Lead InfoSec Engineer, DevSecOps

S&P Global

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
New York, NYLondon, United Kingdom
Salary
$100,000–$130,000 / yr
Posted
53 days ago
Freshness
Confirmed live yesterday
Closes
Jul 20, 2027

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $159k
This role $115k
$88k most similar roles pay here $217k

This role pays less than 92% of similar roles. Most pay $126,800–$192,050 — the shaded band above. At the midpoint, this role pays about $115k versus about $159k for comparable roles.

Based on 240 similar postings.

Employer

About S&P Global

S&P Global delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies and expertise they need to move ahead.

S&P Global currently has 46 open roles on FindRole.

Listed pay typically runs $142,000–$200,000 across 37 roles with salary data.

Most-posted roles

View all roles at S&P Global

At a glance

TL;DR · Lead InfoSec Engineer, DevSecOps

Lead InfoSec Engineer, DevSecOps joins the engineering team to embed security directly into CI/CD pipelines and developer workflows. This role focuses on creating secure-by-default experiences by building internal DevSecOps tooling, reusable pipeline libraries, and automated security gates for build, test, and release stages. The engineer will manage risk-based testing including SAST, DAST, and SCA, while driving cloud-native security architecture across AWS and Azure environments using Kubernetes and infrastructure-as-code tools like Terraform or Pulumi. Key responsibilities include vulnerability management, threat modeling, and translating regulatory requirements into automated controls for audit readiness. The role requires proficiency in Python or Go for automation, experience with containerization technologies like Docker and OpenShift, and a deep understanding of OWASP Top 10 principles to secure complex cloud-native applications and infrastructure within regulated environments.

What you'll do

  • Embed automated security controls and risk-based gates into CI/CD pipelines across build, test, and release stages.
  • Build and maintain scalable internal DevSecOps tooling, including reusable pipeline libraries and automation frameworks.
  • Design "paved road" security patterns and self-service tools to provide a seamless developer experience.
  • Implement cloud-native security architecture for Kubernetes, containerized workloads, and infrastructure-as-code across AWS and Azure.
  • Evaluate and integrate best-of-breed security tools to standardize and consolidate the organization's security stack.
  • Translate regulatory requirements into automated engineering controls to ensure continuous compliance and audit readiness.
  • Lead vulnerability management and remediation efforts across application, pipeline, and cloud environments.
  • Conduct threat modeling and architecture reviews to ensure security is embedded at the design level.

What we're looking for

  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.
  • 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments.
  • Practical expertise with cloud platforms (AWS, Azure, or Google Cloud) and containerization technologies like Docker and Kubernetes.
  • Proficiency with infrastructure-as-code tools such as Terraform, CloudFormation, or Pulumi.
  • Strong understanding of application security concepts including OWASP Top 10 and experience with SAST, DAST, and SCA platforms.
  • Ability to build and maintain internal tooling using scripting languages like Python or Go.
  • Experience with modern development practices including CI/CD pipeline design, Git version control, and agile methodologies.
  • Excellent technical communication skills to articulate security risks and solutions to engineering teams and stakeholders.

More like this

Similar roles

DevSecOps Engineer

Booz Allen Hamilton

Washington, DC 25 days ago $77,600$176,000
DevSecOps CI/CD AWS Azure GCP Terraform CloudFormation CDK Docker Kubernetes Python Bash Go GitLab CI GitHub Actions PostgreSQL MySQL MongoDB Oracle Ansible Prometheus Grafana ELK Helmfile Flux Argo CD IaC SAST SCA
8+ yrs exp

Senior DevSecOps Engineer

Booz Allen Hamilton

Alexandria, VA 63 days ago $77,600$176,000
DevSecOps CI/CD AWS Azure Kubernetes Docker Terraform Ansible Chef Puppet CloudFormation Python Go Bash GitLab CI GitHub Actions Maven Gradle NPM SAST SCA
10+ yrs exp

DevSecOps Engineer

Booz Allen Hamilton

Peterson AFB, CO 23 days ago $99,000$225,000
Kubernetes Docker ArgoCD AWS EC2 EKS IAM Lambda SQS SNS RDS GitLab CI/CD Bash Python Prometheus Grafana Helm SBOM
10+ yrs exp

DevSecOps Security Engineer

General Dynamics

Remote 24 days ago $191,250$258,750
AWS DevSecOps CI/CD Terraform Python Bash Linux NIST 800-53 FedRAMP CloudFormation Security Hub Inspector GuardDuty Config Qualys CrowdStrike Nexus SonarQube Datadog Databricks
8+ yrs exp Remote

Senior DevSecOps Engineer

Booz Allen Hamilton

Fayetteville, NC 37 days ago $77,500$176,000
Kubernetes CI/CD Infrastructure as Code Ansible Terraform Python Bash AWS Azure Google Cloud Linux RHEL Ubuntu Prometheus Grafana ELK OpenSearch Istio ArgoCD Flux Harbor Nautobot NetBox Agile Scrum SAFe
5+ yrs exp

Senior DevSecOps Engineer

Medtronic

Remote (CO) 2 days ago $124,800$187,200
DevSecOps CI/CD Embedded Linux Python Go Bash Docker Snyk SonarQube Yocto Bitbucket Jira Bamboo Confluence GitHub GitLab AWS SAST SCA SBOM Secure Boot
Remote