Lead InfoSec Engineer, Vulnerability Management

S&P Global
New York
Workplace: HybridFull timeUSD 125,000 - 145,000 annuallyFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Leadership","Influence","Analytical thinking","Communication","Cross-functional collaboration"]

Lead the enterprise vulnerability management lifecycle across infrastructure, cloud, and application environments. Partner with application teams, IT managers, and business stakeholders to drive timely remediation while aligning security requirements to business priorities. Build executive-ready reporting and metrics to communicate security posture and risk trends, establish KPIs, and support audit and regulatory compliance. Mentor junior security professionals and improve program maturity through process, governance, and tooling strategy.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
S&P Global
S&P Global
1 month ago

Lead InfoSec Engineer, Vulnerability Management

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 34 days agoStatus: Live

Job Summary

Lead the enterprise vulnerability management lifecycle across infrastructure, cloud, and application environments. Partner with application teams, IT managers, and business stakeholders to drive timely remediation while aligning security requirements to business priorities. Build executive-ready reporting and metrics to communicate security posture and risk trends, establish KPIs, and support audit and regulatory compliance. Mentor junior security professionals and improve program maturity through process, governance, and tooling strategy.
Location: New York
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Lead the enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments with risk-based prioritization.
  • •Drive cross-functional collaboration to ensure timely vulnerability remediation while balancing security requirements with business priorities.
  • •Develop reporting and metrics programs using multiple data sources to provide executive visibility into security posture and risk trends.
  • •Mentor and guide junior security professionals and improve program maturity through process improvements, governance frameworks, and tooling strategy.
  • •Support regulatory compliance and audit activities aligned with enterprise security policies and industry standards, and establish KPIs for remediation outcomes.

Pay and Benefits

Salary: USD 125,000 - 145,000 annually
Perks:Health Insurance

Key Requirements

  • •7+ years of operational security experience in vulnerability management, application security testing, or technical project management in large-scale distributed environments.
  • •Expertise in vulnerability assessment frameworks including CVE, CVSS, and CWE, plus experience with enterprise vulnerability management platforms such as Qualys, Tanium, or Rapid7.
  • •Strong application security knowledge to assess risk, map vulnerabilities to exploitation techniques, and translate findings into actionable recommendations.
  • •Experience with application security testing tools such as DAST/SAST platforms (Fortify, Checkmarx, Veracode, or equivalent).
  • •Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience; relevant certifications such as CISSP, CISM, CEH, or GCIH.
Experience:7+ years
Education:Bachelor's in Computer Science, Cybersecurity, Information Technology
Skills:LeadershipInfluenceAnalytical thinkingCommunicationCross-functional collaboration
Certifications:CISSPCISMCEHGCIH
Tech Stack:Vulnerability managementCVECVSSCWEQualysTaniumRapid7Application securityDASTSASTFortifyCheckmarxVeracodePower BITableauNIST Cybersecurity FrameworkISO 27001NISTISO

Company Brief

S&P Global
Provides financial information, analytics, benchmarks, and credit ratings to markets and institutions worldwide, offering data, research, indices, and risk assessment tools across the financial services and commodities sectors.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: New York, United States
Founded: 1917
WebsiteLinkedIn