Thomson Reuters
Senior Cloud Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Thomson Reuters
Thomson Reuters is a Canadian multinational technology conglomerate based in Toronto, Ontario. Formed in 2008 through the acquisition of Reuters Group by the Thomson Corporation, the company specializes in providing professionals with trusted content, AI-powered technology, and workflow automation solutions. With over 150 years of expertise, Thomson Reuters aims to clarify complex information landscapes, enabling users to act confidently and efficiently. The company offers a wide range of products and services tailored for legal, tax and accounting, financial, and media professionals. Its legal solutions include Westlaw, a leading legal research service, while its tax and accounting offerings help streamline compliance and audit processes. In the financial sector, Thomson Reuters provides market data, trading platforms, and risk management solutions. Additionally, the Reuters news agency delivers real-time news and information services globally. Thomson Reuters serves a diverse clientele, including legal professionals, accountants, financial institutions, corporations, and governments, supporting their decision-making and operational efficiency in regulated environments.
Security at Thomson Reuters
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Thomson Reuters' application security approach is aligned with NIST CSF and ISO/IEC 27002:2013, focusing on protecting customer data and ensuring confidentiality, integrity, and availability.
- Their philosophy prioritizes data security, especially with ethical AI, and aims to apply AI securely.
Security Team
Information not found in the search results.
Key Initiatives
- Key security areas include a secure workplace, platforms, products, brand, response, and governance, risk, and compliance.
- Application security practices involve inventorying applications, assessing business criticality, regular reviews for compliance, and maintaining security measures for internet-accessible applications, including secure development processes, pre-deployment and ongoing security assessments, and secure coding guidelines (e.g., OWASP).
- They use secure APIs, encryption, restrict production environment access, and provision dedicated databases for client data.
- Vulnerability management includes penetration testing and regular scanning, with remediation goals based on vulnerability classification.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.