About the Role
Grade Level (for internal use): 08
Key Responsibilities
- Secure Development Guidance: Assist in providing actionable security guidance to engineering teams across server-side development, UI frameworks, and cloud integrations.
- Threat Modeling & Reviews: Partner with senior engineers to perform threat modeling, secure design reviews, and secure code reviews—with a growing focus on auditing AI agents, LLM pipelines, and cognitive workflows.
- AI Risk Assessment: Assist in identifying vulnerabilities unique to AI systems (such as prompt injection, data poisoning, and insecure output handling) and help evaluate new AI technologies adopted by the business.
- Security Automation: Leverage Python and open-source security tools to build, maintain, and automate security testing within the CI/CD pipeline.
- Vulnerability Research: Help analyze, triage, and remediate vulnerabilities discovered during automated scans or manual testing, acting as a technical advisor for engineering teams.
- Repeatable Security Patterns: Implement and support repeatable application security blueprints, ensuring applications and AI agents are appropriately sandboxed and segmented based on data sensitivity.
- Continuous Learning: Keep pace with evolving security trends, zero-day vulnerabilities, and emerging frameworks for securing AI architectures (such as the OWASP Top 10 for LLMs).
Basic Qualifications
- Education: Bachelor’s degree in Computer Science, Information Security, a related technical field, or equivalent practical experience.
- Experience: 1 year or more of professional experience in Information Security, Application Security, or a highly security-focused software development role.
Technical Skills & Core Competencies
- Scripting & Programming: Proficiency in Python for security scripting, automation, or data handling (exposure to Java or JavaScript/Angular is a plus).
- AI/LLM Awareness: Foundational knowledge of AI concepts, LLM architectures, or AI agents, including an understanding of how to securely interact with APIs and handle data privacy in AI workflows.
- Application Security Basics: Familiarity with core AppSec concepts, web services, microservices/SOA architecture, and standard vulnerability frameworks (OWASP Top 10).
- Network & Cryptography Fundamentals: Solid understanding of TCP/IP networking, transport layer security (TLS/DTLS), PKI, certificate management, and basic encryption concepts.
Benefits
- Health & Wellness: Health care coverage designed for the mind and body.
- Flexible Downtime: Generous time off helps keep you energized for your time on.
- Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
- Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
- Family Friendly Perks: It’s not just about you. S&P Global has perks for your partners and little ones, too, with some best-in class benefits for families.
- Beyond the Basics: From retail discounts to referral incentive awards—small perks can make a big difference.
For more information on benefits by country visit: https://spgbenefits.com/benefit-summaries
Equal Opportunity Employer
S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment.
If you need an accommodation during the application process due to a disability, please send an email to EEO.Compliance@spglobal.com and your request will be forwarded to the appropriate person.
US Candidates Only: Know Your Rights: Workplace discrimination is illegal.