Lead Penetration Test Engineer

S&P Global
Boston, Chicago, Dallas, Houston, Raleigh, New York, Washington, Toronto, Calgary
Workplace: HybridFull timeUSD 135,000 - 200,000 annuallyFunction: QA, Test & Release EngineeringExperience: 8+ yearsEducation: bachelorsSkills: ["Communication","Stakeholder management","Problem-solving","Collaboration","Research"]

Lead penetration testing and offensive security work for the S&P Ratings Security team, performing manual and automated tests across web applications, infrastructure, and cloud environments. Drive vulnerability assessments (DAST, SAST, SCA), retesting, and remediation planning while improving security controls through custom tooling and CI/CD-integrated automation. Lead attack simulations and tabletop exercises, research emerging threats, and clearly communicate risk and mitigation recommendations to technical and non-technical stakeholders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
S&P Global
S&P Global
7 hours ago

Lead Penetration Test Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 day agoStatus: Live

Job Summary

Lead penetration testing and offensive security work for the S&P Ratings Security team, performing manual and automated tests across web applications, infrastructure, and cloud environments. Drive vulnerability assessments (DAST, SAST, SCA), retesting, and remediation planning while improving security controls through custom tooling and CI/CD-integrated automation. Lead attack simulations and tabletop exercises, research emerging threats, and clearly communicate risk and mitigation recommendations to technical and non-technical stakeholders.
Location: Boston, Chicago, Dallas, Houston, Raleigh, New York, Washington, Toronto, Calgary
Workplace: Hybrid
Employment Type: Full time
Job Function: QA, Test & Release Engineering
Seniority: Mid level

Key Responsibilities

  • •Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using manual and automated techniques.
  • •Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.
  • •Perform vulnerability management by collaborating with engineering teams to analyze findings, develop remediation plans, and strengthen security across development and production lifecycles.
  • •Lead security assessments using DAST, SAST, and SCA tools, and evaluate cloud-specific attack techniques including IAM abuse, container/serverless exploitation, and misconfiguration testing.
  • •Lead attack simulations and tabletop exercises, research emerging threats, and present actionable findings and risk mitigation guidance to technical and non-technical stakeholders.

Pay and Benefits

Salary: USD 135,000 - 200,000 annually
Perks:Health InsuranceRetirementLearning BudgetPaid Leave

Key Requirements

  • •Minimum 8 years of information security experience focused on penetration testing, application security, and vulnerability management.
  • •Hands-on penetration testing experience using tools such as Burp Suite, Nessus, Metasploit, and Nmap, and methodologies including OWASP Top 10, MITRE ATT&CK, and PTES.
  • •Expertise identifying and exploiting common infrastructure and web application vulnerabilities such as XSS, SQL Injection, and IDOR.
  • •Strong scripting/programming skills (Bash, Python, Go, PowerShell, JavaScript) and experience integrating security testing into CI/CD pipelines.
  • •At least one recognized offensive security certification (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).
Experience:8+ yearsInformation securityPenetration testingOffensive securityCloud securityApplication security
Education:Bachelor's in Computer Science, Information Systems, or a related field
Skills:CommunicationStakeholder managementProblem-solvingCollaborationResearch
Certifications:OSCPOSCE3OSEPGXPNGPENCREST CRTCREST CCT
Tech Stack:Burp SuiteNessusMetasploitNmapOWASP Top 10MITRE ATT&CKPTESDASTSASTSCACI/CDBashPythonGoPowerShellJavaScriptCVECVSSCWEXSS

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

S&P Global
Provides financial information, analytics, benchmarks, and credit ratings to markets and institutions worldwide, offering data, research, indices, and risk assessment tools across the financial services and commodities sectors.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: New York, United States
Founded: 1917
WebsiteLinkedIn