Lead Penetration Test Engineer

S&P Global

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Boston, MAChicago, ILDallas, TXHouston, TXEnglewood, CORaleigh, NCPrinceton, NJNew York, NYSouthfield, MIWashington, DCToronto, ON, CanadaCalgary, AB, Canada
Salary
$135,000–$200,000 / yr
Posted
22 days ago
Freshness
Confirmed live 2 days ago
Closes
Aug 4, 2027

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $164k
This role $168k
$120k most similar roles pay here $209k

This role pays more than 55% of similar roles. Most pay $137,750–$191,200 — the shaded band above. At the midpoint, this role pays about $168k versus about $164k for comparable roles.

Based on 240 similar postings.

Employer

About S&P Global

S&P Global delivers Essential Intelligence® that shapes decision making. We provide the world’s leading organizations with the right data, connected technologies and expertise they need to move ahead.

S&P Global currently has 46 open roles on FindRole.

Listed pay typically runs $142,000–$200,000 across 37 roles with salary data.

Most-posted roles

View all roles at S&P Global

At a glance

TL;DR · Lead Penetration Test Engineer

Lead Penetration Test Engineer joins the S&P Ratings Security team to protect clients and users from modern security threats. This role involves conducting penetration tests, re-testing, vulnerability scanning, and threat assessments across web applications, infrastructure, and cloud environments. The engineer will develop custom scripts and tools to automate testing within CI/CD pipelines while performing DAST, SAST, and SCA analyses. Key responsibilities include executing attack simulations, researching emerging threats, and collaborating with development teams to create remediation plans. Required technical skills include proficiency in Burp Suite, Nessus, Metasploit, Nmap, and programming languages like Bash, Python, Go, PowerShell, or JavaScript. The role requires expertise in OWASP Top 10, MITRE ATT&CK, and cloud-specific offensive techniques across AWS, Azure, or GCP to identify vulnerabilities and strengthen the organization's overall security posture through actionable reporting.

What you'll do

  • Conduct manual and automated penetration tests on web applications, infrastructure, and cloud environments.
  • Develop custom scripts and tools to automate security testing within CI/CD pipelines.
  • Execute cloud-specific offensive techniques including IAM abuse and container exploitation.
  • Perform DAST, SAST, and SCA scans to validate and improve security controls.
  • Lead attack simulations and tabletop exercises to test organizational response capabilities.
  • Research emerging threats and adversarial techniques to inform defensive strategies.
  • Translate complex technical findings into actionable reports for both technical and non-technical stakeholders.
  • Provide remediation guidance to engineering teams to strengthen application security across the lifecycle.

What we're looking for

  • Minimum of 8 years of experience in information security with a focus on penetration testing, application security, and vulnerability management.
  • Proficiency with tools such as Burp Suite, Nessus, Metasploit, and Nmap using methodologies like OWASP Top 10 and MITRE ATT&CK.
  • Expertise in identifying and exploiting infrastructure and web application vulnerabilities including XSS, SQL Injection, and IDOR.
  • Strong scripting or programming skills in languages such as Bash, Python, Go, PowerShell, or JavaScript.
  • Experience performing DAST, SAST, and SCA assessments and integrating security testing into CI/CD pipelines.
  • Ability to communicate complex technical findings and remediation strategies to both technical and non-technical stakeholders.
  • Possession of at least one recognized offensive security certification such as OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT.
  • Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience.

More like this

Similar roles

Principal Senior Penetration Tester

Northrop Grumman

San Antonio, TX 52 days ago $103,600$155,400
Penetration Testing AWS Azure CI/CD Docker Kubernetes Python Bash PowerShell Terraform Ansible Splunk Sentinel ELK CrowdStrike Linux Windows Infrastructure-as-Code Vulnerability Management RMF
8+ yrs exp

Senior Red Team Operator

Booz Allen Hamilton

Chantilly, VA 17 days ago $86,800$198,000
Red Teaming Purple Teaming Active Directory Python Bash C/C++ C# Rust Go PowerShell Java Nessus Metasploit Burp Suite Pro Cobalt Strike Mythic Azure M365 Terraform x86 Reverse Engineering JTAG UART OWASP ATT&CK

Business Process Red Team Operator

JPMorgan Chase

Columbus, OH 91 days ago
Red Teaming Penetration Testing Social Engineering OWASP NIST Cobalt Strike Metasploit Nmap Nessus Burp Suite Python Ruby Perl C C++ C# Java Linux Windows Unix Cloud Architecture Threat Intelligence Incident Response Firewalls IDS/IPS DLP
5+ yrs exp

Lead Test Engineer

General Dynamics

Scottsdale, AZ 55 days ago $132,930$147,470
Python Embedded Systems Test Automation CI/CD Hardware/Software Integration Signal Analyzer Signal Generator USRP Agile Requirements Management Verification and Validation Scripting Object-Oriented Programming
8+ yrs exp

Lead Manufacturing Test Equipment Engineer

GE Aerospace

Clearwater, FL 17 days ago $95,000$127,000
National Instruments TestStand LabWindows/CVI C C++ C# Microsoft Visual Studio Git GitHub RS-232 ARINC 429 Ethernet CAN DFT Root Cause Analysis Agile Scrum
5+ yrs exp Hybrid

Lead Engineer, Testing

GE Aerospace

Grand Rapids, MI 29 days ago $95,000$127,000
National Instruments TestStand LabWindows/CVI C C++ C# Microsoft Visual Studio Git GitHub RS-232 ARINC 429 Ethernet CAN Circuit Design Root Cause Analysis Agile Scrum
5+ yrs exp Hybrid