Lead Penetration Test Engineer
$135k - $200kS&P Global
Lead Penetration Test Engineer
The Role: Lead Penetration Test Engineer
Location: Hybrid 2 days per week onsite on one of our following sites:
US: Boston, MA, Chicago, IL, Dallas, TX, Houston, TX, Englewood, CO, Raleigh, NC, Princeton, NJ, New York, NY, Southfield, MI, Washington, DC.
Canada: Toronto, ON, Calgary, AB
The Team: The S&P Ratings Security team focuses on protecting our clients and users from modern security threats. Our mission is to safeguard systems and data by developing innovative solutions to the industry's most complex security challenges. We are passionate problem solvers with deep security expertise.
Responsibilities and Impact:
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing and offensive security. The ideal candidate will conduct penetration tests, re-testing, vulnerability scanning, and threat assessments across diverse environments. This role requires strong offensive security skills combined with cloud and application security expertise to identify vulnerabilities and develop effective mitigation strategies.
A successful candidate will excel in the following areas:
Penetration Testing & Vulnerability Assessments
• Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
• Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.
• Apply cloud-specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing.
Vulnerability Management & Remediation
• Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security across development and production lifecycles.
• Perform detailed security assessments using DAST, SAST, and SCA tools to ensure continuous validation and improvement of security controls.
Attack Simulations & Research
• Lead and participate in attack simulations and tabletop exercises to validate security controls and improve organizational response capabilities.
• Research emerging threats, attack vectors, and adversarial techniques to inform offensive and defensive strategies.
• Partner with internal teams to design and execute threat assessments based on intelligence feeds and threat actor analysis.
Security Communication & Reporting
• Communicate and present penetration testing and security assessment findings to both technical and non-technical stakeholders.
• Provide actionable remediation guidance and risk mitigation strategies to strengthen the organization's overall security posture.
What We're Looking For
Basic Required Qualifications
• Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent experience.
• Minimum 8 years of experience in information security with a strong focus on penetration testing, application security, and vulnerability management.
• Hands-on experience with penetration testing tools (e.g., Burp Suite, Nessus, Metasploit, Nmap) and methodologies (e.g., OWASP Top 10, MITRE ATT&CK, PTES).
• Expertise in identifying and exploiting common infrastructure and web application vulnerabilities (e.g., XSS, SQL Injection, IDOR).
• Familiarity with vulnerability classification and scoring frameworks (CVE, CVSS, CWE).
• Strong scripting or programming skills (e.g., Bash, Python, Go, PowerShell, JavaScript).
• Experience performing security assessments (DAST, SAST, SCA, credential scanning) and integrating security testing into CI/CD pipelines.
• Ability to translate complex technical findings into clear, actionable reports and confidently brief cross-functional teams and executives.
• At least one recognized offensive security certification (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).
Preferred Qualifications
• Experience with cloud security across AWS, Azure, or GCP.
• Knowledge of AI/ML security and adversarial testing methods, including evaluating LLMs and other models for manipulation, evasion, and data integrity risks.
• Demonstrated involvement in the infosec community (e.g., open-source projects, bug bounties, CVE research, conference talks, or security publications).
• Experience applying the MITRE ATT&CK Framework to offensive security operations and threat emulation.
• Familiarity with secure software development practices and the software development lifecycle.
• Experience with Java application technologies, deployment frameworks, and associated security best practices.
• Ability to work collaboratively across teams while independently owning deliverables and maintaining accountability to deadlines.
Right to work requirements for US based out candidates:
This role is open only for candidates with indefinite right to work within the US.
Compensation/Benefits Information (US Applicants Only): S&P Global states that the anticipated base salary range for this position is $135,000 USD – $200,000 USD. Final base salary for this role will be based on the individual's geographical location as well as experience and qualifications for the role.
In addition to base compensation, this role is eligible to receive additional S&P Global benefits. For more information on the benefits we provide to our employees, please click here.
Right to work requirements for Canada based out Candidates:
This role is open for candidates with indefinite right to work within Canada.
Compensation/Benefits Information: (This section is only applicable to Canadian Candidates:) S&P Global states that the anticipated range of compensation for this position is 135,000 CAD to 180,000 CAD. Final compensation for this role will be based on the individual's performance, geographic location, as well as experience level, skill set, training, licenses, and certifications.
About S&P Global Ratings At S&P Global Ratings, our analyst-driven credit ratings, research, and sustainable finance opinions provide critical insights that are essential to translating complexity into clarity so market participants can uncover opportunities and make decisions with conviction. By bringing transparency to the market through high-quality independent opinions on creditworthiness, we enable growth across a wide variety of organizations, including businesses, governments, and institutions.
S&P Global Ratings is a division of S&P Global (NYSE: SPGI). S&P Global is the world's foremost provider of credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets. With every one of our offerings, we help many of the world's leading organizations navigate the economic landscape so they can plan for tomorrow, today. For more information, visit
Our Mission:
Advancing Essential Intelligence.
Our People:
We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all. From finding new ways to measure sustainability to analyzing energy transition across the supply chain to building workflow solutions that make it easy to tap into insight and apply it. We are changing the way people see things and empowering them to make an impact on the world we live in. We're committed to a more equitable future and to helping our customers find new, sustainable ways of doing business. Join us and help create the critical insights that truly make a difference.
Our Values:
Integrity, Discovery, Partnership
Throughout our history, the world's leading organizations have relied on us for the Essential Intelligence they need to make confident decisions about the road ahead. We start with a foundation of integrity in all we do, bring a spirit of discovery to our work, and collaborate in close partnership with each other and our customers to achieve shared goals.
Benefits:
We take care of you, so you can take care of business. We care about our people. That's why we provide everything you—and your career—need to thrive at S&P Global. Our benefits include:
- Health & Wellness: Health care coverage designed for the mind and body.
- Flexible Downtime: Generous time off helps keep you energized for your time on.
- Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
- Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
- Family Friendly Perks: It's not just about you. S&P Global has perks for your partners and
$40 per hour
...generation of AI security models Qualifications 2+ years of hands‑on experience in cybersecurity (e.g., penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some coding experience required Fluency...SuggestedHourly payFull timePart timeRemote work- ...Lead Penetration Tester Seeking an experienced Lead Consultant with strong technical expertise and the leadership skills necessary to develop... ...technical security risk assessments and penetration testing across 100 counties. This initiative covers county IT infrastructure...SuggestedWork at office
$114.1k - $268.18k
...development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both... ...KPMG is currently seeking a Lead Specialist, MAST Application Penetration Testing Manager to join our Managed Services practice. Responsibilities...SuggestedH1bLocal area- ...Software Test Engineer Microservices & REST API Location: Raleigh, NC or Dallas, TX (4 days onsite) Duration: 12 months+ Responsibilities... ...improvements. # Communicate closely with the project team leads and managers on test status, risks, and mitigation plans....SuggestedLocal area
- ...Lead Energy Storage Cyber Security Engineer - REMOTE Full time | ThinkBAC Consulting | United States Posted On 11/19/2025 Job Information Work Experience... ...into pragmatic controls, policies, and continuous testing. This is a cross-functional role that will partner across...SuggestedFull timeWork experience placementRemote workFlexible hours
- ...VetsEZ is looking for a mid-level Test Automation Engineer based in the United States to support a federal healthcare technology program. The... ...testing strategies, and work closely with developers and QA leads to enhance testing efficiency. A Bachelor's degree and 10 years...Remote work
- ...TCS207, T3, Band 6 Job-Specific Essential Duties and Responsibilities: - Provides subject matter proficiency supporting system testing activities - Applies analytical skills to support process improvement, specialized studies, and requirements definition -...Minimum wageFull timeContract workTemporary workFor contractorsWork experience placementRemote work
- ...Test Data Privatization Engineer Location: Raleigh, NC Rate: DOE $/Yr. Position Type: Full Time Interview Process: Phone Followed by F2F Job Description: Essential Duties and Responsibilities: Following is a summary of the essential functions for this job. Other...Full timeWork experience placement
- ...A leading construction firm is hiring a Traveling General Superintendent responsible for overseeing complex projects nationwide. The ideal candidate has 12+ years of construction experience and strong leadership skills. Key responsibilities include project management,...For subcontractor
$60 per hour
...part of a growing community of over 100,000 professionals — including front‑end, back‑end, full‑stack, machine learning, and other engineers — who are driving real‑world impact in AI development. Our platform offers an engaging blend of flexibility and challenge: you’ll...Hourly payFull timeRemote workFlexible hours$129.5k - $186.1k
...strategic and execution-oriented Lead Product Manager to drive key... ..., Sales, Operations, Data, Engineering, and Business Systems This... ...accounts Buying group penetration Pipeline influence Opportunity... ...or administer a lie detector test as a condition of employment...Temporary workLocal areaRemote work$110k - $130k
...A leading IT solutions provider is looking for a Senior Subcontracts Administrator to remotely manage the full life cycle of subcontracts. The ideal candidate will have over 8 years of experience in subcontract management, negotiation, and have strong analytical and communication...Remote work- ...Lead and develop a new dermatology clinic in the Raleigh, North Carolina area! The new physician can practice general, medical, surgical, and cosmetic dermatology. An experienced team provides the business and administrative support to ensure the physician's success....Relocation packageFlexible hours
$55k - $68k
...empowering individuals and strengthening communities. We are seeking a passionate Intensive In-Home (IIH) Mental Health Therapist/Team Lead to provide clinical leadership and support to a dedicated team delivering community-based mental health services to youth and...Full timeRelocation package- ...Sigital is seeking an Engagement Manager in North Carolina to lead ServiceNow project management. The candidate should have a minimum of three years of experience, excellent communication skills, and expertise in both IT project management and consultative services. Responsibilities...Full timeRemote work
- ...We Are: Accenture is a leading global professional services company that helps the world's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible...Work experience placementLive inWork at officeLocal area
$100k - $140k
...Must Have Technical/Functional Skills • 10+ years overall experience in data engineering or related fields. • 35 years hands-on experience with Databricks and Spark. • Strong proficiency in SQL and data analysis techniques. • Experience with ETL processes, data...- ...MOD •Performs all other duties as assigned QUALIFICATIONS • A high school graduate or equivalent preferred • Ability to lead and manage a team • Strong understanding of store operations and merchandising techniques preferred • Excellent interpersonal, organizational...Local areaImmediate start
- ...Store Floor Lead With over 58 stores and the largest avocational cooking program in the US, Sur La Table offers an unsurpassed selection of exclusive and premium-quality goods for the kitchen and table – and the culinary expertise and inspiration to go along with it...Work at officeFlexible hoursNight shift
- ...Itron, Inc. is looking for a Technical Implementation Consultant based in the United States. In this role, you will lead the technical implementation of their SaaS platform for utility customers. You will be responsible for configuring systems, leading integrations, and...Remote work
- ...looking for a Systems Solutions & Adoption Lead to join our IT team. As part of the IT... ...a row, Moffatt & Nichol is Ranked #1 in Engineering News-Record for Marine & Port Facilities... ...Apply hands-on AI skills to write, refine, test, and support prompts, agents, and other AI...For contractorsWork at officeWorldwide
- ...are expanding our footprint across the country. We foster a culture built on five core values: Generosity First, Always: We lead with kindness. Our best work happens when we act in service of others Constant Curiosity: We are eager to learn, grow, and...Local areaShift work
$20 per hour
A technology company specializing in AI is seeking a Credentialing Manager to train AI models. The role requires diverse healthcare expertise and focuses on evaluating AI outputs for accuracy and performance. Responsibilities include solving complex healthcare-related ...Hourly payRemote workFlexible hours$17.57 - $22.45 per hour
...the Jobs Hub app or search for Browse Jobs. SUMMARY OF JOB PURPOSE AND FUNCTION : The primary purpose and function of the Shift Lead is to perform the duties of a CSC and/or veterinary assistant/technician, as well as provide continuity and operational support...Hourly payMinimum wageFull timeTemporary workPart timeLocal areaAll shiftsFlexible hoursShift workWeekend workAfternoon shift$132.23k - $176.31k
...impact. We're looking for top-tier talent ready to take on the challenge. Join us in building the future. The Role The Senior Lead, Funnel Governance & Performance Insights leads a new center-of-excellence that defines and enforces sales funnel hygiene standards,...Temporary workRemote work- Rack Room Shoes - - Responsibilities: Assist in supervising and managing all day-to-day store operations; Provide leadership, guidance and training to the store staff; Manage customer issues with urgency and satisfaction; Oversee inventory control, merchandising, and loss...
- ...resilient communities and quality of life. We bring together planners, engineers, architects, construction management staff, environmental,... ...future of mobility. This isn't just a job, it's a chance to lead progress, drive meaningful impact, and leave a legacy of smarter...Local areaNight shift
$14 per hour
...exciting job with one of the largest off-price retail stores in the nation, join the Burlington Stores, Inc. as a Shortage Control Lead ! As a Shortage Control Lead you will be responsible for mitigating theft and fraud in high shortage areas of the store while promoting...Hourly payFull timeLocal areaFlexible hoursNight shift- A government health department is seeking an experienced IT Program Manager to oversee the Child Welfare Information System modernization initiative. The role requires managing complex IT projects and collaborating with various stakeholders to ensure alignment with strategic...Remote work
- ...Description: Job Summary The HVAC CQV Lead is responsible for supporting the... ...specialists, operations personnel, system leads/engineers, document controllers and external... ...workflows and approval cycles for commissioning test plans and specifications Updating the...For contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Penetration Test Engineer. Be the first to apply!
- lead network engineer Raleigh, NC
- lead operating engineer Raleigh, NC
- lead infrastructure engineer Raleigh, NC
- lead engineer Raleigh, NC
- test engineer Raleigh, NC
- lead performance test engineer Raleigh, NC
- performance test engineer Raleigh, NC
- lead piping engineer
- lead android developer
- lead support engineer


