Lead Penetration Tester - Cloud & App Security

S&P Global, Inc.

Princeton (NJ)

Hybrid

USD 135,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

S&P Global Corporate is seeking a Lead Penetration Test Engineer to advance our offensive security program. You will conduct hands-on testing across web, cloud, and infrastructure, develop custom tooling, and drive remediation with engineering teams in a hybrid US-wide environment.

The ideal candidate has 8+ years in information security, strong OSCP/related certs, expertise in OWASP, MITRE ATT&CK, and CI/CD security, and can translate complex findings into actionable risk guidance for

Qualifications

  • 8+ years in information security with a focus on penetration testing and vulnerability management.
  • Hands-on with Burp Suite, Nessus, Metasploit, Nmap and OWASP Top 10.
  • Experience identifying and exploiting common vulnerabilities (XSS, SQLi, IDOR).
  • Familiarity with CVE/CVSS/CWE classification.
  • Strong scripting/programming skills: Bash, Python, Go, PowerShell, JS.
  • Experience integrating security testing into CI/CD pipelines (DAST/SAST/SCA).
  • Ability to translate complex findings into clear reports for technical and executive audiences.
  • At least one offensive security cert (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).
  • Bachelor's degree in CS/IS or equivalent.

Responsibilities

  • Conduct penetration tests across web apps, infrastructure, and cloud environments using both manual and automated techniques.
  • Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.
  • Apply cloud‑specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing.
  • Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen security across lifecycles.
  • Lead and participate in attack simulations and threat research to validate controls and improve response capabilities.
  • Communicate and present findings to technical and non‑technical stakeholders and provide remediation guidance.

Skills

Burp Suite
Nessus
Metasploit
Nmap
OWASP Top 10
MITRE ATT&CK
Scripting
Cloud security
CI/CD security
Security testing

Education

Bachelor’s degree in Computer Science / Information Systems

Tools

Python
Bash
PowerShell
Go
JavaScript

Job description

S&P Global Corporate is seeking a Lead Penetration Test Engineer to advance our offensive security program. You will conduct hands-on testing across web, cloud, and infrastructure, develop custom tooling, and drive remediation with engineering teams in a hybrid US-wide environment.

The ideal candidate has 8+ years in information security, strong OSCP/related certs, expertise in OWASP, MITRE ATT&CK, and CI/CD security, and can translate complex findings into actionable risk guidance for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Penetration Test Engineer | Hybrid & Cloud Security
Lead Penetration Test Engineer | Hybrid & Cloud Security

S&P Global • New York (NY)

Hybrid
USD 135,000 - 200,000
Lead Penetration Test Engineer — Hybrid (2 days onsite)
Lead Penetration Test Engineer — Hybrid (2 days onsite)

S&P Global • Englewood (CO)

Hybrid
USD 135,000 - 200,000
Lead Penetration Tester — Cloud & AppSec Lead
Lead Penetration Tester — Cloud & AppSec Lead

Relha LLC • Princeton (NJ), Northern (KY)

Hybrid
USD 135,000 - 200,000
Health & Wellness
Flexible downtime
Continuous learning
+3
Lead Pen Test Engineer - Hybrid, Cloud & App Security
Lead Pen Test Engineer - Hybrid, Cloud & App Security

spgi • Princeton (NJ)

Hybrid
USD 140,000 - 190,000
Lead Penetration Test Engineer
Lead Penetration Test Engineer

spgi • Princeton (NJ)

Hybrid
USD 140,000 - 190,000
Remote Lead Penetration Tester — Offensive Security Lead
Remote Lead Penetration Tester — Offensive Security Lead

Alignerr • Seattle (WA)

On-site
USD 165,000 - 248,000
Fully remote
Contract role
Diversified engagements
Senior Penetration Tester: Cloud, Web & App Security
Senior Penetration Tester: Cloud, Web & App Security

Triwill Group • United States

Remote
USD 120,000 - 170,000
Career development
Training reimbursement
Competitive compensation
+2
Senior Penetration Tester – Offensive Security Lead
Senior Penetration Tester – Offensive Security Lead

LPL Financial • San Diego (CA)

On-site
USD 123,000 - 204,000
401K matching
Health benefits
Employee stock options
+2
Senior Penetration Tester - Remote, Cloud & App Security
Senior Penetration Tester - Remote, Cloud & App Security

Schellman • United States

On-site
USD 80,000 - 110,000
Flexible work environment
Continuous education opportunities
Annual team meet-ups
Senior Penetration Test Lead — Remote Engagements
Senior Penetration Test Lead — Remote Engagements

HeadHR • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Remote work