Distinguished Engineer, AI Threat Defense

Thomson ReutersEagan, MN
Hybrid

About The Position

Thomson Reuters is enhancing its Cyber Defense capability in response to an AI-driven threat landscape that has fundamentally changed the speed, scale, and nature of cyberattacks. The Distinguished Engineer, AI Threat Defense is an individual contributor and senior technical authority embedded within the existing 60+ person Cyber Defense organization. Reporting to the VP of Cyber Defense, this individual will strengthen AI-specific threat defense strategy and build AI-augmented detection and response capability into the existing Security Operations Center (SOC) and Cyber Incident Response Team (CIRT). This role has no direct reports or management authority. Instead, the individual will drive impact through technical credibility, architecture, hands-on engineering, influence, and mentorship across SOC Operations, CIRT, Threat Detection Engineering, Vulnerability Management, Attack Surface Reduction, and Cyber Threat Management. The role also owns two areas where the current organization lacks a dedicated deep technical owner: the technical strategy against AI-specific attack vectors and the hands-on architecture and delivery of AI-augmented detection and response within the existing SOC and CIRT.

Requirements

  • 12+ years of progressive cybersecurity engineering experience, including experience operating at Principal, Staff, or Distinguished Engineer level within a large, complex enterprise.
  • Deep hands-on knowledge of AI-specific attack vectors and defensive architectures.
  • Production experience governing AI systems, agentic infrastructure, MCP or equivalent integration patterns.
  • Proven experience architecting or delivering AI-assisted detection and response within a mature 24/7 SOC and/or CIRT.
  • Experience enhancing an established security organization rather than simply building a new function from scratch.
  • Demonstrated ability to drive adoption of detection capabilities and security controls across: SOC Operations, CIRT, Threat Detection Engineering, Vulnerability Management, Attack Surface Reduction.
  • Ability to influence technical teams through credibility rather than direct reporting authority.
  • Exceptional communication skills, including the ability to explain AI-related security risk to senior executives and technical audiences.
  • Experience within a regulated, multi-segment enterprise requiring coordination across legal, compliance, procurement, and governance organizations.

Nice To Haves

  • Experience in financial services, legal technology, or professional information services.
  • Experience embedding major technical capabilities into an existing mature security operations organization.
  • Familiarity with frontier AI vulnerability research programs such as Anthropic Project Glasswing / Claude Code Security or comparable agentic vulnerability-discovery initiatives.
  • Hands-on experience building or operating agentic AI systems using multiple LLMs, including open-weight and hosted/frontier models.
  • Experience integrating AI capabilities with SAST/AppSec tooling and vulnerability-management workflows.
  • Working knowledge of safely operating open-weight or less-restricted AI models for authorized internal security research.
  • Published research, conference speaking, or active participation within AI security research communities.
  • Relevant certifications such as CISSP, CISM, advanced AI/ML security, cloud security (AWS/Azure/GCP), or detection-engineering credentials.

Responsibilities

  • Own Thomson Reuters' monitoring and response strategy against AI-specific attack vectors including prompt injection, Model Context Protocol (MCP) exploitation, agentic system compromise, deepfake-enabled social engineering, and AI-assisted reconnaissance.
  • Partner with Security Engineering and Architecture to define standards for securing AI infrastructure and ensuring it can be effectively monitored and defended.
  • Track emerging offensive AI capabilities, adversary tooling, published research, and threat-actor adoption of AI so Cyber Defense capabilities evolve ahead of emerging threats.
  • Drive monitoring and defenses for AI-specific threat classes including: Direct and indirect prompt injection, Jailbreaks and guardrail bypass, Sensitive-information and system-prompt disclosure, Unsafe model output and downstream execution, Excessive agency and MCP/tool abuse, Model and data poisoning, AI supply-chain compromise, Model denial-of-service / denial-of-wallet attacks, Model, prompt, and intellectual-property theft.
  • Own technical monitoring and response for Thomson Reuters AI-enabled applications, features, and agentic services while partnering with Product Engineering, Security Engineering & Architecture, and AppSec to embed security directly into the software development lifecycle.
  • Build AI-augmented detection content and analytics for AI-specific attack patterns.
  • Integrate AI threat detection into the existing SIEM, detection engineering, and SOC monitoring stack.
  • Build AI-assisted playbooks and runbooks and integrate them into existing CIRT and SOAR workflows.
  • Serve as the principal technical architect for incorporating AI capabilities into the existing 24/7 SOC and CIRT rather than creating a separate security function.
  • Design automated workflows for AI-related detection, triage, investigation, and response.
  • Increase analyst productivity while maintaining human-in-the-loop controls, audit trails, and rollback capability.
  • Drive adoption across SOC Operations, CIRT, Threat Detection Engineering, Vulnerability Management, and Attack Surface Reduction.
  • Act as the recognized technical authority for AI threat defense across the Cyber Defense organization.
  • Provide hands-on mentorship and technical uplift to SOC, CIRT, engineering, and security professionals without formal management responsibility.
  • Represent Cyber Defense externally with industry groups, customers, and regulators.
  • Influence engineers and analysts through technical reviews, direct collaboration, architecture guidance, and knowledge sharing.

Benefits

  • Hybrid Work Model
  • Flexibility & Work-Life Balance (including work from anywhere for up to 8 weeks per year)
  • Career Development and Growth (Grow My Way programming)
  • Industry Competitive Benefits (flexible vacation, two company-wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing)
  • Globally recognized, award-winning reputation for inclusion and belonging, flexibility, work-life balance, and more.
  • Social Impact (two paid volunteer days off annually and opportunities to get involved with pro-bono consulting projects and Environmental, Social, and Governance (ESG) initiatives)
  • Market competitive health, dental, vision, disability, and life insurance programs
  • Competitive 401k plan with company match
  • Competitive vacation, sick and safe paid time off
  • Paid holidays (including two company mental health days off)
  • Parental leave
  • Sabbatical leave
  • Optional hospital, accident and sickness insurance paid 100% by the employee
  • Optional life and AD&D insurance paid 100% by the employee
  • Flexible Spending and Health Savings Accounts
  • Fitness reimbursement
  • Access to Employee Assistance Program
  • Group Legal Identity Theft Protection benefit paid 100% by employee
  • Access to 529 Plan
  • Commuter benefits
  • Adoption & Surrogacy Assistance
  • Tuition Reimbursement
  • Access to Employee Stock Purchase Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service