Lead Security Engineer

Thomson Reuters

Bengaluru

Hybrid

INR 4,000,000 - 6,000,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model

Job summary

Thomson Reuters is seeking a Lead Security Engineer to act as the technical leader for security across applications, cloud, and infrastructure. You will shape the security backlog, set direction, and own remediation efforts with no direct line-management responsibilities.

The role requires designing security controls across OS, containers, CI/CD, cloud configurations, and network boundaries to defend against sophisticated threats.

Qualifications

  • 8+ years of hands-on experience in security engineering, vulnerability management, or cloud security.
  • Deep understanding of security principles across application, cloud, and infrastructure layers.
  • Working command of vulnerability management at scale: CVSS/EPSS, CISA KEV, SLA-driven burndown.

Responsibilities

  • Act as the technical lead for security across application, cloud, and infrastructure, setting direction and owning the security backlog.
  • Design and build security controls across OS, containers, CI/CD, cloud configuration, and network boundaries.
  • Revamp patching cycles and image refreshes across cloud and on-prem to balance speed and safety.
  • Propose improvements, turn them into standards, and mentor engineers.
  • Set the technical approach across the full security scope including WAF, guardrails, and secrets management; prioritize by risk and adopt AI-augmented tooling (SAST/SCA).
  • Review fixes and coordinate with security teams across regions to align standards across time zones.
  • Own reporting and runbooks to make security repeatable and auditable.

Skills

Security engineering
Vulnerability management
Cloud security
Infrastructure security
Technical leadership
Cross-functional collaboration

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

AWS
Azure
GCP
OCI

Job description

About The Role

In this opportunity as Lead Security Engineer, you will:

  • Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line-management responsibility.
  • Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
  • Design new security processes and ways of working, revamping patching cycles and golden-image and base-image refreshes across cloud and on-prem, so the team can move fast without sacrificing safety.
  • Come to the table with ideas: identify where security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
  • Set the technical approach across the full security scope: application and open-source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine-identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and SCA.
  • Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
  • Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About The Role

In this opportunity as Lead Security Engineer, you will:

  • Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line-management responsibility.
  • Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
  • Design new security processes and ways of working, revamping patching cycles and golden-image and base-image refreshes across cloud and on-prem, so the team can move fast without sacrificing safety.
  • Come to the table with ideas: identify where security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
  • Set the technical approach across the full security scope: application and open-source dependency fixes, infrastructure patching, cloud configuration and guardrails, WAF, network isolation, and secrets and machine-identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and SCA.
  • Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
  • Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About You

You're a fit for the role of Lead Security Engineer if your background includes:

  • 8+ years of hands‑on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers, plus a bachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
  • A deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers.
  • A working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
  • Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls, with multi‑cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on‑premises infrastructure.
  • A track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, rather than only executing them, with a proactive mindset for identifying and closing security gaps through automation and tooling; experience with AI‑assisted or automated security tooling is an advantage.
  • Strong judgment on balancing risk reduction against operational and customer impact.
  • Excellent written and verbal communication, comfortable operating across security, engineering, and business audiences and able to convey complex security concepts to technical and non‑technical stakeholders, with enthusiasm for collaborating with cross‑functional teams to build secure, reliable systems that scale globally.
What’s in it For You?
  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead- Product Security
Lead- Product Security

42 Gears Mobility Systems • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Lead IT Risk and Security Engineer
Lead IT Risk and Security Engineer

The Depository Trust & Clearing Corporation (DTCC) • Hyderabad

On-site
Competitive compensation
Comprehensive health and life insurance
Pension / retirement benefits
+1
Head of Security Engineering
Head of Security Engineering

Brevan Howard • Bengaluru Urban

On-site
INR 1,800,000 - 2,500,000
Cyber Security Team Lead
Cyber Security Team Lead

Cloud Counselage Pvt Ltd • Mumbai

Hybrid
INR 1,500,000 - 2,500,000
Competitive salary and benefits package
Professional development opportunities
Certification and training opportunities
Lead Security Engineer
Lead Security Engineer

Crossbow Cybersecurity • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Competitive salary and benefits
Medical Insurance
Parental Support – Maternity Leave & Paternity Leave
+3
Director, Information Security
Director, Information Security

InvestCloud India • Bengaluru

On-site
INR 7,000,000 - 12,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000
Security Engineering Manager
Security Engineering Manager

Smartstream • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Cybersecurity Engineer / Lead
Cybersecurity Engineer / Lead

Talent Inspire Consulting • Mumbai

On-site
INR 800,000 - 1,500,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000