Thomson Reuters · 1 day ago
FedRAMP Enterprise Security Architect
Thomson Reuters is a global business that informs the way forward by bringing together trusted content and technology. The FedRAMP Enterprise Security Architect will be responsible for architecting, securing, and maturing the organization’s cloud platforms in alignment with federal requirements, while influencing the enterprise’s security posture across various teams.
FinanceConsultingBig DataSoftwareProperty & Casualty InsuranceProfessional ServicesAdviceAnalyticsFinancial ServicesManagement ConsultingRisk Management
Responsibilities
Architect and integrate secure solutions across AWS, Azure, GCP, and modern application platforms including containers and Kubernetes
Build, evaluate, and refine authorization boundary diagrams, network/data flow diagrams, and enterprise security design patterns
Execute technical security controls within production federal environments
Enhance detection and monitoring capabilities by identifying gaps and implementing improved logging, alerting, and analytics
Partner with engineering, product, DevOps, and operations to embed security early in the development lifecycle
Translate complex NIST and audit requirements into clear engineering tasks and architectural recommendations
Act as a trusted security advisor during customer engagements, proposal reviews, and technical deep dives
Review vendor and customer contracts to ensure alignment with federal security standards
Contribute to broader enterprise compliance programs including ISO 27001, SOC 2, PCI-DSS, and others
Maintain and evolve core security policies, standards, incident response plans, and contingency plans
Conduct architecture reviews to ensure federal architecture requirements are incorporated into new platform features and services
Collaborate with engineering, DevOps, compliance, and public-sector stakeholders to address security challenges and drive improvements
Support new FedRAMP authorizations and significant change processes in collaboration with 3PAOs
Stay current with FedRAMP, DISA, NIST, CC SRG, and STIG requirements and ensure timely remediation of compliance gaps
Build detailed FedRAMP-compliant diagrams including ABD, NFD, and DFD using tools such as Lucid Chart or Visio
Qualification
Required
10+ years in cloud security architecture, engineering, or related roles (federal workloads preferred)
Demonstrated expertise for FedRAMP, NIST RMF, and NIST SP 800‑53 Rev 5 controls
Deep technical expertise in securing cloud-native platforms: AWS, Azure, Kubernetes, containers, microservices, and modern app architectures
Experience both shaping compliance strategy and implementing technical controls hands-on
Proven ability to influence cross-functional leaders and drive organizational change
Experience providing executive-level updates and navigating Agile environments
Preferred
3+ years supporting public sector cloud programs (FedRAMP, DoD, state/local)
Experience with IaC, CI/CD, automation (Terraform, GitOps, etc.)
Knowledge of DISA STIGs, CC SRG, FIPS 140-2/3, and federal encryption requirements
Experience collaborating with 3PAOs or participating in assessment cycles
Benefits
Hybrid Work Model: We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected.
Flexibility & Work-Life Balance: Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset.
Career Development and Growth: By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real-world solutions.
Industry Competitive Benefits: We offer comprehensive benefit plans to include flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing.
Culture: Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more.
Social Impact: Make an impact in your community with our Social Impact Institute.
Making a Real-World Impact: We are one of the few companies globally that helps its customers pursue justice, truth, and transparency.
Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match.
Optional hospital, accident and sickness insurance paid 100% by the employee;
Optional life and AD&D insurance paid 100% by the employee;
Flexible Spending and Health Savings Accounts;
Fitness reimbursement;
Access to Employee Assistance Program;
Group Legal Identity Theft Protection benefit paid 100% by employee;
Access to 529 Plan;
Commuter benefits;
Adoption & Surrogacy Assistance;
Tuition Reimbursement;
Access to Employee Stock Purchase Plan.
Company
Thomson Reuters
Thomson Reuters delivers critical information from the financial, legal, accounting, intellectual property, science, and media markets.
H1B Sponsorship
Thomson Reuters has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (13)
2024 (12)
2023 (5)
Funding
Current Stage
Public CompanyTotal Funding
unknown1995-11-20IPO
Recent News
2026-02-11
Company data provided by crunchbase