security Engineer securing Cohere’s enterprise AI products and foundation models. Reviewing architecture, threat modeling capabilities, and testing vulnerabilities across production systems.
Ingénieur cybersécurité renforçant la posture de sécurité d’EDC, société canadienne de financement du commerce international. Intégration de contrôles, DevSecOps et sécurité de l’IA.
Senior Program Manager driving enterprise cybersecurity programs for NBCUniversal, a global media and entertainment company. Coordinating technical delivery, operational change, adoption, risk, and executive reporting.
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.