Lead Security Engineer

S&P Global, Inc.

Gdańsk

Hybrid

PLN 180,000 - 360,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

S&P Global, Inc. in Gdańsk, Poland, seeks a senior security testing professional to lead hands-on penetration testing across product portfolios and to direct red team activities within approved scope.

You will drive AI-assisted testing adoption, engage with senior leadership on findings, and mentor teams in advanced security assessment techniques to strengthen the enterprise-wide security posture.

Qualifications

  • 5+ years of experience in penetration testing, red teaming, or offensive security engineering with leadership experience.
  • Strong web, API, and cloud-native security testing across multiple environments.
  • Experience with microservices, CI/CD, containers, and SaaS security frameworks.
  • Advanced scripting in Python/Go/JavaScript for tooling and exploit development.
  • Familiarity with OWASP Top 10, CWE/SANS Top 25, and secure development practices.
  • Excellent communication skills for executive leadership and technical teams.

Responsibilities

  • Lead hands-on application and cloud penetration testing across product portfolios.
  • Plan, conduct, and supervise red team activities within approved scope.
  • Drive AI-assisted testing techniques to improve coverage and quality.
  • Engage with senior leadership to explain findings and remediation priorities.
  • Develop educational programs and guidance from findings and remediation efforts.

Skills

Penetration testing
Red team leadership
Web/API/Cloud security
CI/CD security
Scripting (Python/Go/JS)
Security governance

Tools

Jenkins
GitLab CI
Azure DevOps
Docker
Kubernetes

Job description

About the Role

Grade Level (for internal use): 12 The Team: Risk & Valuations Services (RVS) is part of S&P Global Market Intelligence, providing critical data, insights, and analytics to diverse customer segments across global financial markets. Our security engineering team operates as a highly collaborative, strategic unit where leaders combine deep offensive security expertise with business acumen to proactively identify and mitigate enterprise-scale risks across our expanding product portfolio. We value innovation, cross-divisional partnership, and the development of security capabilities that enable safe, authorized operations while driving S&P Global's mission to provide essential intelligence for confident decision-making.

Responsibilities and Impact
  • Lead and oversee hands‑on application and cloud penetration testing across assigned product portfolios, focusing on real-world exploitability and business risk while directing security engineering strategy for the region.
  • Plan, conduct, and supervise red team activities in accordance with approved scope, authorization, and Rules of Engagement defined by Corporate Offensive Security, ensuring team compliance and operational excellence.
  • Drive adoption of AI‑assisted testing techniques (e.g., intelligent discovery, fuzzing, and analysis) across security teams to improve coverage, efficiency, and testing quality while establishing best practices.
  • Engage directly with senior product and engineering leadership to explain attack paths, prioritize findings, and facilitate timely, durable remediation while building organizational security capabilities.
  • Establish validation processes for remediation effectiveness, ensuring exploit paths are fully closed and do not regress, while mentoring team members on advanced security assessment techniques.
  • Transform findings and remediation efforts into educational programs and strategic guidance to drive stronger proactive security posture in alignment with Corporate and Divisional security teams, contributing to enterprise offensive security standards, playbooks, and threat scenarios while producing executive‑level reports that communicate exploitability, impact, and remediation status to senior leadership.
What We're Looking For
Basic Required Qualifications
  • 5+ years of experience in penetration testing, red teaming, application security, or offensive security engineering with demonstrated leadership experience in managing security teams or strategic initiatives
  • Strong expertise in web, API, and cloud‑native security testing across multiple environments, including authentication, authorization, and identity abuse scenarios with ability to architect comprehensive security assessment programs
  • Experience testing modern architectures including microservices, CI/CD platforms (such as Jenkins, GitLab CI, or Azure DevOps), containerization technologies (such as Docker, Kubernetes, or OpenShift), and SaaS security frameworks
  • Advanced scripting and development experience in programming languages (such as Python, Go, JavaScript, or similar technologies) to support exploit development, automation, and security tooling at enterprise scale
  • Deep knowledge of security frameworks including OWASP Top 10, CWE/SANS Top 25, and secure development practices with proven ability to establish governance processes within formal red team programs
  • Exceptional written and verbal communication skills with demonstrated ability to convey complex security risks to executive leadership, technical teams, and business stakeholders across all organizational levels
Additional Preferred Qualifications
  • Advanced offensive security certifications (such as OSCP, OSCE, GXPN, CRTO) or equivalent professional experience demonstrating mastery in penetration testing and red team leadership
  • Experience testing AI‑enabled or agentic systems with ability to develop security assessment frameworks for emerging technologies and guide organizational adoption strategies
  • Proven experience with threat modeling and secure architecture review including ability to influence enterprise security architecture decisions and mentor teams on advanced security design principles
  • Demonstrated success in building and scaling security programs across multiple business units or geographic regions with experience driving organizational security culture transformation
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Poland

On-site
PLN 254,022 - 381,033
Health care coverage
Generous time off
Continuous learning resources
+2
Senior Offensive Security Lead - Cloud & App PenTesting
Senior Offensive Security Lead - Cloud & App PenTesting

S&P Global, Inc. • Poland

On-site
PLN 254,022 - 381,033
Health care coverage
Generous time off
Continuous learning resources
+2
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Offensive Security Lead Expert
Offensive Security Lead Expert

Experis • Wrocław

Hybrid
PLN 180,000 - 300,000
Lead Security Engineer: Cloud, AI & Offensive Security
Lead Security Engineer: Cloud, AI & Offensive Security

S&P Global, Inc. • Gdańsk

Hybrid
PLN 180,000 - 360,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Senior Cybersecurity Delivery Manager
Senior Cybersecurity Delivery Manager

EPAM Systems Inc • Polska

On-site
PLN 260,000 - 450,000
Offensive Security Engineer: AI App Security & Fuzzing
Offensive Security Engineer: AI App Security & Fuzzing

Commit • Warszawa

On-site
PLN 60,000 - 90,000
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Senior Security Engineer (Red Team)
Senior Security Engineer (Red Team)

Atos SE • Bydgoszcz

On-site
PLN 213,310 - 298,634
Dynamic international environment
Professional growth opportunities
Competitive salary and benefits package