Posted:
6/13/2024, 5:00:00 PM
Location(s):
Texas, United States ⋅ New York, New York, United States ⋅ New York, United States ⋅ Dallas, Texas, United States
Experience Level(s):
Senior
Field(s):
IT & Security ⋅ Software Engineering
Workplace Type:
Hybrid
Looking forward to advance your career and Upgrade Yourself? We are growing and we are hiring, come join us for a great future and an exciting journey with an Enterprise which has demonstrated business growth year on year with a successful track record of employee satisfaction.
Lead individual Enterprise Security Architect role for complex security functions reducing risk, improving defensive capabilities, and mitigating cyber threats to both Thomson Reuters and its customers.
About the role:
In this opportunity as Technical Security Architect, you will:
Maintain a deep understanding of core public cloud security disciplines, with close attention to developing industry trends in the context of networking, identity, and platform security technologies
Serve as the Cloud Security Lead in the design, implementation, and integration phases of business products and services to meet business security requirements, address corporate risks and exposures in cloud-based solutions
Maintain a deep understanding of capabilities and patterns to controlling access to the public cloud through authentication, authorization, access policy, and secrets management
Collaborate with business and technology peers to understand business goals, use cases for cloud-native deployments or lift-and-shift
Thoroughly interact with DevOps, platform engineering team, Network security engineers, and Identity build and run teams. Should be able to guide the teams to drive results and maturity
Perform threat modelling on the cloud-based scenarios and able to apply the principles to secure the cloud platforms
Drive security design principles and requirements to enhance ISRMs ability to streamline the implementation of security controls into new and existing solutions
Should be able to enforce the security principles in live scenarios by working closing with landing zone teams
Serve as a cloud security subject matter expert during discussions and meetings with key stakeholders within the business unit and infrastructure teams
Interact with peers, project teams, technical specialists, and other senior members of the company to provide advice on cloud security and identity- related security.
Provide technical security expertise, including communicating security architectural decisions, benefits, risks, and other activities including security requirement definition, and facilitation of security testing and management of residual risk with the product or application teams
Develop and maintain security frameworks, consisting of appropriate controls from NIST CSF, PCI-DSS, HIPAA, and other relevant industry documentation
Authoritatively assess, analyse and recommend security best practices and controls based on TR standard based and industry aligned regulatory requirements specific security controls and guidelines while integrating and onboarding new technologies and platforms within TR DC IT cloud network environments to support various TR initiatives and business objectives - These can be new age digital initiatives such as hybrid / multi-cloud platforms / AI - ML based solutions or technologies in compliance with global data privacy / data protection standards
About you:
You're a fit for the role of Technical Security Architect if your background includes:
Minimum 10+ Years experience in a security-related domain and technologies
Minimum 8+ Years experience in security architecture space
Minimum 5+ Years of Hands-On experience in the cloud security platforms such as AWS, Azure or Google (preferably engineering)
Hands-on capability on Cloud platforms and migrating workloads from Data Center to Cloud Platforms
Should be conversant with most of the Cloud Platform Security domains
Should have good knowledge of security containers and hands-on experience on SecDevOps principles and has a good handle on end-to-end Sec Dev Ops processes.
Good understanding of Technologies such Web Application Firewall, Key Management, Secrets Handling, knowledge on the tools which provide services like Single Sign-On, MFA, enabling data security principles in the cloud platforms. Etc Technology and hands-on exposure to Active Directory, Palo Alto Prisma, Advanced firewalls, virtual directory services, etc
Bachelor’s degree in Computer Science, Computer Engineering, or related field required
Certification like AWS Security Specialty, Google Cloud Platform Engineer with focus on security, Azure Security, etc are preferred
Technical understanding of cloud-native architecture and engineering best practices
CISSP or equivalent certification are preferred
Has demonstrated experience in
Cyber Security Controls Definition & Solutions Architecture Design based on industry specific and regulatory standards & compliances such as ISO27001, NIST 800-53, PCI-DSS, HIPAA and Data Privacy Standards viz GDPR, CCPA etc
Pre-acquisition / Pre-Onboarding - 3rd Party Integration Risk Assessment & Due Diligence of vendor technologies
Cloud security architecture reviews, across cloud / hybrid / multi-cloud platforms
Design & ensure delivery of high quality cyber security processes and tools across cloud infrastructure covering but not limited to –
Secure business Process & Applications Integration;
3rd Party Vendor Integration Risk Assessment;
Network Security – Segmentation & Zoning across environments, regions, VPCs and security groups;
Secure Access / Network Connect;
Remote Access VPN & Private Links / DirectConnect etc;
Perimeter Protection - Layer 4-7 Security – WAF/LB/ADDoS and Web/Email/API Gateway;
Secure End Points and Secure Workspace; Secure Hosts and Compute Workloads; Containers / Microservices Security;
Identity Access Governance; Secure Access for Employees, Vendors & Customers;
Data Privacy / Protection – Encryption / Anonymization / Tokenization etc;
Logging, Auditing and Monitoring; Security Incident Response Management;
Cyber Threat Intelligence; Threat Hunting / Threat Management;
Insider Threats and Breach Risk Detection and Cyber Forensic;
Defensive Security and Engineering;
Vulnerability and Threat Management thereby reducing attack surface improving cyber risk posture of enterprise following Secure Change Configuration management Processes
Authoritatively drive continuous improvements in key cyber defence capabilities by streamlining technology acquisition and deployment, engineering solutions and driving deployment of innovative processes and controls
Designs and executes cyber security plans, activities, and policies that protect Thomson Reuters’ information infrastructure, customer base, and products.
Assists in maturing cyber defense capabilities, enforces organizational security principles and industry recognized best practices, and demonstrates responsible resource management.
Works independently or leads functional project teams to implement security controls, monitor and mitigate threats, tune and optimize security appliances, coordinate with enterprise information services teams, interface with product teams, or other tasks associated with cyber defence and cyber fusion centers.
Understands and have proven experience around cloud and cloud security architectures and related compliances and standards. The role demands knowledge and experience around cloud security architectures and solutions design, review and risk assessment
#LI-LP2
What's in it For You?
You will join our inclusive culture of world-class talent, where we are committed to your personal and professional growth through:
Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected
Wellbeing: Comprehensive benefit plans; flexible and supportive benefits for work-life balance: flexible vacation, two company-wide Mental Health Days Off; work from another location for up to a total of 8 weeks in a year, 4 of those weeks can be out of the country and the remaining in the country, Headspace app subscription; retirement, savings, tuition reimbursement, and employee incentive programs; resources for mental, physical, and financial wellbeing.
Culture: Globally recognized and award-winning reputation for equality, diversity and inclusion, flexibility, work-life balance, and more.
Learning & Development: LinkedIn Learning access; internal Talent Marketplace with opportunities to work on projects cross-company; Ten Thousand Coffees Thomson Reuters café networking.
Social Impact: Ten employee-driven Business Resource Groups; two paid volunteer days annually; Environmental, Social and Governance (ESG) initiatives for local and global impact.
Purpose Driven Work: We have a superpower that we’ve never talked about with as much pride as we should – we are one of the only companies on the planet that helps its customers pursue justice, truth and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
Do you want to be part of a team helping re-invent the way knowledge professionals work? How about a team that works every day to create a more transparent, just and inclusive future? At Thomson Reuters, we’ve been doing just that for almost 160 years. Our industry-leading products and services include highly specialized information-enabled software and tools for legal, tax, accounting and compliance professionals combined with the world’s most global news services – Reuters. We help these professionals do their jobs better, creating more time for them to focus on the things that matter most: advising, advocating, negotiating, governing and informing.
We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments that celebrate diversity and inclusion. At a time when objectivity, accuracy, fairness and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.
Accessibility
As a global business, we rely on diversity of culture and thought to deliver on our goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity/Affirmative Action Employer providing a drug-free workplace.
We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law.
Protect yourself from fraudulent job postings click here to know more.
More information about Thomson Reuters can be found on https://thomsonreuters.com.
Website: https://thomsonreuters.com/
Headquarter Location: Toronto, Ontario, Canada
Employee Count: 10001+
Year Founded: 1977
IPO Status: Public
Industries: Advice ⋅ Analytics ⋅ Financial Services ⋅ Management Consulting ⋅ Professional Services ⋅ Risk Management ⋅ Software