Distinguished Engineer, AI Threat Defense

Relha LLC

Eagan (MN)

Hybrid

USD 198,000 - 424,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thomson Reuters is seeking a Distinguished Engineer, AI Threat Defense to lead the AI security strategy and hands-on delivery within the Cyber Defense organization. This senior individual contributor role reports to the VP of Cyber Defense and operates across SOC, CIRT, Threat Detection Engineering, Vulnerability Management, and governance functions.

The role emphasizes technical credibility, architecture, and mentorship without direct reports, driving AI-specific threat defense strategy and

Qualifications

  • 12+ years of progressive cybersecurity engineering experience at senior levels (Principal/Staff/Distinguished Engineer).
  • Deep hands-on knowledge of AI-specific attack vectors and defensive architectures.
  • Production experience governing AI systems, agentic infrastructure, MCP or equivalent integration patterns.
  • Proven experience delivering AI-assisted detection and response within a mature 24/7 SOC and/or CIRT.
  • Experience influencing security controls across SOC Operations, CIRT, Threat Detection Engineering, and Governance.

Responsibilities

  • Own Thomson Reuters' monitoring and response strategy against AI-specific attack vectors.
  • Define standards for securing AI infrastructure and ensuring monitorability.
  • Track emerging AI threats and adapt Cyber Defense capabilities accordingly.
  • Own monitoring for AI-enabled applications and integrate with SDLC to embed security.
  • Build AI-augmented detection content and analytics for AI threat patterns.
  • Integrate AI threat detection into SIEM, SOC monitoring stack, and runbooks.

Skills

AI threat defense
Security architecture
SOC / CIRT expertise
Mentorship & influence
Cross-functional collaboration

Job description

Thomson Reuters is enhancing its Cyber Defense capability in response to an AI-driven threat landscape that has fundamentally changed the speed, scale, and nature of cyberattacks.

The Distinguished Engineer, AI Threat Defense is an individual contributor and senior technical authority embedded within the existing 60+ person Cyber Defense organization. Reporting to the VP of Cyber Defense, this individual will strengthen AI-specific threat defense strategy and build AI-augmented detection and response capability into the existing Security Operations Center (SOC) and Cyber Incident Response Team (CIRT).

This role has no direct reports or management authority. Instead, the individual will drive impact through technical credibility, architecture, hands‑on engineering, influence, and mentorship across SOC Operations, CIRT, Threat Detection Engineering, Vulnerability Management, Attack Surface Reduction, and Cyber Threat Management.

The role also owns two areas where the current organization lacks a dedicated deep technical owner: the technical strategy against AI‑specific attack vectors and the hands‑on architecture and delivery of AI‑augmented detection and response within the existing SOC and CIRT.

What You’ll Do

Own Thomson Reuters' monitoring and response strategy against AI-specific attack vectors including prompt injection, Model Context Protocol (MCP) exploitation, agentic system compromise, deepfake‑enabled social engineering, and AI‑assisted reconnaissance.

Partner with Security Engineering and Architecture to define standards for securing AI infrastructure and ensuring it can be effectively monitored and defended.

Track emerging offensive AI capabilities, adversary tooling, published research, and threat‑actor adoption of AI so Cyber Defense capabilities evolve ahead of emerging threats.

Protect Thomson Reuters AI Applications and Systems
Drive monitoring and defenses for AI-specific threat classes including:
  • Direct and indirect prompt injection
  • Jailbreaks and guardrail bypass
  • Sensitive-information and system-prompt disclosure
  • Unsafe model output and downstream execution
  • Excessive agency and MCP/tool abuse
  • Model and data poisoning
  • Model, prompt, and intellectual‑property theft

Own technical monitoring and response for Thomson Reuters AI‑enabled applications, features, and agentic services while partnering with Product Engineering, Security Engineering & Architecture, and AppSec to embed security directly into the software development lifecycle.

Build AI-Augmented Detection and Response

Build AI‑augmented detection content and analytics for AI‑specific attack patterns.

Integrate AI threat detection into the existing SIEM, detection engineering, and SOC monitoring stack.

Build AI‑assisted playbooks and runbooks and integrate them into existing CIRT and SOAR workflows.

Serve as the principal technical architect for incorporating AI capabilities into the existing 24/7 SOC and CIRT rather than creating a separate security function.

Design automated workflows for AI-related detection, triage, investigation, and response.

Increase analyst productivity while maintaining human‑in‑the‑loop controls, audit trails, and rollback capability.

Drive adoption across SOC Operations, CIRT, Threat Detection Engineering, Vulnerability Management, and Attack Surface Reduction.

Technical Leadership & Influence

Act as the recognized technical authority for AI threat defense across the Cyber Defense organization.

Provide hands‑on mentorship and technical uplift to SOC, CIRT, engineering, and security professionals without formal management responsibility.

Represent Cyber Defense externally with industry groups, customers, and regulators.

Influence engineers and analysts through technical reviews, direct collaboration, architecture guidance, and knowledge sharing.

About You

You are a deeply technical cybersecurity leader who can operate at a Distinguished Engineer level without relying on formal organizational authority.

You combine strong hands‑on Cyber Defense expertise with practical knowledge of AI systems, AI‑specific attack vectors, and production security architecture.

You are comfortable working across mature enterprise security organizations and can influence senior executives, engineers, architects, SOC teams, incident responders, and other technical stakeholders.

You are equally comfortable developing strategy, architecting systems, building technical capabilities, mentoring engineers, and representing the organization externally.

Required Skills / Qualifications

12+ years of progressive cybersecurity engineering experience, including experience operating at Principal, Staff, or Distinguished Engineer level within a large, complex enterprise.

Deep hands‑on knowledge of AI‑specific attack vectors and defensive architectures.

Production experience governing AI systems, agentic infrastructure, MCP or equivalent integration patterns.

Proven experience architecting or delivering AI‑assisted detection and response within a mature 24/7 SOC and/or CIRT.

Experience enhancing an established security organization rather than simply building a new function from scratch.

Demonstrated ability to drive adoption of detection capabilities and security controls across:

  • SOC Operations
  • CIRT
  • Threat Detection Engineering
  • Vulnerability Management

Ability to influence technical teams through credibility rather than direct reporting authority.

Exceptional communication skills, including the ability to explain AI‑related security risk to senior executives and technical audiences.

Experience within a regulated, multi‑segment enterprise requiring coordination across legal, compliance, procurement, and governance organizations.

Preferred Qualifications

Experience in financial services, legal technology, or professional information services.

Experience embedding major technical capabilities into an existing mature security operations organization.

Familiarity with frontier AI vulnerability research programs such as Anthropic Project Glasswing / Claude Code Security or comparable agentic vulnerability‑discovery initiatives.

Hands‑on experience building or operating agentic AI systems using multiple LLMs, including open‑weight and hosted/frontier models.

Experience integrating AI capabilities with SAST/AppSec tooling and vulnerability‑management workflows.

Working knowledge of safely operating open‑weight or less‑restricted AI models for authorized internal security research.

Published research, conference speaking, or active participation within AI security research communities.

Relevant certifications such as CISSP, CISM, advanced AI/ML security, cloud security (AWS/Azure/GCP), or detection‑engineering credentials.

What’s in it For You?

Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office‑based roles while delivering a seamless experience that is digitally and physically connected.

Flexibility & Work‑Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work‑life balance.

Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real‑world solutions. Our Grow My Way programming and skills‑first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI‑enabled future.

Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company‑wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.

Culture: Globally recognized, award‑winning reputation for inclusion and belonging, flexibility, work‑life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.

Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro‑bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.

Making a Real‑World Impact:We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match. In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave. These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws. Finally, Thomson Reuters offers the following additional benefits: optional hospital, accident and sickness insurance paid 100% by the employee; optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement; access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan; commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.

Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position. The base compensation range varies across locations.

Eligible office location(s) for this role include one or more of the following: New York City, San Los Angeles, and/or Irvine, CA; McLean, VA; Washington, DC. The base compensation range for the role in any of those locations is $228,000 USD - $424,000 USD.

For any eligible US locations, unless otherwise noted, the base compensation range for this role is $198,200 USD - $368,000 USD.

Base pay is positioned within the range based on several factors including an individual’s knowledge, skills and experience with consideration given to internal equity. Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs.

This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance.

About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug‑free workplace.

Thomson Reuters makes reasonable accommodations for applicants with disabilities, including veterans with disabilities, and for sincerely held religious beliefs in accordance with applicable law. If you reside in the United States and require an accommodation in the recruiting process, you may contact our Human Resources Department at HR.Leave-Expert@thomsonreuters.com. Disability accommodations in the recruiting process may include things like a sign language interpreter, making interview rooms accessible, providing assistive technology, or other relevant accommodations. Please note this email is not intended for general recruitment questions and we will promptly respond to inquiries regarding accommodations. More information on requesting an accommodation here.

Learn more on how to protect yourself from fraudulent job postings here.

More information about Thomson Reuters can be found on thomsonreuters.com
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Distinguished Engineer, AI Threat Defense
Distinguished Engineer, AI Threat Defense

Thomson Reuters • Frisco (TX)

Hybrid
USD 198,000 - 368,000
Hybrid Work Model
Tuition Reimbursement
Employee Stock Purchase Plan
+1
Distinguished Engineer, AI Threat Defense
Distinguished Engineer, AI Threat Defense

Thomson Reuters • Frisco (TX)

On-site
USD 198,000 - 424,000
Hybrid Work Model
Competitive Benefits
Distinguished Engineer, AI Threat Defense
Distinguished Engineer, AI Threat Defense

Socket.dev • Town of Texas (WI)

On-site
USD 198,000 - 368,000
Hybrid Work Model
Career Growth
Industry Benefits
+3
Distinguished Engineer, AI Threat Defense
Distinguished Engineer, AI Threat Defense

Thomson Reuters • Eagan (MN)

Hybrid
USD 198,000 - 424,000
Hybrid Work Model
Medical benefits
Tuition reimbursement
+1
Senior Software Engineer, AI
Senior Software Engineer, AI

Socket.dev • Minnesota

Hybrid
USD 110,000 - 204,000
Hybrid Work Model
Flex My Way
Career Development
+4
Senior Software Engineer, AI
Senior Software Engineer, AI

Relha LLC • Eagan (MN), Northern (KY)

Hybrid
USD 110,000 - 204,000
Hybrid Work Model
401(k) matching
Vice President, Technology - M&A Integration
Vice President, Technology - M&A Integration

Socket.dev • New York (NY), Town of Texas (WI)

Hybrid
USD 171,000 - 318,000
Hybrid work model
Competitive benefits
Paid time off
Staff Software Engineer I
Staff Software Engineer I

Relha LLC • Eagan (MN), Northern (KY)

Hybrid
USD 118,000 - 220,000
Hybrid work model
Mental health days off
Tuition reimbursement
+1
Lead Software Engineer I
Lead Software Engineer I

Relha LLC • Eagan (MN)

Hybrid
USD 118,000 - 220,000
Health benefits
401k with company match
Tuition reimbursement
Senior Software Engineer - AI (Materia AI)
Senior Software Engineer - AI (Materia AI)

Thomson Reuters • Eagan (MN)

On-site
USD 110,000 - 204,000