Lead Information Security Engineer
TLDR
Harden cloud and SaaS estates, test AI agents and applications, and operate Google SecOps tooling across security architecture and cyber defence.
Security Architecture and Cyber Defence
InfoSec covers a vast domain of knowledge within the organization. Our mission is to embed security excellence in our business to foster client trust and increase Thoughtworker confidence. Security is an integral part of the change Thoughtworks brings to clients and the industry. We make the right things easy to do. InfoSec work includes security consulting, risk management, cyber security, incident response, and more. InfoSec is a distributed team, spread across the Americas, Europe, India, China, Southeast Asia, and Australia.
The Security Architecture and Cyber Defence functions within InfoSec work closely together to improve Thoughtworks' collective security posture. Security Architecture connects incidents, risks, priorities, and initiatives into a whole-of-business security plan of work and partners with other business functions to deliver on those plans; leads our offensive security testing program; and secures our adoption of AI and agentic systems. The Security Engineering function within the Cyber Defence team builds and operates many of the tools, platforms, and controls that put these strategies into practice. Together, these teams are a trusted source of security know-how for Thoughtworkers and a partner to business and technology teams across the organisation.
This role will be situated in India. The role is remote first, with some expectation to be able to work from the closest Thoughtworks office on a regular cadence. Calls and collaboration outside standard local business hours are a normal and expected part of the role.
Job responsibilities:
The Senior Security Consultant is a hands-on, technical role that sits across both the Security Architecture and Security Engineering teams, reporting to the Head of Security Architecture. You will work as a practitioner, reading and contributing to code, operating and extending security tooling, running projects and workstreams, and working directly with engineering and product teams across the business. You will be expected to lead initiatives independently, drive them to completion, and represent the security function credibly with stakeholders at all levels.
Technical depth and human skills are equally important in this role. Working across a distributed, multicultural organisation means that trust and clear communication are the mechanism by which the technical work gets done. The ability to build solid working relationships across functions, time zones, and cultures is a core part of what we are looking for.
Essential job duties and responsibilities
1. Security architecture and posture improvement
- Lead and contribute to hands-on security architecture initiatives across multi-functional, multi-disciplinary teams, bringing technical know-how, a strong security mindset, and project leadership skills.
- Work in ongoing partnership with the internal application security team to harden the organisation's security posture across our estate.
- Review and threat model system and application designs, identify security gaps, and provide actionable, constructive recommendations that teams can implement without stalling delivery.
- While AI tooling is in active use in the team, candidates will be expected to demonstrate a baseline capability to recognise, describe, and suggest improvements to common software and system architecture patterns, integration strategies, etc without AI assistance.
- Contribute to the development and maintenance of security standards, processes, and patterns for the broader organisation.
- Harden the security architecture of our cloud-based and SaaS-based estates, including identity, network exposure, and configuration.
2. Offensive security and AI agent security
- Review AI system designs and guardrail implementations, and give security-by-design feedback before deployment.
- Test AI and LLM-backed applications and agents for security weaknesses, including prompt injection, tool and MCP integration security, excessive agency, and identity and authorisation issues.
- Contribute to CI/CD pipeline security standards and to hardening the paths by which company software reaches production.
- Plan and run offensive security tests across web applications, APIs, cloud environments, and other infrastructure, combining manual testing with automated and agentic AI tooling. The emphasis is on judgement and quality of findings rather than volume.
- Validate, triage, and de-duplicate findings, and support engineering teams through remediation and re-testing with clear, actionable reporting.
2. Security engineering
- Write and contribute to scripts, automation, and tooling to support security operations and testing workflows. While AI tooling is used within the team for code generation and other activities, candidates will be expected to demonstrate that they can read and describe what a codebase, snippet, or script does without AI assistance.
- Support the evaluation and integration of new security tools and platforms, with a focus on practical capability and operational fit.
- Operate, maintain, and extend our SIEM (Google SecOps), including implementing new connectors to data sources, tuning detection rules, and improving alert quality to reduce noise and increase signal.
- Contribute to SOAR playbook development to automate containment and response actions.
- Contribute to incident response and post-incident review activity, including analysis, containment support, and improvement of detections.
Skills and experience
Required
- At least 5-7 years of hands-on experience in information security, spanning security engineering, testing, or architecture.
- Demonstrated ability to lead initiatives across multi-disciplinary teams, manage competing priorities, and drive work to completion.
- Ability to read, reason about, and contribute to code and scripts as a working practitioner. The use of AI-assisted and AI-driven coding tools is a common practice within the team. However, the right candidate should be able to read and explain the basic functionality of unobfuscated code without AI assistance.
- Ability to communicate effectively with different types of audiences, including explaining technical risk to non-technical stakeholders and working constructively with engineering teams who may be new to security engagement. The ability to build trust and working relationships across the organisation is a core competency of this role.
- Comfort working across different cultural contexts, time zones, and communication styles. Our team is global, and the ability to adapt your communication and collaboration approach accordingly is essential.
- A high standard of written and spoken English.
Highly desirable
- Practical experience assessing and improving security posture in cloud environments (AWS, GCP), including identity, network exposure, and configuration.
- Familiarity with AI system security, or a strong interest and foundational understanding (prompt injection, agent and tool security, the OWASP Top 10 for LLM Applications).
- Experience contributing to or leading security architecture discussions across multi-functional teams, and confidence in giving security input at the design stage of the SDLC.
- Practical experience operating and tuning a SIEM (experience with Google SecOps is a strong advantage. Demonstrated depth in any enterprise SIEM is acceptable). Experience implementing log sources and connectors and developing detection content.
- Hands-on experience with penetration testing across web, API, and cloud environments, with working knowledge of the OWASP Top 10 and OWASP API Security Top 10. Depth in one or more areas is valued.
Education and certification requirements
- Education: Bachelor's degree in computer science, information assurance, MIS, or a related field, or equivalent experience.
- Certification: CISSP, CCSP, SANS certifications (e.g., GSEC, GCIH, GCIA) a plus.
Traits we are looking for in a candidate:
- Have a solid moral compass on which to base your security work. Understand the difference between finding a weakness and the responsible handling of it
- Strong empathy, including the ability to understand where a colleague or team is coming from, meet them there, and build trust across technical and non-technical boundaries
- Ability to communicate effectively to different types of audiences, adapting style and register as needed
- Ability to categorise, visualise, and present findings to stakeholders
- Strong interest in continued learning in the security domain, particularly as AI tools reshape the threat landscape and the way we work
- Understanding of how security vulnerabilities translate into business risks
- Capable of self-management while following broad strategic objectives on a distributed, autonomous team
- Strong sense of commitment and delivery
- Ability to prioritise and handle unplanned work
Other things to know
Learning & Development
There is no one-size-fits-all career path at Thoughtworks: however you want to develop your career is entirely up to you. But we also balance autonomy with the strength of our cultivation culture. This means your career is supported by interactive tools, numerous development programs and teammates who want to help you grow. We see value in helping each other be our best and that extends to empowering our employees in their career journeys.
Onsite Work Expectation
You may be expected to work out of our Thoughtworks office or at our client's office location for all five working days of the week, depending on business or clients’ needs.
About Thoughtworks
Thoughtworks is a global technology consultancy that integrates strategy, design and engineering to drive digital innovation. For 30+ years, our clients have trusted our autonomous teams to build solutions that look past the obvious. Here, computer science grads come together with seasoned technologists, self-taught developers, midlife career changers and more to learn from and challenge each other. Career journeys flourish with the strength of our cultivation culture, which has won numerous awards around the world.
Join Thoughtworks and thrive. Together, our extra curiosity, innovation, passion and dedication overcomes ordinary.
Benefits
Flexible Work Hours
You may be expected to work out of our Thoughtworks office or at our client's office location for all five working days of the week, depending on business or clients’ needs.
Learning Budget
your career is supported by interactive tools, numerous development programs and teammates who want to help you grow
Remote-Friendly
The role is remote first.
Referrals Only is a job board designed specifically for companies that thrive on employee recommendations. By creating a platform focused solely on referrals, we help organizations find top talent through trusted connections, ensuring a more efficient and reliable hiring process.
- Founded
- Founded 1993
- Employees
- 500+ employees
- Industry
- Professional Services
- Total raised
- $750M raised