Lead penetration testing across web, infrastructure, and cloud environments for S&P Global, a financial intelligence provider. Develop offensive security tools, assess threats, and guide remediation.
Responsibilities
Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments
Perform re-testing, vulnerability scanning, and threat assessments across diverse environments
Develop custom scripts, tools, and methodologies to improve penetration testing and automate security testing in CI/CD pipelines
Apply cloud offensive techniques including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing
Collaborate with engineering and development teams on vulnerability analysis, remediation plans, and application security
Perform DAST, SAST, and SCA security assessments
Lead and participate in attack simulations and tabletop exercises
Research emerging threats, attack vectors, and adversarial techniques
Design and execute threat assessments using intelligence feeds and threat actor analysis
Present findings to technical and non-technical stakeholders
Provide remediation guidance and risk mitigation strategies
Requirements
Minimum 8 years of experience in information security focused on penetration testing, application security, and vulnerability management
Hands-on experience with Burp Suite, Nessus, Metasploit, and Nmap
Knowledge of OWASP Top 10, MITRE ATT&CK, and PTES
Expertise identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR
Familiarity with CVE, CVSS, and CWE
Strong scripting or programming skills in Bash, Python, Go, PowerShell, or JavaScript
Experience with DAST, SAST, SCA, credential scanning, and CI/CD security integration
Ability to communicate technical findings through actionable reports and brief cross-functional teams and executives
At least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT
Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent experience
US-based candidates must have indefinite right to work in the US; Canada-based candidates must have indefinite right to work in Canada
Benefits
Health care coverage designed for the mind and body
Generous time off
Continuous learning resources and career development
Competitive pay
Retirement planning
Continuing education program with company-matched student loan contribution
SDET II building automated testing frameworks and QA strategies for Best Buy, Canada’s technology retailer. Testing Java/Groovy applications across APIs, UI, microservices, frontend, and backend systems.
Test Engineer designing automated manufacturing test stations and VB.NET/Python software. Supporting reliable testing for ORBCOMM’s IoT products across engineering and production.
Photonic Test Engineer developing cryogenic measurement procedures for quantum emitters. Testing and improving integrated photonic circuits for scalable quantum technologies at Photonic.
Integration and test engineer validating naval communications systems for L3Harris Technologies. Designing, automating, executing, and troubleshooting system verification tests.
Platform test engineer validating Nokia’s routers, Ethernet optics, and hardware/software features. Developing automated Linux regression tests and troubleshooting with engineering teams.
Automation QA Engineer testing Torrero’s white - label casino, sportsbook, and B2B aggregation platforms. Ensuring web and mobile product quality through functional, integration, regression, and usability testing.
SDET building manual and automated tests for Picton Investments’ alternative investment applications. Developing Playwright, API, and end - to - end testing frameworks to ensure reliable user experiences.
Analyste QA senior concevant la couverture et les scénarios pré - UAT pour la plateforme hypothécaire fintech de nesto. Coordination du triage, analyse des automatisations et soutien client pendant l'UAT.