Lead Penetration Test Engineer

Posted 3 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Lead penetration testing across web, infrastructure, and cloud environments for S&P Global, a financial intelligence provider. Develop offensive security tools, assess threats, and guide remediation.

Responsibilities

  • Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments
  • Perform re-testing, vulnerability scanning, and threat assessments across diverse environments
  • Develop custom scripts, tools, and methodologies to improve penetration testing and automate security testing in CI/CD pipelines
  • Apply cloud offensive techniques including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing
  • Collaborate with engineering and development teams on vulnerability analysis, remediation plans, and application security
  • Perform DAST, SAST, and SCA security assessments
  • Lead and participate in attack simulations and tabletop exercises
  • Research emerging threats, attack vectors, and adversarial techniques
  • Design and execute threat assessments using intelligence feeds and threat actor analysis
  • Present findings to technical and non-technical stakeholders
  • Provide remediation guidance and risk mitigation strategies

Requirements

  • Minimum 8 years of experience in information security focused on penetration testing, application security, and vulnerability management
  • Hands-on experience with Burp Suite, Nessus, Metasploit, and Nmap
  • Knowledge of OWASP Top 10, MITRE ATT&CK, and PTES
  • Expertise identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR
  • Familiarity with CVE, CVSS, and CWE
  • Strong scripting or programming skills in Bash, Python, Go, PowerShell, or JavaScript
  • Experience with DAST, SAST, SCA, credential scanning, and CI/CD security integration
  • Ability to communicate technical findings through actionable reports and brief cross-functional teams and executives
  • At least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT
  • Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent experience
  • US-based candidates must have indefinite right to work in the US; Canada-based candidates must have indefinite right to work in Canada

Benefits

  • Health care coverage designed for the mind and body
  • Generous time off
  • Continuous learning resources and career development
  • Competitive pay
  • Retirement planning
  • Continuing education program with company-matched student loan contribution
  • Financial wellness programs
  • Family benefits and perks
  • Retail discounts
  • Referral incentive awards

Job title

Job type

Full Time

Experience level

Senior

Salary

$135,000 - $200,000 per year

Degree requirement

Bachelor's Degree

Tech skills

CloudJavaScriptPythonSQLGo

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.