Lead Vulnerability Management Engineer
Cloudflare, Inc
Quick summary
Market check
How this pay compares to similar roles
This role pays less than 88% of similar roles. Most pay $154,425–$208,975 — the shaded band above. At the midpoint, this role pays about $135k versus about $182k for comparable roles.
Based on 240 similar postings.
Employer
S&P Global delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies and expertise they need to move ahead.
S&P Global currently has 46 open roles on FindRole.
Listed pay typically runs $142,000–$200,000 across 37 roles with salary data.
Most-posted roles
At a glance
Lead InfoSec Engineer, Vulnerability Management joins the Information Security team to transition the organization from reactive response to proactive risk management. This role involves leading the enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments while providing strategic oversight and risk-based prioritization for critical assets. The engineer will collaborate with cross-functional teams to ensure timely remediation, develop reporting programs using multiple data sources, mentor junior professionals, and support regulatory compliance activities. Key technical requirements include expertise in CVE, CVSS, and CWE frameworks, along with experience using platforms like Qualys, Tanium, or Rapid7. Candidates should be proficient in DAST/SAST tools such as Fortify, Checkmarx, or Veracode. The role also requires skills in Power BI or Tableau for data visualization and a deep understanding of NIST and ISO 27001 frameworks to manage complex security risks.
Skills
What you'll do
What we're looking for
More like this
Cloudflare, Inc
SoFi
SoFi
Neurocrine
SoFi
Take-Two Interactive