Thomson Reuters

Senior Software Engineer II (Security)

Thomson Reuters · Bengaluru, Karnataka, India

Software Development · 10,001+ employees

20 h ago
Senior (5-10 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will design and develop secure-by-default frameworks, libraries, and automation to enhance software supply chain security. This includes building CI/CD machinery, managing artifact provenance, and developing a centralized security application for product teams.

What they look for

Golang JavaScript VueJS REST APIs GraphQL GitHub Actions AWS Terraform Software supply chain security SBOM CI/CD Secrets management SLSA Sigstore Cosign In-toto

Requirements

Candidates must have 6+ years of experience in Golang and JavaScript with a strong background in CI/CD pipelines and AWS cloud services. Proficiency in software supply chain security concepts and infrastructure-as-code tools like Terraform is required.

Benefits

Flexible vacation Mental health days Headspace app access Retirement savings Tuition reimbursement Employee incentive programs Volunteer days off Flexible work arrangements

Full description

As a Senior Software Engineer II, you will focus on designing and developing our next generation of Software Supply Chain Security capabilities. This role will help establish secure-by-default frameworks, libraries, and automation that improve how product teams generate SBOMs, capture software supply chain provenance, sign and verify artifacts, and adopt trusted build and release patterns across their S-SDLCs. The work will span IDE plugins, Continuous Integration (CI) libraries, secure defaults, secrets management helpers, and our single pane of glass product security application that product teams can easily consume.

About the role: 

As a Senior Software Engineer, your Job roles include below:

  • Develop our SecDevOps machinery that provides teams with secure defaults that powers our frictionless vision of product security. 
  • Work on sets of secure libraries, CI templates, IDE plugins to further adoption of security. 
  • Develop our single pane of glass application, providing insights and self-service to our product teams. 
  • Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, build provenance, artifact signing, signature verification, and trusted release workflows.
  • Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
  • Work with our application security and cloud native security teams to develop supply chain security toolchain. 
  • Partner with application security, cloud native security, platform engineering, and compliance teams to mature SSCS/SSCP practices aligned to industry approaches such as SLSA, Sigstore/Cosign, SPDX, CycloneDX, and in-toto attestations.
  • Write all needed unit, integration, regression, security tests to consistently deliver quality and security. 
  • Provide expert technical security advice to management. 
  • Participate in developing software development guidelines and documentation. 

  About You:

You are a fit for the role if you meet the below qualifications: 

  • 6+years as a software developer in Golang (backend) and JavaScript (frontend – mainly VueJS) along with a solid understanding of whatever the language's frameworks/ecosystem is. You can take on any programming assignments autonomously and deliver. 
  • Expert in developing robust, scalable and well documented REST APIs. Exposure to GraphQL a plus. 
  • Working proficiency in building (secure) CI/CD pipelines with GitHub Actions.
  • Well-versed in automation workflows and scalability
  • Working proficiency leveraging and operating the AWS services such as (but not limited to) IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, and EC2. 
  • Working proficiency building infrastructure as code with Terraform. 
  • All things as-code mindset to expand to adjacent security teams. 
  • Familiarity with software supply chain security concepts such as SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
  • In-depth understanding of software development methodologies. 
  • Understanding and experience in dealing with secrets management (e.g Conjur/Vault) and other Privileged Access Management workflows a plus. 
  • Familiarity with secrets detection automation, including detection, triage, remediation workflows, and integration into developer and CI/CD tooling.
  • Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows.
  • Background in security engineering, application security, DevSecOps, platform security, or product security automation strongly preferred.
  • Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement is a plus.
  • Hands-on security engineering or application security experience a plus. 
  • Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate 
  • Bachelor’s degree in Computer Science preferred 

  

#LI-VGA1

What’s in it For You?

  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.

Learn more on how to protect yourself from fraudulent job postings here.

More information about Thomson Reuters can be found on thomsonreuters.com.