AI Security Associate Architect at Thomson Reuters | CA | Rezi

AI Security Associate Architect at Thomson Reuters

AI Security Associate Architect

Thomson Reuters · CA

2 weeks ago

AI Security Associate Architect

Thomson Reuters · CA

14 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Shape how AI-powered products are designed and secured at enterprise scale. Define secure architecture for products and systems used by millions of professionals worldwide. Join Thomson Reuters' Security Architecture team, setting the technical direction for designing and securing products and enterprise systems end-to-end. Lead architecture and design reviews, threat modeling, and Secure AI assessments across the product portfolio, focusing on building, shipping, and running AI-powered features and their supporting platforms. Partner with product engineering, platform engineering, information security, and risk management teams to ensure security is shaped early and designed in. Work alongside domain architects and contribute to the multi-year Security Architecture direction.

Responsibilities

  • Architect security across products and platforms by leading security architecture reviews and design consultations across Thomson Reuters' product portfolio.
  • Develop reference architectures and secure design patterns including architecture decision records, guardrails, and implementation guidance for adoption by engineering teams.
  • Lead Secure AI architecture by conducting Secure AI design reviews for AI-powered products, features, platforms, and internal AI development workflows.
  • Build and evolve threat models for AI systems, including risks related to prompt injection, model and data integrity, agent and tool-use security, AI supply chain, RAG, LLMs, model serving, AI gateways, and MCP-based tools.
  • Drive threat modeling and risk-informed design across web, API, mobile, cloud, container, Kubernetes, and modern application architectures.
  • Partner with engineering as a trusted technical advisor on new initiatives, architectural pivots, high-impact features, vendor decisions, and customer-facing architecture decisions.
  • Strengthen the Security Architecture practice by improving knowledge bases, review templates, decision records, and mentoring product and platform engineers on secure design.

Requirements

  • 7+ years of experience in security architecture, product security, application security, or cloud security engineering, with hands-on architectural ownership.
  • Demonstrated experience leading architecture and design reviews across multiple products or platforms.
  • Hands-on expertise with at least one major cloud platform (AWS, Azure, or Google Cloud), including identity, networking, secrets management, data protection, and logging.
  • Practical experience securing modern application architectures, including APIs, microservices, containers, Kubernetes, and CI/CD.
  • Working knowledge of GenAI and LLM security, including prompt injection, model and data integrity, agent and tool-use security, AI supply chain considerations, and secure AI design patterns.
  • Strong understanding of core security principles, including cryptography, public key infrastructure, authentication and authorization, OAuth 2.0, and network security protocols.
  • Ability to engage deeply with technical teams, including reading and discussing code in Python, Go, Java, or similar languages when an architecture review requires it.
  • Strong threat modeling skills and the judgment to apply frameworks pragmatically, including OWASP ASVS, NIST CSF, NIST SSDF, OWASP LLM Top 10, and MITRE ATLAS.
  • Excellent written and verbal communication skills, with the ability to influence senior engineers and translate complex security trade-offs into clear recommendations.

Skills

  • AI Security
  • Secure Architecture
  • Threat Modeling
  • Cloud Security
  • API Security
  • Microservices Security
  • Container Security
  • Kubernetes Security
  • CI/CD Security
  • GenAI Security
  • LLM Security
  • Prompt Injection
  • Model Integrity
  • Data Integrity
  • Agent Security
  • Tool-Use Security
  • AI Supply Chain Security
  • RAG
  • LLMs
  • Model Serving
  • AI Gateways
  • MCP-based Tools
  • Web Security
  • Mobile Security
  • Cryptography
  • Public Key Infrastructure
  • Authentication
  • Authorization
  • OAuth 2.0
  • Network Security Protocols
  • Python
  • Go
  • Java
  • OWASP ASVS
  • NIST CSF
  • NIST SSDF
  • OWASP LLM Top 10
  • MITRE ATLAS
  • Google Cloud Security
  • Vertex AI
  • IAM
  • VPC Service Controls
  • Security Command Center
  • AI/ML Platforms
  • SageMaker
  • Bedrock
  • Azure AI
  • AI Red Teaming
  • Adversarial ML Evaluation
  • LLM Security Testing
  • Software Supply Chain Security
  • SBOM
  • SLSA
  • Provenance
  • Attestation
  • Workload Identity
  • OWASP SAMM
  • BSIMM
  • Infrastructure as Code
  • Terraform
  • CDK
  • OSCP
  • OSWE
  • CKA/CKS
  • GCP Professional Cloud Security Engineer
  • AWS Security Specialty
  • CCSP

Location

  • Toronto

Work Type

  • Hybrid

Experience Level

  • 7+ years

Salary/Compensations

  • $140,000 CAD - $175,000 CAD

Benefits

  • Flexible vacation
  • Two company-wide Mental Health Days off
  • Access to the Headspace app
  • Retirement savings
  • Tuition reimbursement
  • Employee incentive programs
  • Resources for mental, physical, and financial wellbeing
  • Flexibility & Work-Life Balance
  • Work from anywhere for up to 8 weeks per year
  • Career Development and Growth
  • Grow My Way programming
  • Skills-first approach
  • Two paid volunteer days off annually
  • Opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives

About the Company

  • Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions.
  • We serve professionals across legal, tax, accounting, compliance, government, and media.
  • Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency.
  • Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
  • We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments.
  • At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them.
  • Join us and help shape the industries that move society forward.
  • We are one of the few companies globally that helps its клиенты pursue justice, truth, and transparency.
  • Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

Equal Opportunity

  • As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals.
  • To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law.
  • Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
  • We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law.