Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Penetration Test Engineer

$135k - $200k

S&P Global HQ North America

Lead Penetration Test Engineer

The Role: Lead Penetration Test Engineer

Location: Hybrid 2 days per week onsite on one of our following sites:

US: Boston, MA, Chicago, IL, Dallas, TX, Houston, TX, Englewood, CO, Raleigh, NC, Princeton, NJ, New York, NY, Southfield, MI, Washington, DC.

Canada: Toronto, ON, Calgary, AB

The Team: The S&P Ratings Security team focuses on protecting our clients and users from modern security threats. Our mission is to safeguard systems and data by developing innovative solutions to the industry's most complex security challenges. We are passionate problem solvers with deep security expertise.

Responsibilities and Impact:

We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing and offensive security. The ideal candidate will conduct penetration tests, re-testing, vulnerability scanning, and threat assessments across diverse environments. This role requires strong offensive security skills combined with cloud and application security expertise to identify vulnerabilities and develop effective mitigation strategies.

A successful candidate will excel in the following areas:

Penetration Testing & Vulnerability Assessments

• Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

• Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.

• Apply cloud-specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing.

Vulnerability Management & Remediation

• Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security across development and production lifecycles.

• Perform detailed security assessments using DAST, SAST, and SCA tools to ensure continuous validation and improvement of security controls.

Attack Simulations & Research

• Lead and participate in attack simulations and tabletop exercises to validate security controls and improve organizational response capabilities.

• Research emerging threats, attack vectors, and adversarial techniques to inform offensive and defensive strategies.

• Partner with internal teams to design and execute threat assessments based on intelligence feeds and threat actor analysis.

Security Communication & Reporting

• Communicate and present penetration testing and security assessment findings to both technical and non-technical stakeholders.

• Provide actionable remediation guidance and risk mitigation strategies to strengthen the organization's overall security posture.

What We're Looking For

Basic Required Qualifications

• Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent experience.

• Minimum 8 years of experience in information security with a strong focus on penetration testing, application security, and vulnerability management.

• Hands-on experience with penetration testing tools (e.g., Burp Suite, Nessus, Metasploit, Nmap) and methodologies (e.g., OWASP Top 10, MITRE ATT&CK, PTES).

• Expertise in identifying and exploiting common infrastructure and web application vulnerabilities (e.g., XSS, SQL Injection, IDOR).

• Familiarity with vulnerability classification and scoring frameworks (CVE, CVSS, CWE).

• Strong scripting or programming skills (e.g., Bash, Python, Go, PowerShell, JavaScript).

• Experience performing security assessments (DAST, SAST, SCA, credential scanning) and integrating security testing into CI/CD pipelines.

• Ability to translate complex technical findings into clear, actionable reports and confidently brief cross-functional teams and executives.

• At least one recognized offensive security certification (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).

Preferred Qualifications

• Experience with cloud security across AWS, Azure, or GCP.

• Knowledge of AI/ML security and adversarial testing methods, including evaluating LLMs and other models for manipulation, evasion, and data integrity risks.

• Demonstrated involvement in the infosec community (e.g., open-source projects, bug bounties, CVE research, conference talks, or security publications).

• Experience applying the MITRE ATT&CK Framework to offensive security operations and threat emulation.

• Familiarity with secure software development practices and the software development lifecycle.

• Experience with Java application technologies, deployment frameworks, and associated security best practices.

• Ability to work collaboratively across teams while independently owning deliverables and maintaining accountability to deadlines.

Right to work requirements for US based out candidates:

This role is open only for candidates with indefinite right to work within the US.

Compensation/Benefits Information (US Applicants Only): S&P Global states that the anticipated base salary range for this position is $135,000 USD – $200,000 USD. Final base salary for this role will be based on the individual's geographical location as well as experience and qualifications for the role.

In addition to base compensation, this role is eligible to receive additional S&P Global benefits. For more information on the benefits we provide to our employees, please click here.

Right to work requirements for Canada based out Candidates:

This role is open for candidates with indefinite right to work within Canada.

Compensation/Benefits Information: (This section is only applicable to Canadian Candidates:) S&P Global states that the anticipated range of compensation for this position is 135,000 CAD to 180,000 CAD. Final compensation for this role will be based on the individual's performance, geographic location, as well as experience level, skill set, training, licenses, and certifications.

About S&P Global Ratings At S&P Global Ratings, our analyst-driven credit ratings, research, and sustainable finance opinions provide critical insights that are essential to translating complexity into clarity so market participants can uncover opportunities and make decisions with conviction. By bringing transparency to the market through high-quality independent opinions on creditworthiness, we enable growth across a wide variety of organizations, including businesses, governments, and institutions.

S&P Global Ratings is a division of S&P Global (NYSE: SPGI). S&P Global is the world's foremost provider of credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets. With every one of our offerings, we help many of the world's leading organizations navigate the economic landscape so they can plan for tomorrow, today. For more information, visit

Our Mission:

Advancing Essential Intelligence.

Our People:

We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all. From finding new ways to measure sustainability to analyzing energy transition across the supply chain to building workflow solutions that make it easy to tap into insight and apply it. We are changing the way people see things and empowering them to make an impact on the world we live in. We're committed to a more equitable future and to helping our customers find new, sustainable ways of doing business. Join us and help create the critical insights that truly make a difference.

Our Values:

Integrity, Discovery, Partnership

Throughout our history, the world's leading organizations have relied on us for the Essential Intelligence they need to make confident decisions about the road ahead. We start with a foundation of integrity in all we do, bring a spirit of discovery to our work, and collaborate in close partnership with each other and our customers to achieve shared goals.

Benefits:

We take care of you, so you can take care of business. We care about our people. That's why we provide everything you—and your career—need to thrive at S&P Global. Our benefits include:

  • Health & Wellness: Health care coverage designed for the mind and body.
  • Flexible Downtime: Generous time off helps keep you energized for your time on.
  • Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
  • Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
  • Family Friendly Perks: It's not just about you. S&P Global has perks for your partners and
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Lead Penetration Test Engineer in Chicago, IL vacancy
  • $107k - $214.5k

     ...We are the leading provider of professional services to the middle market globally,...  ...performing vulnerability assessments, penetration testing, and secure architecture reviews of a...  ...wireless penetration testing, social engineering campaigns (email, web, phone, physical... 
    Suggested
    Work experience placement
    Local area

    RSM US LLP

    Chicago, IL
    2 days ago
  •  ...Job Summary We are seeking an experienced Manual QA Test Engineer with strong banking domain experience to support end-to-end testing of enterprise applications. The ideal candidate will have deep expertise in manual testing , test planning and execution, SQL... 
    Suggested
    Local area

    Prophecy Technologies

    Chicago, IL
    4 days ago
  •  ...Role : Azure Security Lead Location: Chicago, IL (Onsite) Contract...  ...pipelines Conduct security audits, penetration testing coordination, and remediation planning...  ...Lead and mentor a team of security engineers and act as a subject matter expert (SME... 
    Suggested
    Contract work

    AceStack LLC

    Chicago, IL
    4 days ago
  • $98.4k - $199k

     ...PCI Compliance Lead Job Locations US-IN-Lafayette | US-MN-Lake Elmo |...  ...overall security posture. Conduct control testing to evaluate effectiveness and identify...  ...actionable recommendations. Ensure ASV scans, penetration testing, and related remediation... 
    Suggested
    Full time

    Old National Bank

    Chicago, IL
    3 days ago
  •  ...Digital Test Automation Engineer IL - Chicago, IN - Indianapolis, MI - Detroit, MN - Minneapolis, MN - St Paul, OH - Cincinnati, OH - Columbus - Cleveland, OH - MO - Kansas City, Toledo, MO - St Louis, WI - Milwaukee – Midwest NEW MIDWEST JOB LOCATIONS...: AK - Ft.... 
    Suggested

    ClifyX

    Chicago, IL
    4 days ago
  •  ...Test Automation Engineer Location: Chicago, IL Position Type: Full Time Salary: DOE US Citizen, Green Card, GC EAD and TN visa only....  ...configuration problems R&D on new tools and technologies and find innovative solutions Leading a distributed testing effort... 
    Full time
    H1b
    Visa sponsorship

    Staffing the Universe

    Chicago, IL
    2 days ago
  •  ...Senior Software Development Engineer In Test AKA Senior SDET Extend testing automation framework using JAVA/JAVA Script. Take ownership in understanding business requirements/ACs and develop test strategy/test plan Develop automation test cases using existing automation... 
    Flexible hours

    Samprasoft

    Chicago, IL
    15 hours ago
  • The QA Test Automation Engineer will work closely with developers, product owners, and stakeholders to ensure high-quality software delivery. This role involves defining, implementing, and championing quality practices across the software development lifecycle. The engineer... 

    Compunnel, Inc.

    Chicago, IL
    4 days ago
  •  ...Job Title: Performance Test Engineer Location: Chicago, IL Duration: 06 Month RTH Job Description: Job Responsibilities...  ...2 round of interviews 1 with manager and her lead 2 will be Panel with engineering team Payment... 

    3B Staffing LLC

    Chicago, IL
    1 day ago
  •  ...have partnered with our client in their search for a Performance Test Engineer in Chicago, IL Responsibilities * Define and own...  ...for UI, API, microservices, and data workflows. * Lead the end-to-end performance testing lifecycle: requirements gathering... 
    Work experience placement

    Korn Ferry

    Chicago, IL
    3 days ago
  •  ...Our client is currently seeking a Performance Test Engineer to join their team in Chicago. This role is ideal for someone with strong expertise in performance testing and automation, along with experience working in both on-premises and AWS cloud environments .... 

    The Judge Group

    Chicago, IL
    4 days ago
  •  ...Overview: Role Overview We are seeking an experienced Performance Test Engineer with strong expertise in load and performance testing to ensure the scalability, reliability, and stability of enterprise applications. The ideal candidate will work closely... 

    Purple Drive

    Chicago, IL
    4 days ago
  •  ...Test Performance Engineer Location: Chicago, IL Rate: DOE $/hr. Position Type: contract Interview Process: Phone Followed by F2F Job Description: • Define, build and implement performance testing strategy, approach and framework • Partner with Architecture and... 
    Contract work

    Georgia IT Inc

    Chicago, IL
    9 days ago
  • $75 per hour

     ...systems/infrastructure for large-scale programs (e.g., Expert Engineers) starting to be firm-wide resources working on projects across...  ...techniques such as Continuous Integration, Continuous Delivery, Test Driven Development, Cloud Development, resiliency, security Stays... 
    Contract work
    Temporary work
    Work experience placement
    Immediate start
    Worldwide
    Flexible hours

    Innova Solutions

    Chicago, IL
    3 days ago
  •  ...Performance Test Engineer Location: Chicago, IL Duration: 6 Months At least 8 years of experience in PT Loadrunner with TruClient protocol knowledge. Should have in-depth knowledge on PT life cycle and contents on all documents. Hands on experience with AppDynamics... 

    ClifyX

    Chicago, IL
    4 days ago
  • S & C Electric Company seeks a Manufacturing Quality Engineer I to join their US QA team in Chicago. You will be crucial in ensuring the quality of operations and supporting a diverse team in driving strategic quality initiatives. This role emphasizes resolving complex... 

    S & C Electric Company

    Chicago, IL
    3 days ago
  • $180.22k - $256.1k

     ...Senior Vice President, Team Lead Publicis Groupe is a global leader in communication and is positioned at every step of the value...  ...bookings targets Strategic Account Expansion – Deepen penetration within existing Groupe clients by selling higher-value, programmatic... 
    Temporary work
    Freelance
    Flexible hours

    Prodigious Worldwide

    Chicago, IL
    15 hours ago
  • $16 - $24.75 per hour

     ...deliver an exceptional customer experience * Serves as a Brand Ambassador embodying of Coach values and increasing brand awareness * Leads implementation of Company initiatives and support full operation of the business * Maintain a growth mindset for business and... 
    Minimum wage
    Shift work

    Tapestry

    Skokie, IL
    2 days ago
  • $58.7k - $86.28k

     ...Lead Generation Specialist-Unilever Food Solutions - Chicago page is loaded Lead Generation...  ...to UFS marketing campaigns Create Penetration playbook, build basket affinities for Citadel...  ...subject to verification of pre-screening tests, which may include drug screening,... 
    Temporary work
    Work experience placement
    Local area
    Remote work
    Worldwide
    Monday to Friday
    Flexible hours

    Unilever

    Chicago, IL
    2 days ago
  •  ...214-4555 or Jessolin at (***) ***-**** Title: Document Control Lead/Supervisor (Hybrid) Location: Chicago, IL Duration: 12 Months...  ...define construction specifications that insure conformance to engineering and/or project management requirements, develops and maintains... 
    Work at office

    divihn.com

    Chicago, IL
    1 day ago
  •  ...Solutions Group is looking for an experienced Document Control Lead/Supervisor located in Chicago, IL. Our client is a Natural...  ...processes for a team of Document Control Specialists supporting engineering and construction projects. This role ensures all project documentation... 
    Work at office
    Shift work

    MARS IT Corp

    Chicago, IL
    1 day ago
  •  ...exciting opportunity for a Security Practice Lead to join our Cybersecurity National...  ...with the broader Presidio Sales and Engineering organization. Travel Requirements 20‑...  ...Security consulting services (e.g., penetration testing, PCI audit, security assessment) is highly... 
    For contractors
    Local area

    Presidio, Inc.

    Chicago, IL
    4 days ago
  •  ...Application Security Tester & AI Red Team Subject Matter Expert in Chicago, IL. In this senior-level role, you will lead application penetration tests and be a key authority in AI-enabled security practices. Candidates should have 5-8+ years of offensive security experience... 
    Flexible hours

    Evolve Security

    Chicago, IL
    15 hours ago
  •  ...automotive components, and North American market penetration, while acting as the key liaison between...  ...the full foreign trade sales cycle from lead generation to contract negotiation and account maintenance. Coordinate sample testing processes, pricing strategies, quotations... 
    Remote job
    Contract work
    Overseas

    MatchaTalent

    Chicago, IL
    4 days ago
  • Capgemini is seeking a Test Automation Engineer based in Chicago, IL. This role is key in ensuring software quality through functional validation and automation testing. The ideal candidate will design, execute, and maintain automated test solutions while collaborating... 

    Capgemini

    Chicago, IL
    2 days ago
  • $53.58k - $122.4k

    # Test Automation Engineer - Spanish/Catalan/ValencianChicagoApply for this job* Permanent* Experienced Professionals* Quality Engineering & Testing...  ...to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a... 
    Permanent employment
    Full time
    Local area

    Capgemini

    Chicago, IL
    2 days ago
  • A leading electrical solutions firm is seeking a Staff Manufacturing Quality Engineer in Chicago, IL. This role involves leading quality initiatives, resolving complex manufacturing issues, and improving processes across departments. Ideal candidates should have 7-10 years... 

    S & C Electric Company

    Chicago, IL
    3 days ago
  •  ...Job Title: Salesforce QA Test Automation Engineer Job Summary: We are seeking a skilled Test Automation Engineer to design, develop, and maintain automated test scripts for Salesforce applications, leveraging Selenium with C# for web and Appium for mobile... 

    TriOptus LLC

    Chicago, IL
    23 days ago
  • $110.5k - $133k

     ...of experience with our customers, we apply leading-edge technologies to support security and safety throughout the world. We engineer our products from start to finish and manufacture...  ...and executing software and hardware test plans for embedded systems. The Test engineer... 
    Relocation

    Motorola Solutions

    Chicago, IL
    23 hours ago
  • HIL Test Engineer, Mossville (Chicago, IL) Overview The role is for an HIL engineering. The HIL engineer will set up HIL systems, do plant modeling for the HIL and test software that is being released. Some harness development may be required. Responsibilities Setting up... 
    Contract work
    Immediate start

    Cedent

    Chicago, IL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Penetration Test Engineer. Be the first to apply!