Remote Lead Penetration Test Engineer-Cloud & App Security

S&P Global, Inc.

New Jersey

Hybrid

USD 135,000 - 200,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health & Wellness
Flexible Downtime
Continuous Learning
Invest in Your Future
Family Friendly Perks
Beyond the Basics

Job summary

S&P Global is seeking a Lead Penetration Test Engineer to drive offensive security across web, cloud, and infrastructure. You will conduct penetration tests, re-testing, vulnerability assessments, and threat modeling, delivering clear remediation guidance.

The role requires 8+ years in information security, hands-on expertise with Burp Suite, Nessus, Metasploit, Nmap, and scripting in Bash, Python, or PowerShell. A relevant OSCP/GPEN or similar cert is expected, with ability to brief executives.

Qualifications

  • 8+ years in information security with focus on pentesting and vulnerability management.
  • Experience with DAST, SAST, SCA and CI/CD integration.
  • Strong scripting or programming skills in Bash, Python, Go, PowerShell, or JavaScript.

Responsibilities

  • Conduct penetration testing of web apps, infrastructure, and cloud environments using manual and automated techniques.
  • Develop custom tools and CI/CD integrated security testing
  • Lead threat assessments, attack simulations, and risk-based remediation planning.
  • Communicate findings clearly to technical and non-technical stakeholders.

Skills

Penetration testing
Scripting
Reporting to execs
Cloud security
Offensive security

Education

Bachelor's degree in CS/IS or related field

Tools

Burp Suite
Nessus
Metasploit
Nmap

Job description

S&P Global is seeking a Lead Penetration Test Engineer to drive offensive security across web, cloud, and infrastructure. You will conduct penetration tests, re-testing, vulnerability assessments, and threat modeling, delivering clear remediation guidance.

The role requires 8+ years in information security, hands-on expertise with Burp Suite, Nessus, Metasploit, Nmap, and scripting in Bash, Python, or PowerShell. A relevant OSCP/GPEN or similar cert is expected, with ability to brief executives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Penetration Test Lead — Remote Engagements
Senior Penetration Test Lead — Remote Engagements

HeadHR • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Remote work
Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000
Penetration Testing Manager - Offensive Security Lead
Penetration Testing Manager - Offensive Security Lead

EY • Las Vegas (NV)

On-site
USD 145,000 - 266,000
Global opportunities
Penetration Tester
Penetration Tester

TalentFish • Illinois

Remote
USD 100,000 - 160,000
Lead Application Security Engineer
Lead Application Security Engineer

Cisco • Austin (TX)

On-site
USD 139,000 - 204,000
Medical, dental & vision insurance
401(k) with company match
Paid parental leave
+1
Senior Penetration Tester & Technical Lead - Remote
Senior Penetration Tester & Technical Lead - Remote

Trespass Security LLC • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Testing Engineer – VP
Penetration Testing Engineer – VP

Jobtailor • Massachusetts

On-site
USD 120,000 - 160,000
Senior Penetration Tester - Remote, Cloud & App Security
Senior Penetration Tester - Remote, Cloud & App Security

Schellman • United States

On-site
USD 80,000 - 110,000
Flexible work environment
Continuous education opportunities
Annual team meet-ups
Lead Penetration Tester
Lead Penetration Tester

Infinite Ranges • United States

Remote
USD 138,000 - 248,000