Lead Security Engineer
Eagan, MN · Hybrid
Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and ...
Eagan, MN · Hybrid
Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and ...
Eagan, MN · Hybrid
Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and ...
Additional certifications such as CIA, CFA, CAIA, or CISA. Experience reviewing SOC1 and SOC2 reports. What We're Looking For Required Bachelor's degree in Accounting, Finance, or a related field. CP ...
Additional certifications such as CIA, CFA, CAIA, or CISA. Experience reviewing SOC1 and SOC2 reports. What We're Looking For Required Bachelor's degree in Accounting, Finance, or a related field. CP ...
Eagan, MN · Hybrid
Implement the controls and follow the runbooks, standards, and risk-based prioritization (in line with CISA guidance) set by the senior engineer and technical lead. * Track status accurately from ...
Eagan, MN · Hybrid
Implement the controls and follow the runbooks, standards, and risk-based prioritization (in line with CISA guidance) set by the senior engineer and technical lead. * Track status accurately from ...
Eagan, MN · Hybrid
$116K - $160K/yr
Familiarity with vulnerability prioritization (CVSS/EPSS, CISA KEV) and SLA-driven burndown, plus comfort with AI-assisted tooling and reviewing its output critically. * Clear communication, some ...
Eagan, MN · Hybrid
$116K - $160K/yr
Familiarity with vulnerability prioritization (CVSS/EPSS, CISA KEV) and SLA-driven burndown, plus comfort with AI-assisted tooling and reviewing its output critically. * Clear communication, some ...
Golden Valley, MN · On-site
Relational database experience ITIL Foundation certification Project Management experience Security Audit experience Entitlement Review experience CISSP, CISA, and/or CISM certification Healthcare ...
Golden Valley, MN · On-site
Relational database experience ITIL Foundation certification Project Management experience Security Audit experience Entitlement Review experience CISSP, CISA, and/or CISM certification Healthcare ...
Industry level Security certification (Sec+, CISM, CISSP, CISA) * Background in a technical field (IT, Systems Engineering, Architecture, Development) * Former ISSM, ISSE, or SCA assignments Skills ...
New
Industry level Security certification (Sec+, CISM, CISSP, CISA) * Background in a technical field (IT, Systems Engineering, Architecture, Development) * Former ISSM, ISSE, or SCA assignments Skills ...
New
Minneapolis, MN · On-site
$136K - $137K/yr
PMP / PRINCE2 / SAFe, plus one of CISSP, CISM, CRISC, or CISA Nice to have * Familiarity with security vulnerability management: CVE/CVSS, severity triage, SLA-based remediation cycles * Exposure to ...
Minneapolis, MN · On-site
$136K - $137K/yr
PMP / PRINCE2 / SAFe, plus one of CISSP, CISM, CRISC, or CISA Nice to have * Familiarity with security vulnerability management: CVE/CVSS, severity triage, SLA-based remediation cycles * Exposure to ...
Maplewood, MN · Remote
$49 - $85/hr
CISSP, CISM, CISA, or CRISC. * Bachelor's degree in Information Technology or a related area, or an equivalent combination of education, certification, and experience. Preferred Skills * Hands-on ...
Maplewood, MN · Remote
$49 - $85/hr
CISSP, CISM, CISA, or CRISC. * Bachelor's degree in Information Technology or a related area, or an equivalent combination of education, certification, and experience. Preferred Skills * Hands-on ...
Virginia, MN · On-site
$107K - $220K/yr
SecurityX/CASP+,CCNP Security,CISA,CCSP, or CISSP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - ...
Virginia, MN · On-site
$107K - $220K/yr
SecurityX/CASP+,CCNP Security,CISA,CCSP, or CISSP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - ...
Virginia, MN · On-site
$97K - $181K/yr
SecurityX/CASP+, CCNP Security, CISA, CCSP, CISSP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - 7 years of ...
Virginia, MN · On-site
$97K - $181K/yr
SecurityX/CASP+, CCNP Security, CISA, CCSP, CISSP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - 7 years of ...
Virginia, MN · On-site
$92K - $184K/yr
SecurityX / CASP+, CCNP Security, CISA, CISSP, CISSP-ISSAP, or CISSP-ISSEP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor ...
Virginia, MN · On-site
$92K - $184K/yr
SecurityX / CASP+, CCNP Security, CISA, CISSP, CISSP-ISSAP, or CISSP-ISSEP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor ...
Virginia, MN · On-site
$97K - $181K/yr
SecurityX / CASP+, CCNP Security, CISA, FITSP-O, GICSP, or SSCP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - ...
Virginia, MN · On-site
$97K - $181K/yr
SecurityX / CASP+, CCNP Security, CISA, FITSP-O, GICSP, or SSCP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - ...
New Brighton, MN · On-site
$90K - $120K/yr
Professional certifications such as CISA, CPA, or CISM are a plus. * Experience working with ERP, financial, HRIS, or other enterprise business applications is preferred. This opportunity is ideal ...
Quick apply
New Brighton, MN · On-site
$90K - $120K/yr
Professional certifications such as CISA, CPA, or CISM are a plus. * Experience working with ERP, financial, HRIS, or other enterprise business applications is preferred. This opportunity is ideal ...
Virginia, MN · On-site
$67K - $117K/yr
SecurityX / CASP+ ,CCNP Security, CISA, FITSP-O, GICSP, or SSCP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree
Virginia, MN · On-site
$67K - $117K/yr
SecurityX / CASP+ ,CCNP Security, CISA, FITSP-O, GICSP, or SSCP certification (for Senior role) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree
Virginia, MN · On-site
$97K - $181K/yr
SecurityX/CASP+, CCNP Security, CISA, CCSP, CISSP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - 7 years of ...
Virginia, MN · On-site
$97K - $181K/yr
SecurityX/CASP+, CCNP Security, CISA, CCSP, CISSP (for Senior roles) * We are actively seeking multiple levels: * Junior: 0 - 3 years of experience + Bachelor's Degree * Journeyman: 4 - 7 years of ...
CISA and/or CISSP certifications are desired * Prior experience as a consultant is desired * Experience with port scanning, vulnerability assessment and penetration testing tools (e.g., Nmap, Nessus ...
CISA and/or CISSP certifications are desired * Prior experience as a consultant is desired * Experience with port scanning, vulnerability assessment and penetration testing tools (e.g., Nmap, Nessus ...
New Brighton, MN · On-site
$90K - $120K/yr
Professional certifications such as CISA, CPA, or CISM are a plus. * Experience working with ERP, financial, HRIS, or other enterprise business applications is preferred. This opportunity is ideal ...
Quick apply
New Brighton, MN · On-site
$90K - $120K/yr
Professional certifications such as CISA, CPA, or CISM are a plus. * Experience working with ERP, financial, HRIS, or other enterprise business applications is preferred. This opportunity is ideal ...
Minneapolis, MN · On-site
CISA and/or CISSP certifications are desired * Prior experience as a consultant is desired * Experience with port scanning, vulnerability assessment and penetration testing tools (e.g., Nmap, Nessus ...
Minneapolis, MN · On-site
CISA and/or CISSP certifications are desired * Prior experience as a consultant is desired * Experience with port scanning, vulnerability assessment and penetration testing tools (e.g., Nmap, Nessus ...
Eagan, MN · On-site
GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate results in planning and delivering complex ...
Eagan, MN · On-site
GSEC, CISSP, CISA, CISM, ITIL Preferred exposure in SOC2, ISO 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate results in planning and delivering complex ...
Virginia, MN · On-site
$85K - $202K/yr
CCE, CCISO, CCNP Security, CCSP, CFR, CISA, CISM, CISSO, CISSP, CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP, CPTE, CySA+, FITSP-A, FITSP-M, FITSP-O, GCFA, GCIA, GCIH, GCLD, GCSA, GDSA, GFACT, GICSP, GPEN ...
Virginia, MN · On-site
$85K - $202K/yr
CCE, CCISO, CCNP Security, CCSP, CFR, CISA, CISM, CISSO, CISSP, CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP, CPTE, CySA+, FITSP-A, FITSP-M, FITSP-O, GCFA, GCIA, GCIH, GCLD, GCSA, GDSA, GFACT, GICSP, GPEN ...
$60.7K - $68.6K
2% of jobs
$68.6K - $76.4K
4% of jobs
$76.4K - $84.2K
7% of jobs
$84.2K - $92.1K
11% of jobs
$92.3K is the 25th percentile. Wages below this are outliers.
$92.1K - $99.9K
21% of jobs
The median wage is $101.9K / yr.
$99.9K - $107.7K
17% of jobs
$107.7K - $115.6K
11% of jobs
$117K is the 75th percentile. Wages above this are outliers.
$115.6K - $123.4K
9% of jobs
$123.4K - $131.2K
9% of jobs
$131.2K - $139.1K
6% of jobs
$139.1K - $146.9K
3% of jobs
$60.7K
$107.5K
$146.9K
A Certified Information Systems Auditor (CISA) job involves assessing, auditing, and ensuring the security and integrity of an organization's information systems. Professionals in this role evaluate IT controls, identify risks, and ensure compliance with industry standards and regulations. They often work in governance, risk management, and compliance to help organizations protect sensitive data and maintain operational efficiency. CISA-certified professionals can work in various industries, including finance, healthcare, and government.
CISAs often encounter challenges such as staying current with rapidly evolving technology threats and ensuring compliance with complex regulatory requirements. They must regularly interface with various departments to collect the necessary information for audits, which can require strong interpersonal and negotiation skills. Balancing thoroughness and efficiency while conducting audits is essential, as is providing actionable recommendations that are practical within the business context. Overcoming these challenges helps CISAs add significant value to their organizations by improving IT controls and mitigating risk.
To thrive as a CISA (Certified Information Systems Auditor), you need a strong understanding of IT auditing, risk assessment, and information systems governance, typically validated by the CISA certification. Proficiency with audit management software, data analytics tools, and familiarity with regulatory compliance frameworks (such as COBIT or ISO 27001) are essential. Strong analytical thinking, effective communication, and attention to detail are key soft skills that help in collaborating with stakeholders and presenting findings clearly. These skills and qualities are crucial for ensuring information systems are secure, reliable, and compliant with industry standards.
The most popular types of Cisa jobs in Minnesota are:
For Cisa jobs in Minnesota, the most frequently searched job titles are:
The top searched job categories for Cisa jobs in Minnesota are:
Cities in Minnesota with the most Cisa job openings:

Eagan, MN • Hybrid
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 18 days ago
Act as the technical lead for security across application, cloud, and infrastructure, setting technical direction and owning the security backlog.
Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries.
Design new security processes, revamp patching cycles and image refreshes, and develop standards and escalation paths for security operations.
8.9
Based on 22 frontline employees who took The Breakroom Quiz
The Opportunity
Do you want to set the technical direction for how a global business secures its infrastructure at scale? Thomson Reuters is investing in a dedicated security engineering capability, and we are looking for a hands-on technical lead to help build and shape it. You will design how we secure our estate end to end, not just work through a backlog. This role sits on our Service Management & Transformation team.
As the Lead Security Engineer, you will be the technical lead for security across our application, cloud, and infrastructure estate, which spans on-premises datacentersand major clouds. This is a senior individual-contributor role: you set the technical direction and guide the work of the engineers around you, but you are not their line manager. It is as much a process-design role as a hands-on one. You will design new security controls and ways of working across patching, hardening, network isolation, identity, and secrets management, revamping patching cycles and golden-image refreshes so the team can move fast without sacrificing safety, and you will partner across Information Security, Platform Engineering, and application teams to raise our overall security posture.
About the Role
In this opportunity as Lead Security Engineer, you will:
Act as the technical lead for security across application, cloud, and infrastructure. Set technical direction, make the key calls, own the shape and quality of the security backlog end to end, and serve as the point of escalation for complex security and remediation work, without direct line-management responsibility.
Design and build security controls across layers such as operating systems, container orchestration, CI/CD pipelines, cloud configuration, and network boundaries, to defend against sophisticated adversaries and insider threats.
Design new security processes and ways of working, revamping patching cycles and golden-image and base-image refreshes across cloud and on-prem, so the team can move fast without sacrificing safety.
Come to the table with ideas:identifywhere security and remediation processes can be improved, propose better approaches, and turn them into standards the team adopts.
Set the technical approach across the full security scope: application and open-source dependency fixes, infrastructure patching, cloudconfigurationand guardrails, WAF, network isolation, and secrets and machine-identity management. Prioritize by risk in line with industry best practice such as CISA guidance (CISA KEV, CVSS/EPSS, and SLA-driven burndown), and champion adoption of AI-augmented security tooling, including SAST and SCA.
Raise the technical bar by reviewing fixes and mentoring engineers, and coordinate with the wider security team across regions to keep standards and priorities aligned across time zones.
Own clear reporting and metrics, and build the runbooks, standards, and escalation paths that make security a repeatable, auditable capability.
About You
You'rea fit for the role of Lead Security Engineer if your background includes:
8+ years of hands-on experience in security engineering, vulnerability management, or cloud and infrastructure security, including time as a technical lead or senior individual contributor setting direction and guiding the technical work of other engineers, plus abachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
A deep understanding of security principles, common vulnerabilities, and best practice across application, cloud, and infrastructure layers.
A working command of vulnerability management at scale: prioritization frameworks, CVSS/EPSS, CISA KEV, and SLA-driven burndown.
Breadth across the security stack: application and dependency vulnerabilities, infrastructure patching, guardrails, WAF, network isolation, and identity and access controls, with multi-cloud experience across two or more of AWS, Azure, GCP, and OCI (all four an advantage) alongside on-premises infrastructure.
A track record of designing and improving technical processes, such as patching cycles, image or GAMI refreshes, or remediation workflows, rather than only executing them, with a proactive mindset for identifying and closing security gaps through automation and tooling; experience with AI-assisted or automated security tooling is an advantage.
Strong judgment on balancing risk reduction against operational and customer impact.
Excellent written and verbal communication, comfortable operating across security, engineering, and business audiences and able to convey complex security concepts to technical and non-technical stakeholders, with enthusiasm for collaborating with cross-functional teams to build secure, reliable systems that scale globally.
#LI-LB1
What's in it For You?
About Us
Thomson Reuters informs the way forward by bringing together the trusted content and technology that people and organizations need to make the right decisions. We serve professionals across legal, tax, accounting, compliance, government, and media. Our products combine highly specialized software and insights to empower professionals with the data, intelligence, and solutions needed to make informed decisions, and to help institutions in their pursuit of justice, truth, and transparency. Reuters, part of Thomson Reuters, is a world leading provider of trusted journalism and news.
We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments. At a time when objectivity, accuracy, fairness, and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.
As a global business, we rely on the unique backgrounds, perspectives, and experiences of all employees to deliver on our business goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity Employer providing a drug-free workplace.
Thomson Reuters makes reasonable accommodations for applicants with disabilities, including veterans with disabilities, and for sincerely held religious beliefs in accordance with applicable law. If you reside in the United States and require an accommodation in the recruiting process, you may contact our Human Resources Department atHR.Leave-Expert@thomsonreuters.com. Disability accommodations in the recruiting process may include things like a sign language interpreter, making interview rooms accessible, providing assistive technology, or other relevant accommodations. Please note this email is not intended for general recruitment questions and we will promptly respond to inquiries regarding accommodations. More information on requesting an accommodation here.
Learn more on how to protect yourself from fraudulent job postings here.
More information about Thomson Reuters can be found on thomsonreuters.com
Get the full story on Breakroom
Sourced by ZipRecruiter
Analytics and business intelligence systems, finance and insurance, business management consulting, professional, scientific, and technical services and software development
10,000+ Employees
New York, NY, US