Lead InfoSec Engineer, DevSecOps

S&P Global
New York, London
Workplace: HybridFull timeUSD 100,000 - 130,000 annuallyFunction: CybersecurityExperience: 8+ yearsEducation: bachelorsSkills: ["Technical communication","Collaboration","Mentorship","Risk-based thinking","Stakeholder influence"]

Embed security into engineering platforms and CI/CD pipelines to deliver secure-by-default developer experiences. Build and scale internal DevSecOps tooling, including pipeline libraries, security plugins, and automation frameworks. Drive cloud-native security architecture across AWS and Azure, covering Kubernetes, containerized workloads, and infrastructure-as-code. Integrate and standardize security testing (SAST, DAST, SCA, container scanning), support continuous compliance and automated evidence collection, and lead vulnerability remediation alongside threat modeling and architecture reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
S&P Global
S&P Global
1 month ago

Lead InfoSec Engineer, DevSecOps

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 37 days agoStatus: Live

Job Summary

Embed security into engineering platforms and CI/CD pipelines to deliver secure-by-default developer experiences. Build and scale internal DevSecOps tooling, including pipeline libraries, security plugins, and automation frameworks. Drive cloud-native security architecture across AWS and Azure, covering Kubernetes, containerized workloads, and infrastructure-as-code. Integrate and standardize security testing (SAST, DAST, SCA, container scanning), support continuous compliance and automated evidence collection, and lead vulnerability remediation alongside threat modeling and architecture reviews.
Location: New York, London
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Embed automated security controls into CI/CD pipelines across build, test, and release stages using risk-based security gates and security testing (SAST, DAST, SCA, container scanning).
  • •Build and maintain internal DevSecOps tooling and platform extensions, including reusable pipeline libraries, security plugins, and automation frameworks.
  • •Drive cloud-native security architecture across AWS and Azure, implementing controls for Kubernetes, containerized workloads, and infrastructure-as-code.
  • •Evaluate and integrate security tools across application, pipeline, container, and cloud needs to standardize and reduce complexity.
  • •Provide technical leadership and mentorship as an embedded security subject matter expert; lead vulnerability management, remediation, and participate in threat modeling and architecture reviews.

Pay and Benefits

Salary: USD 100,000 - 130,000 annually
Perks:Health InsurancePaid LeaveLearning BudgetRetirement

Key Requirements

  • •8+ years of software engineering, DevOps, or DevSecOps experience in enterprise or regulated environments, with hands-on CI/CD pipeline security.
  • •Expertise with AWS, Azure, or Google Cloud, including containerization (Docker, Kubernetes, OpenShift) and infrastructure-as-code (Terraform, CloudFormation, Pulumi).
  • •Strong application security knowledge (OWASP Top 10, secure coding) and experience with SAST, DAST, and SCA tools.
  • •Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience in DevSecOps or security engineering.
  • •Ability to build and maintain internal tooling using scripting languages such as Python or Go for automation and platform development.
Experience:8+ yearsEnterpriseRegulated environments
Education:Bachelor's
Skills:Technical communicationCollaborationMentorshipRisk-based thinkingStakeholder influence
Certifications:CISSPCISMCCSPAWS Certified Security SpecialtyAzure Security Engineer
Tech Stack:AWSAzureGoogle CloudDockerKubernetesOpenShiftTerraformCloudFormationPulumiOWASP Top 10SASTDASTSCAContainer scanningCI/CDGitPythonGoInfrastructure-as-CodeHashiCorp Vault

Company Brief

S&P Global
Provides financial information, analytics, benchmarks, and credit ratings to markets and institutions worldwide, offering data, research, indices, and risk assessment tools across the financial services and commodities sectors.
Industry: Data Infrastructure
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: New York, United States
Founded: 1917
WebsiteLinkedIn