Senior Application Security Engineer

hace 4 semanas


Ciudad de México Thomson Reuters A tiempo completo

Senior Application Security Engineer
As a Senior Application Security engineer within Information Security and Risk Management (ISRM) Product Security, you will join us on our mission to bring frictionless and continuous security to our engineering teams who build our products to securely “Inform The Way Forward”. We promise you won’t be bored with all our bold security engineering initiatives You will be working on most S-SDLC activities and controls that will ensure our applications are designed and implemented with regards to the highest level of security standards, as well as nurturing our security champions’ program comprised of 100s of engineers and influencers.

About the Role   
As a Senior Application Security Engineer , you will:

Work closely with teams across multiple functions across the organization, foster our engineering-centric security culture, and bring palatable security to the masses. Be a subject matter expert on our cross-functional security projects with end-to-end ownership on topics such as CI/CD integration and automation, SAST/DAST/SCA security, API security, vulnerability disclosure program/bug bounties and more. Lead and guide threat modeling sessions and secure remediation planning discussions with application teams. Contribute to building and scaling our Software Supply Chain Security endeavors. Contribute to security tools development and automation as well as related actionable metrics to enhance TR’s Secure Software Development Life Cycle (S-SDLC). Create/maintain PowerBI apps/metrics, as well as security guidance and documentation. 


About you
You’re a fit for the role of Senior Application Security Engineer if your background includes:

4+ years of significant applied application security experience. You can prove your scripting abilities and can develop solutions dealing with remote APIs. (Preferred languages/tools: Bash, Python, GoLang, Postman). Deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls.  You have experience around SAST, DAST and SCA scanning tools (Veracode, Checkmarx, Semgrep, etc.) and you are able to help developers cut through the noise and prioritize the true positives.  Experience in building secure CI/CD pipelines (GitHub Actions preferred). All things as-code mindset to expand to security teams.  Understanding of application and cloud and other security frameworks such as OWASP’s, CIS and NIST CSF/SSDF. Experience with OWASP SAMM or BSIMM a plus. Proven success collaborating with many product development groups to instill security.  Experience with Snyk.


What’s in it For You?
You will join our inclusive culture of world-class talent, where we are committed to your personal and professional growth through:
Hybrid Work Model: We’ve adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
Culture: Globally recognized and award-winning reputation for equality, diversity and inclusion, flexibility, work-life balance, and more.
Wellbeing: Comprehensive benefit plans; flexible and supportive benefits for work-life balance: two company-wide Mental Health Days Off; work from another location for up to a total of 8 weeks in a year, 4 of those weeks can be out of the country and the remaining in the country,
 Headspace app subscription; retirement, savings, tuition reimbursement, and employee incentive programs; resources for mental, physical, and financial wellbeing.
 Learning & Development: LinkedIn Learning access; internal Talent Marketplace with opportunities to work on projects cross-company; Ten Thousand Coffees Thomson Reuters café networking.
Social Impact: Nine employee-driven Business Resource Groups; two paid volunteer days annually; Environmental, Social and Governance (ESG) initiatives for local and global impact.
Purpose Driven Work: We have a superpower that we’ve never talked about with as much pride as we should – we are one of the only companies on the planet that helps its customers pursue justice, truth and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.
#LI-IL1


Do you want to be part of a team helping re-invent the way knowledge professionals work? How about a team that works every day to create a more transparent, just and inclusive future? At Thomson Reuters, we’ve been doing just that for almost 160 years. Our industry-leading products and services include highly specialized information-enabled software and tools for legal, tax, accounting and compliance professionals combined with the world’s most global news services – Reuters. We help these professionals do their jobs better, creating more time for them to focus on the things that matter most: advising, advocating, negotiating, governing and informing.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments that celebrate diversity and inclusion. At a time when objectivity, accuracy, fairness and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward. 

Accessibility 

As a global business, we rely on diversity of culture and thought to deliver on our goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity/Affirmative Action Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law.

More information about Thomson Reuters can be found on .



  • Ciudad de México, Ciudad de México Refinitiv A tiempo completo

    Senior Application Security Engineer page is loaded Senior Application Security Engineer Apply remote type Remote Job: Hybrid locations MEX-Distrito Federal-Reforma 26 time type Full time posted on Posted 3 Days Ago job requisition id JREQ177031 Senior Application Security EngineerAs a Senior Application Security engineer within Information Security and...


  • Ciudad de México, Ciudad de México Refinitiv A tiempo completo

    Senior Application Security Engineer page is loaded Senior Application Security Engineer Apply remote type Remote Job: Hybrid locations MEX-Distrito Federal-Reforma 26 time type Full time posted on Posted 3 Days Ago job requisition id JREQ177031 Senior Application Security Engineer As a Senior Application Security engineer within Information Security...


  • Ciudad de México, Ciudad de México Tiger Text A tiempo completo

    Senior Application Security EngineerAs a Senior Application Security engineer within Information Security and Risk Management (ISRM) Product Security, you will join us on our mission to bring frictionless and continuous security to our engineering teams who build our products to securely Inform The Way Forward .We promise you won't be bored with all our bold...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    Senior Application Security Engineer As a Senior Application Security engineer within Information Security and Risk Management (ISRM) Product Security, you will join us on our mission to bring frictionless and continuous security to our engineering teams who build our products to securely "Inform The Way Forward". We promise you won't be bored with all...


  • Ciudad de México Backbase Inc. A tiempo completo

    Join the Big Shift at Backbase ENGAGE Americas Register now Looking for a journey instead of a job? Then let’s talk! We are THE pioneers in banking tech. We see opportunities and take the leap. Having the guts to push limits and break barriers to make things happen. We learn and reinvent ourselves for maximum impact, never giving up. We are creators,...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the Role As a Senior Application Security Engineer , you will: Work closely with teams across multiple functions across the organization, foster our engineering-centric security culture, and bring palatable security to the masses. Be a subject matter expert on our cross-functional security projects with end-to-end ownership on topics such as...


  • Ciudad de México Orbia A tiempo completo

    Orbia Advance Corporation is a Purpose-led company with big aspirations. We are out to advance life around the world while maximizing value to our shareholders, customers and employees. The Company is passionate about the topics that define how people will live and thrive tomorrow: the future of cities, buildings, agriculture, and materials. Orbia Advance...


  • Ciudad de México, Ciudad de México Orbia A tiempo completo

    Orbia Advance Corporation is a Purpose-led company with big aspirations. We are out to advance life around the world while maximizing value to our shareholders, customers and employees.The Company is passionate about the topics that define how people will live and thrive tomorrow: the future of cities, buildings, agriculture, and materials. Orbia Advance...


  • Ciudad de México, Ciudad de México Ford Motor Company A tiempo completo

    We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we're all a part of something bigger than ourselves. Are you ready to change the way the world moves? Enterprise Technology plays a critical part in shaping the future of mobility. If you're looking for the...


  • Ciudad de México, Ciudad de México Security Bank & Trust Co. A tiempo completo

    The role of a Security Solutions Engineer at Cover Genius involves enhancing the company's security posture through a rigorous understanding of information security standards and the development of security solutions. Key responsibilities include writing risk management policies, assessing and remediating cloud infrastructure security, assisting engineering...


  • Ciudad de México MetaMap A tiempo completo

    We’re living at the dawn of a borderless world, but most people still don't have the tools needed to engage in critical high-trust services including everything from access to financial services, to sharing assets in peer-to-peer marketplaces, and even managing talent. At MetaMap, our work is centered on addressing this gap by building an identity data...


  • Ciudad de México, Ciudad de México Security Bank & Trust Co. A tiempo completo

    Cover Genius is seeking a Security Systems Engineer responsible for enhancing the company's security posture. This involves writing Risk Management Framework-based policies, assessing and remediating cloud infrastructure security, and helping implement a "shift left" security culture. Required familiarity with cloud platforms, identity providers, and...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Capability Center is currently hiring a: Application Security Testing Engineer Role Description: Application Security Testing Engineer is responsible of the Application Security toolset administration for the Security Testing BTO Team, providing global support to Zurich IT projects and to enable them to perform SAST, DAST and IAST toolset...


  • Naucalpan de Juárez, México Zurich Insurance Company A tiempo completo

    Zurich Capability Center is currently hiring a: Application Security Testing Engineer Role Description: Application Security Testing Engineer is responsible of the Application Security toolset administration for the Security Testing BTO Team, providing global support to Zurich IT projects and to enable them to perform SAST, DAST and IAST toolset...


  • Ciudad de México Signifyd A tiempo completo

    Please apply in English About the role As a Senior Cloud Security Engineer at Signifyd, you will work to control and improve security outcomes across the company. You will operate at the front line of risk, identifying vulnerabilities and threats, and collaborate cross-functionally across the organization to implement defenses. As a core member of our...


  • México Skyhigh Security A tiempo completo

    Mexico City, Distrito Federal, Mexico Job ID: JR0032447 Job Title: Web Security Gateway Implementation Engineer Role Overview: As a Web Security Gateway Implementation Engineer, you will design and deploy Cloud Security solutions across large enterprise customers. You will follow best practices across the Cloud Security and Governance solutions for one...

  • Security Engineer

    hace 4 semanas


    Ciudad de México Stori Card - MX A tiempo completo

    You will Design and cybersecurity controls for cloud architecture (Cloud, endpoints, AWS) Follow up on control development and implementation Perform assessments on infrastructure and application controls to ensure compliance with security policy and security architecture requirements Requirements Bachelor’s Degree in Computer Science, Cyber Security,...

  • Security Engineer

    hace 3 días


    Ciudad de México, Ciudad de México Stori Card - MX A tiempo completo

    You will Design and cybersecurity controls for cloud architecture (Cloud, endpoints, AWS) Follow up on control development and implementation Perform assessments on infrastructure and application controls to ensure compliance with security policy and security architecture requirements Requirements Bachelor's Degree in Computer Science, Cyber Security,...


  • México AgileEngine A tiempo completo

    We are looking for a collaborative Application Security Engineer to join our international team of 1000+ software experts. If challenging tasks and an agile environment are your cup of tea, we'd like to get to know you. **WHAT YOU NEED TO SUCCEED**: - Be agile to pick up new languages and skills and deliver new solutions to unexpected problems. - Be...


  • México AgileEngine A tiempo completo

    We are looking for a collaborative Application Security Engineer to join our international team of 1000+ software experts. If challenging tasks and an agile environment are your cup of tea, we'd like to get to know you. **WHAT YOU NEED TO SUCCEED** - Be language agnostic and agile to pick up new languages and skills and deliver new solutions to unexpected...