Lead Penetration Test Engineer
Core
Lead a team of penetration testers to conduct offensive security assessments, vulnerability management, and attack simulations across web applications, infrastructure, and cloud environments.
Role type
Lead Penetration Test Engineer (Offensive Security)
Builds
Security testing capabilities, remediation plans, and threat assessment strategies for S&P Global's clients and internal systems.
Domain
Cybersecurity / Offensive Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, vulnerability management, cloud offensive techniques, scripting (Python, Bash, Go, PowerShell), DAST/SAST/SCA integration, threat modeling, report writing
Preferred skills
Cloud security (AWS/Azure/GCP), AI/ML adversarial testing, MITRE ATT&CK framework application, secure SDLC practices, Java application security
Technologies
Burp Suite, Nessus, Metasploit, Nmap, CI/CD pipelines, AWS, Azure, GCP
Responsibilities
Conduct comprehensive penetration tests of web apps and cloud environments; develop custom tools to automate security testing; collaborate with engineering teams on vulnerability remediation; lead attack simulations and tabletop exercises; research emerging threats and attack vectors; present findings to technical and non-technical stakeholders
Seniority
Senior, hands-on IC with team leadership