Thomson Reuters

Senior Cloud Security Engineer

Thomson Reuters Bengaluru, Karnataka, India

Software Development · 10,001+ employees

13 h ago
security Mid (2-5 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will coordinate remediation efforts across business units to address cloud security findings and vulnerabilities. Additionally, you will partner with engineering teams to implement preventative guardrails and ensure security compliance across multi-cloud environments.

What they look for

Cloud security Vulnerability management AWS Azure GCP OCI Wiz Prisma Cloud Terraform CloudFormation Python Bash Kubernetes ServiceNow Stakeholder management Risk assessment

Requirements

The role requires at least 3 years of experience in cloud security, vulnerability management, or security remediation programs. Candidates must possess strong technical knowledge of multi-cloud environments and the ability to translate security findings into actionable remediation plans.

Benefits

Flexible hybrid work model Flexible vacation Mental health days Headspace app access Retirement savings Tuition reimbursement Employee incentive programs Volunteer days

Full description

Thomson Reuters’ Information Security and Risk Management (ISRM) organization is seeking an experienced Senior Cloud Security Engineer to join our Cloud Security Engineering team. In this role, you’ll drive remediation outcomes across a complex, multi-cloud estate, partnering with application, platform, and service teams to turn security findings into clear, prioritized, and achievable remediation plans and preventative guardrails.

You will be the connective tissue between Security Engineering and distributed engineering teams, playing a crucial role in fostering trust and collaboration across the business to mitigate cloud security risks.

About the Role   

In this opportunity as a Senior Cloud Security Engineer you will: 

  • Own remediation coordination and follow-through across TR business units to drive timely closure of cloud security findings.
  • Triage and operationalize findings from Wiz, across domains such as cloud misconfigurations, vulnerabilities, external exposures, data security risks, and AI risks, ensuing the right teams have the right context to take action.
  • Partner with engineering, architecture, and landing zone teams to confirm scope, reduce false positives, and ensure remediation guidance is actionable and aligned to cloud patterns.
  • Track and report remediation performance, with an emphasis on backlog burndown, trend analysis, and executive-ready status updates.
  • Collaborate across ISRM with peer security teams to strengthen business engagement strategies, standardizing communications, and identifying automation opportunities for workflow efficiency. 

About You  

You’re a fit for the role of Senior Cloud Security Engineer if you have the following required qualifications:

  • Bachelor’s degree preferred and 3+ years in cloud security, cloud operations, vulnerability management, or security remediation programs.
  • Strong understanding of cloud security fundamentals and common misconfiguration and vulnerability classes in AWS, Azure, GCP, and/or OCI (multi-cloud experience strongly valued).
  • Demonstrated ability to triage findings, drive remediation across multiple teams, and keep work moving forward through strong follow-up and stakeholder management.
  • Experience translating technical findings into clear risk narratives and remediation plans for engineering audiences.
  • Excellent written and verbal communication; comfort facilitating working sessions, aligning on action plans, and managing timelines.
  • Familiarity with IaC technologies and delivery pipelines (Terraform/CloudFormation; CI/CD concepts and common tooling like GitHub workflows/CodePipeline/CodeDeploy.
  • Experience working with CSPM/CNAPP platforms (Wiz, Prisma Cloud, etc.) and driving remediation outcomes.
  • Basic scripting/automation skills (e.g. Python, Bash) to streamline operational tasks.
  • Familiarity with security compliance frameworks (NIST 800-53, FedRAMP, CIS, ISO 27001) and how they influence remediation prioritization.
  • Familiarity with container and Kubernetes ecosystems (e.g. image scanning concepts, runtime v build time issues).
  • Background working with ServiceNow for ticketing, workflow management, and remediation tracking.
  • Familiarity with FedRAMP authorization and continuous monitoring requirements.

#LI-VGA1

What’s in it For You?

  • Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work-life balance.
  • Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions. Our Grow My Way programming and skills-first approach ensures you have the tools and knowledge to grow, lead, and thrive in an AI-enabled future.
  • Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
  • Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more. We live by our values: Obsess over our Customers, Compete to Win, Challenge (Y)our Thinking, Act Fast / Learn Fast, and Stronger Together.
  • Social Impact: Make an impact in your community with our Social Impact Institute. We offer employees two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives.
  • Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

About Us

Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.

Learn more on how to protect yourself from fraudulent job postings here.

More information about Thomson Reuters can be found on thomsonreuters.com.

Similar roles