Senior Software Engineer II (Security)

Thomson Reuters

Bengaluru

Hybrid

INR 2,500,000 - 3,800,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid Work Model
Career Development
Mental Health Days
Headspace access

Job summary

Thomson Reuters seeks a Senior Software Engineer II to design and build secure-by-default Software Supply Chain Security capabilities. You will develop SBOM generation, build provenance, artifact signing, and trusted release workflows across CI/CD, focusing on scalable back-end and VueJS front-end work.

You will collaborate with security, cloud-native security, platform engineering, and compliance teams to mature SSCS/SSCP practices and contribute to standards like SLSA, Sigstore/Cosign, SPDX,

Qualifications

  • 6+ years as a software developer with backend focus (Golang) and frontend (VueJS).
  • Expert in building robust REST APIs; GraphQL a plus.
  • Experience building secure CI/CD pipelines with GitHub Actions.
  • Familiar with automation workflows and scalability.
  • Proficient with AWS services (IAM, S3, Lambda, DynamoDB, RDS, EKS, EC2).
  • Proficient with infrastructure as code using Terraform.
  • Knowledge of SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
  • Understanding of software development methodologies and security practices.
  • Bachelor’s degree in Computer Science.

Responsibilities

  • Develop SecDevOps machinery with secure defaults and CI templates.
  • Build secure libraries, CI templates, IDE plugins to promote security adoption.
  • Develop a single pane of glass security application for product teams.
  • Lead and contribute to Software Supply Chain Security initiatives (SBOM, provenance, signing, verification).
  • Design automation and policy-driven controls for trusted builds and release governance.
  • Collaborate with security, cloud-native security, platform engineering, and compliance teams to mature SSCS/SSCP practices.
  • Write unit, integration, regression and security tests; provide technical security guidance.
  • Create development guidelines and documentation.

Skills

Golang
VueJS
REST APIs
GraphQL
GitHub Actions
AWS
Terraform
SBOM
Artifact signing
Security tooling
OWASP
Secrets management

Education

Bachelor’s degree in Computer Science

Tools

GitHub Actions
Terraform
Sigstore/Cosign
SPDX
CycloneDX
Trivy
Syft

Job description

As a Senior Software Engineer II, you will focus on designing and developing our next generation of Software Supply Chain Security capabilities. This role will help establish secure-by-default frameworks, libraries, and automation that improve how product teams generate SBOMs, capture software supply chain provenance, sign and verify artifacts, and adopt trusted build and release patterns across their S-SDLCs. The work will span IDE plugins, Continuous Integration (CI) libraries, secure defaults, secrets management helpers, and our single pane of glass product security application that product teams can easily consume.

About The Role

As a Senior Software Engineer, your Job roles include below:

  • Develop our SecDevOps machinery that provides teams with secure defaults that powers our frictionless vision of product security.
  • Work on sets of secure libraries, CI templates, IDE plugins to further adoption of security.
  • Develop our single pane of glass application, providing insights and self-service to our product teams.
  • Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, build provenance, artifact signing, signature verification, and trusted release workflows.
  • Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
  • Work with our application security and cloud native security teams to develop supply chain security toolchain.
  • Partner with application security, cloud native security, platform engineering, and compliance teams to mature SSCS/SSCP practices aligned to industry approaches such as SLSA, Sigstore/Cosign, SPDX, CycloneDX, and in-toto attestations.
  • Write all needed unit, integration, regression, security tests to consistently deliver quality and security.
  • Provide expert technical security advice to management.
  • Participate in developing software development guidelines and documentation.
About You

You are a fit for the role if you meet the below qualifications:

  • 6+years as a software developer in Golang (backend) and JavaScript (frontend – mainly VueJS) along with a solid understanding of whatever the language's frameworks/ecosystem is. You can take on any programming assignments autonomously and deliver.
  • Expert in developing robust, scalable and well documented REST APIs. Exposure to GraphQL a plus.
  • Working proficiency in building (secure) CI/CD pipelines with GitHub Actions.
  • Well-versed in automation workflows and scalability
  • Working proficiency leveraging and operating the AWS services such as (but not limited to) IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, and EC2.
  • Working proficiency building infrastructure as code with Terraform.
  • All things as-code mindset to expand to adjacent security teams.
  • Familiarity with software supply chain security concepts such as SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
  • In-depth understanding of software development methodologies.
  • Understanding and experience in dealing with secrets management (e Conjur/Vault) and other Privileged Access Management workflows a plus.
  • Familiarity with secrets detection automation, including detection, triage, remediation workflows, and integration into developer and CI/CD tooling.
  • Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows.
  • Background in security engineering, application security, DevSecOps, platform security, or product security automation strongly preferred.
  • Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement is a plus.
  • Hands-on security engineering or application security experience a plus.
  • Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate
  • Bachelor’s degree in Computer Science preferred.
What’s in it For You?
  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact:We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.

More information about Thomson Reuters can be found on thomsonreuters.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer II (Security)
Senior Software Engineer II (Security)

JobCubby • India

Hybrid
INR 1,800,000 - 2,400,000
Hybrid work model
Flex My Way
Career development
+2
Lead Security Engineer
Lead Security Engineer

PowerToFly • Bengaluru

Hybrid
INR 3,500,000 - 6,000,000
Hybrid work model
Flex My Way policy
Career development and growth
Lead Security Engineer
Lead Security Engineer

Thomson Reuters India Pvt Ltd • Bengaluru

Hybrid
INR 4,000,000 - 8,000,000
Hybrid work model
Career development and growth
Industry competitive benefits
+2
Senior Security Engineer
Senior Security Engineer

Refinitiv • India

Hybrid
INR 2,500,000 - 6,000,000
Hybrid work model
Flexible vacation
Mental health days
+3
Lead Security Engineer
Lead Security Engineer

Refinitiv • India

Hybrid
INR 2,800,000 - 5,200,000
Flexible vacation
Mental Health Days off
Headspace app
+4
Software Engineer I
Software Engineer I

PowerToFly • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Flexibility & work-life balance
Career development
+4
Senior Software Engineer
Senior Software Engineer

Thomson Reuters • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
Software Engineer I
Software Engineer I

Thomson Reuters • Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Hybrid Work Model
Flexible policies
Mental Health Days
+3
Senior Software Engineer
Senior Software Engineer

Refinitiv • India

Hybrid
INR 1,800,000 - 2,600,000
Hybrid work model
Flex My Way
Career development
Vice President, Product Engineering
Vice President, Product Engineering

Jobtailor • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Hybrid Work Model
Career Development and Growth
Industry Competitive Benefits
+1