
As a Senior Software Engineer II, you will focus on designing and developing our next generation of Software Supply Chain Security capabilities. This role will help establish secure-by-default frameworks, libraries, and automation that improve how product teams generate SBOMs, capture software supply chain provenance, sign and verify artifacts, and adopt trusted build and release patterns across their S-SDLCs. The work will span IDE plugins, Continuous Integration (CI) libraries, secure defaults, secrets management helpers, and our single pane of glass product security application that product teams can easily consume.
About the role:
As a Senior Software Engineer, your Job roles include below:
Develop our SecDevOps machinery that provides teams with secure defaults that powers our frictionless vision of product security.
Work on sets of secure libraries, CI templates, IDE plugins to further adoption of security.
Develop our single pane of glass application, providing insights and self-service to our product teams.
Lead and contribute to Software Supply Chain Security initiatives, including SBOM generation and consumption, build provenance, artifact signing, signature verification, and trusted release workflows.
Design automation and policy-driven controls that help teams prove what was built, where it came from, and whether it can be trusted before deployment.
Work with our application security and cloud native security teams to develop supply chain security toolchain.
Partner with application security, cloud native security, platform engineering, and compliance teams to mature SSCS/SSCP practices aligned to industry approaches such as SLSA, Sigstore/Cosign, SPDX, CycloneDX, and in-toto attestations.
Write all needed unit, integration, regression, security tests to consistently deliver quality and security.
Provide expert technical security advice to management.
Participate in developing software development guidelines and documentation.
About You:
You are a fit for the role if you meet the below qualifications:
6+years as a software developer in Golang (backend) and JavaScript (frontend – mainly VueJS) along with a solid understanding of whatever the language's frameworks/ecosystem is. You can take on any programming assignments autonomously and deliver.
Expert in developing robust, scalable and well documented REST APIs. Exposure to GraphQL a plus.
Working proficiency in building (secure) CI/CD pipelines with GitHub Actions.
Well-versed in automation workflows and scalability
Working proficiency leveraging and operating the AWS services such as (but not limited to) IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, and EC2.
Working proficiency building infrastructure as code with Terraform.
All things as-code mindset to expand to adjacent security teams.
Familiarity with software supply chain security concepts such as SBOMs, artifact signing, provenance attestations, dependency integrity, trusted builds, and release governance.
In-depth understanding of software development methodologies.
Understanding and experience in dealing with secrets management (e.g Conjur/Vault) and other Privileged Access Management workflows a plus.
Familiarity with secrets detection automation, including detection, triage, remediation workflows, and integration into developer and CI/CD tooling.
Experience with software supply chain security tooling and standards such as SLSA, Sigstore/Cosign, in-toto, SPDX, CycloneDX, Syft, Trivy, GitHub Actions provenance, or related artifact attestation and verification workflows.
Background in security engineering, application security, DevSecOps, platform security, or product security automation strongly preferred.
Experience implementing guardrails for secure CI/CD, dependency governance, container image trust, vulnerability management, or policy-as-code enforcement is a plus.
Hands-on security engineering or application security experience a plus.
Deep understanding of OWASP Top 10 vulnerabilities, and how best to mitigate
Bachelor’s degree in Computer Science preferred
#LI-VGA1
What’s in it For You?
About Us
Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.
As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law. More information on requesting an accommodation here.
Learn more on how to protect yourself from fraudulent job postings here.
More information about Thomson Reuters can be found on thomsonreuters.com.
From $199 · 3,500+ companies hire here