Lead Penetration Test Engineer
Core
Lead offensive security engineer conducting penetration tests, vulnerability assessments, and attack simulations across web applications, infrastructure, and cloud environments.
Role type
Lead Penetration Test Engineer
Builds
Security testing capabilities, remediation plans, and threat assessment strategies for S&P Global Ratings clients and internal systems.
Domain
Cybersecurity / Offensive Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing (manual & automated), Cloud offensive techniques (IAM abuse, container exploitation), Vulnerability management, Scripting (Python, Bash, Go, PowerShell), Security assessment tools (DAST, SAST, SCA), Reporting & risk communication
Preferred skills
AI/ML security and adversarial testing, MITRE ATT&CK framework application, Secure software development lifecycle (SDLC), Java application security
Technologies
Burp Suite, Nessus, Metasploit, Nmap, AWS, Azure, GCP
Responsibilities
Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments; Develop custom scripts and tools to automate security testing within CI/CD pipelines; Collaborate with engineering teams to analyze vulnerabilities and develop remediation plans; Lead attack simulations and tabletop exercises to validate security controls; Research emerging threats and attack vectors to inform offensive strategies; Communicate security findings and risk mitigation strategies to technical and non-technical stakeholders
Seniority
Senior, hands-on IC with leadership responsibilities