Lead Security Engineer

S&P Global, Inc.

Poland

On-site

PLN 254,022 - 381,033

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health care coverage
Generous time off
Continuous learning resources
Retirement planning
Family-friendly benefits

Job summary

S&P Global, Inc. is looking for a seasoned leader in security engineering to manage critical penetration testing across diverse applications and cloud platforms. With a focus on real-world exploitability, your expertise will help enhance security across our expansive product portfolio.

The ideal candidate will have over 10 years of experience in offensive security with strong leadership abilities, particularly in web and API security testing. Benefits include health care, flexible downtime, and a commitment to continuous learning.

Qualifications

  • 10+ years in penetration testing or offensive security engineering with leadership experience.
  • Strong expertise in web, API, and cloud-native security testing methods.
  • Experience with CI/CD platforms and containerization technologies.

Responsibilities

  • Lead application and cloud penetration testing across product portfolios.
  • Plan and supervise red team activities ensuring compliance.
  • Drive adoption of AI-assisted testing techniques to improve security.

Skills

Penetration testing
Cloud security testing
API security testing
Advanced scripting
Effective communication

Tools

Python
Go
JavaScript
Docker
Kubernetes

Job description

About the Role

Grade Level (for internal use): 12

Risk & Valuations Services (RVS) is part of S&P Global Market Intelligence, providing critical data, insights, and analytics to diverse customer segments across global financial markets. The security engineering team operates as a highly collaborative, strategic unit where leaders combine deep offensive security expertise with business acumen to proactively identify and mitigate enterprise‑scale risks across our expanding product portfolio.

Responsibilities and Impact
  • Lead and oversee hands‑on application and cloud penetration testing across assigned product portfolios, focusing on real‑world exploitability and business risk while directing security engineering strategy for the region.
  • Plan, conduct, and supervise red team activities in accordance with approved scope, authorization, and Rules of Engagement defined by Corporate Offensive Security, ensuring team compliance and operational excellence.
  • Drive adoption of AI‑assisted testing techniques (e.g., intelligent discovery, fuzzing, and analysis) across security teams to improve coverage, efficiency, and testing quality while establishing best practices.
  • Engage directly with senior product and engineering leadership to explain attack paths, prioritize findings, and facilitate timely, durable remediation while building organizational security capabilities.
  • Establish validation processes for remediation effectiveness, ensuring exploit paths are fully closed and do not regress, while mentoring team members on advanced security assessment techniques.
  • Transform findings and remediation efforts into educational programs and strategic guidance to drive stronger proactive security posture in alignment with Corporate and Divisional security teams, contributing to enterprise offensive security standards, playbooks, and threat scenarios while producing executive‑level reports that communicate exploitability, impact, and remediation status to senior leadership.
What We're Looking For
Basic Required Qualifications
  • 10+ years of experience in penetration testing, red teaming, application security, or offensive security engineering with demonstrated leadership experience in managing security teams or strategic initiatives.
  • Strong expertise in web, API, and cloud‑native security testing across multiple environments, including authentication, authorization, and identity abuse scenarios with ability to architect comprehensive security assessment programs.
  • Experience testing modern architectures including microservices, CI/CD platforms (such as Jenkins, GitLab CI, or Azure DevOps), containerization technologies (such as Docker, Kubernetes, or OpenShift), and SaaS security frameworks.
  • Advanced scripting and development experience in programming languages (such as Python, Go, JavaScript, or similar technologies) to support exploit development, automation, and security tooling at enterprise scale.
  • Deep knowledge of security frameworks including OWASP Top 10, CWE/SANS Top 25, and secure development practices with proven ability to establish governance processes within formal red team programs.
  • Exceptional written and verbal communication skills with demonstrated ability to convey complex security risks to executive leadership, technical teams, and business stakeholders across all organizational levels.
Additional Preferred Qualifications
  • Advanced offensive security certifications (such as OSCP, OSCE, GXPN, CRTO) or equivalent professional experience demonstrating mastery in penetration testing and red team leadership.
  • Experience testing AI‑enabled or agentic systems with ability to develop security assessment frameworks for emerging technologies and guide organizational adoption strategies.
  • Proven experience with threat modeling and secure architecture review including ability to influence enterprise security architecture decisions and mentor teams on advanced security design principles.
  • Demonstrated success in building and scaling security programs across multiple business units or geographic regions with experience driving organizational security culture transformation.
Benefits
  • Health & Wellness: Health care coverage designed for the mind and body.
  • Flexible Downtime: Generous time off helps keep you energized for your time on.
  • Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
  • Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company‑matched student loan contribution, and financial wellness programs.
  • Family Friendly Perks: It's not just about you. S&P Global has perks for your partners and little ones, too, with some best‑in‑class benefits for families.
  • Beyond the Basics: From retail discounts to referral incentive awards small perks can make a big difference.
Equal Opportunity Employer

S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment. If you need an accommodation during the application process due to a disability, please send an email to EEO.Compliance@spglobal.com and your request will be forwarded to the appropriate person. US Candidates Only: Know Your Rights: Workplace discrimination is illegal.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Offensive Security Lead - Cloud & App PenTesting
Senior Offensive Security Lead - Cloud & App PenTesting

S&P Global, Inc. • Poland

On-site
PLN 254,000 - 382,000
Health care coverage
Generous time off
Continuous learning resources
+2
Senior Offensive Security Engineer, Penetration Testing
Senior Offensive Security Engineer, Penetration Testing

Procter & Gamble Company • Poland

On-site
PLN 283,000 - 378,000
Private health care
P&G stock options
Regular salary increases and promotions
+1
Tech Risk Advisory - Red Team Operator/Pentester - Associate/Vice President - Warsaw
Tech Risk Advisory - Red Team Operator/Pentester - Associate/Vice President - Warsaw

Goldman Sachs • Warszawa

On-site
PLN 80,000 - 100,000
Senior Penetration Testing Engineer IRC301690
Senior Penetration Testing Engineer IRC301690

GlobalLogic • Kraków

On-site
PLN 180,000 - 280,000
Empowering Projects
Empowering Growth
DE&I Matters
+3
Tech Risk Advisory - Red Team Operator - Associate/Vice President - Warsaw Warsaw · Poland · Vi[...]
Tech Risk Advisory - Red Team Operator - Associate/Vice President - Warsaw Warsaw · Poland · Vi[...]

Goldman Sachs Bank AG • Warszawa

On-site
Software Engineer - Commodity Insights
Software Engineer - Commodity Insights

S&P Global, Inc. • Województwo pomorskie

On-site
PLN 150,000 - 190,000
Health & Wellness
Flexible Downtime
Continuous Learning
+3
Offensive Security Engineer, Penetration Testing
Offensive Security Engineer, Penetration Testing

Procter & Gamble • Poland

On-site
PLN 180,000 - 260,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Senior (Staff) Penetration Tester
Senior (Staff) Penetration Tester

Snowflake • Warszawa

On-site
PLN 296,000 - 372,000
Fast-paced working environment
Strong support for innovation
Collaborative team culture
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

Hybrid
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4