Lead Penetration Test Engineer | Hybrid & Cloud Security

S&P Global

New York (NY)

Hybrid

USD 135,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

S&P Global is seeking a Lead Penetration Test Engineer to conduct comprehensive pentests of web apps, infrastructure, and cloud environments across multiple sites in the US. You will develop scripts, drive vulnerability management, and lead threat simulations to strengthen security across development and production lifecycles.

The role requires 8+ years in information security, hands-on pentesting with Burp Suite/Nessus/Metasploit/Nmap, and certifications like OSCP or CREST.

Qualifications

  • Bachelor’s degree or equivalent experience in computer science, information systems, or related field.
  • 8+ years in information security focusing on pentesting, app security, and vulnerability management.
  • Hands-on experience with pentesting tools (Burp Suite, Nessus, Metasploit, Nmap) and methods (OWASP Top 10, MITRE ATT&CK, PTES).
  • Expertise in identifying and exploiting common infra and web app vulnerabilities (XSS, SQLi, IDOR).
  • Familiarity with vulnerability scoring (CVE, CVSS, CWE).
  • Strong scripting/programming (Bash, Python, Go, PowerShell, JavaScript).
  • Experience integrating security testing into CI/CD pipelines and producing actionable reports.
  • At least one OSCP/OSCE3/OSEP/GXPN/CREST CRT/CCT certification.

Responsibilities

  • Lead and perform penetration tests across web apps, infrastructure, and cloud environments.
  • Develop custom scripts/tools to enhance testing and automate security checks in CI/CD.
  • Conduct vulnerability assessments and threat modeling to improve security controls.

Skills

Penetration testing
Scripting
CI/CD security
Threat modeling
Cloud security
Communication to executives
Vulnerability assessment
Security reporting
OSCP/OCSE3/SEP/GPEN/CREST

Education

Bachelor’s degree in CS/IS or related field

Tools

Burp Suite
Nessus
Metasploit
Nmap

Job description

S&P Global is seeking a Lead Penetration Test Engineer to conduct comprehensive pentests of web apps, infrastructure, and cloud environments across multiple sites in the US. You will develop scripts, drive vulnerability management, and lead threat simulations to strengthen security across development and production lifecycles.

The role requires 8+ years in information security, hands-on pentesting with Burp Suite/Nessus/Metasploit/Nmap, and certifications like OSCP or CREST.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Penetration Tester - Cloud & App Security
Lead Penetration Tester - Cloud & App Security

S&P Global, Inc. • Princeton (NJ)

Hybrid
USD 135,000 - 200,000
Lead Penetration Test Engineer — Hybrid (2 days onsite)
Lead Penetration Test Engineer — Hybrid (2 days onsite)

S&P Global • Englewood (CO)

Hybrid
USD 135,000 - 200,000
Lead Pen Test Engineer - Hybrid, Cloud & App Security
Lead Pen Test Engineer - Hybrid, Cloud & App Security

spgi • Princeton (NJ)

Hybrid
USD 140,000 - 190,000
Lead Penetration Test Engineer
Lead Penetration Test Engineer

spgi • Princeton (NJ)

Hybrid
USD 140,000 - 190,000
Security Engineer
Security Engineer

Horizontal Talent • Brooklyn Park (MN)

On-site
USD 120,000 - 160,000
Senior Penetration Tester: Cloud, Web & App Security
Senior Penetration Tester: Cloud, Web & App Security

Triwill Group • United States

Remote
USD 120,000 - 170,000
Career development
Training reimbursement
Competitive compensation
+2
Penetration Tester
Penetration Tester

OVA.Work • New York (NY)

Hybrid
USD 110,000 - 180,000
Senior Penetration Test Lead — Remote Engagements
Senior Penetration Test Lead — Remote Engagements

HeadHR • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Remote work
Senior Penetration Tester — Advanced Security Testing Lead
Senior Penetration Tester — Advanced Security Testing Lead

CyberCX • Town of Florida (NY)

On-site
USD 95,000 - 150,000
Senior Pen Test Lead: Drive Security Assessments
Senior Pen Test Lead: Drive Security Assessments

CyberCX • South Carolina

On-site
USD 90,000 - 130,000