Lead InfoSec Engineer, Vulnerability Management

S&P Global

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
New York, NY
Salary
$125,000–$145,000 / yr
Posted
53 days ago
Freshness
Confirmed live 2 days ago
Closes
Jul 20, 2027

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $135k
$113k most similar roles pay here $233k

This role pays less than 88% of similar roles. Most pay $154,425–$208,975 — the shaded band above. At the midpoint, this role pays about $135k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About S&P Global

S&P Global delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies and expertise they need to move ahead.

S&P Global currently has 46 open roles on FindRole.

Listed pay typically runs $142,000–$200,000 across 37 roles with salary data.

Most-posted roles

View all roles at S&P Global

At a glance

TL;DR · Lead InfoSec Engineer, Vulnerability Management

Lead InfoSec Engineer, Vulnerability Management joins the Information Security team to transition the organization from reactive response to proactive risk management. This role involves leading the enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments while providing strategic oversight and risk-based prioritization for critical assets. The engineer will collaborate with cross-functional teams to ensure timely remediation, develop reporting programs using multiple data sources, mentor junior professionals, and support regulatory compliance activities. Key technical requirements include expertise in CVE, CVSS, and CWE frameworks, along with experience using platforms like Qualys, Tanium, or Rapid7. Candidates should be proficient in DAST/SAST tools such as Fortify, Checkmarx, or Veracode. The role also requires skills in Power BI or Tableau for data visualization and a deep understanding of NIST and ISO 27001 frameworks to manage complex security risks.

What you'll do

  • Lead the enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments.
  • Provide risk-based prioritization to protect critical business assets from identified vulnerabilities.
  • Coordinate with IT managers and application teams to ensure timely remediation of security flaws.
  • Develop reporting programs and dashboards to provide executive leadership with visibility into security trends.
  • Establish and monitor key performance indicators to drive measurable improvements in vulnerability remediation.
  • Support regulatory compliance and audit activities by aligning operations with enterprise security policies.
  • Mentor junior security professionals and contribute to program maturity through process and tooling improvements.

What we're looking for

  • Must have 7+ years of operational security experience in vulnerability management, application security testing, or technical project management.
  • Requires deep expertise in vulnerability assessment frameworks including CVE, CVSS, and CWE.
  • Experience with enterprise vulnerability management platforms such as Qualys, Tanium, Rapid7, or similar solutions is required.
  • Must possess strong application security knowledge to assess risk and translate technical findings into business recommendations.
  • Experience with DAST/SAST tools like Fortify, Checkmarx, or Veracode is required.
  • A Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience is required.
  • Must possess relevant certifications such as CISSP, CISM, CEH, GCIH, or other industry-recognized credentials.
  • Proven ability to lead cross-functional initiatives and communicate security risks to both technical and executive audiences.

More like this

Similar roles

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 7 days ago $124,800$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Staff Vulnerability Management Engineer

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Vulnerability Management Python Go JavaScript TypeScript Java Kubernetes AWS GCP Azure CI/CD Infrastructure as Code SAST SCA SBOM Tines Wiz Semgrep Snyk Rapid7 Tenable Checkmarx CVSS EPSS CISA KEV AI/ML

Senior Systems Engineer, Vulnerability Management

Neurocrine

Remote (San Diego, CA) 8 days ago $103,300$141,000
AWS Azure Linux Windows Python Bash PowerShell Ansible SSM) Patch Manager WSUS SCCM Intune Configuration Management ITIL ServiceNow GxP SOX Vulnerability Management Patch Management
4+ yrs exp Remote

Vulnerability Management Engineer

SoFi

San Francisco, CA 7 days ago $99,200$186,000
Vulnerability Management AppSec SAST DAST AWS Python Go Bash Java CI/CD OWASP CVE CVSS Agile

Senior Vulnerability Advisor

Take-Two Interactive

Austin, TX 127 days ago
Vulnerability Management Risk Management AWS GCP Azure Prisma Cloud Qualys Tenable ServiceNow NIST CSF ISO 27001 CIS
5+ yrs exp