Lead Penetration Test Engineer
$135k - $200kS&P Global
Lead Penetration Test Engineer
The Role: Lead Penetration Test Engineer
Location: Hybrid 2 days per week onsite on one of our following sites:
US: Boston, MA, Chicago, IL, Dallas, TX, Houston, TX, Englewood, CO, Raleigh, NC, Princeton, NJ, New York, NY, Southfield, MI, Washington, DC.
Canada: Toronto, ON, Calgary, AB
The Team: The S&P Ratings Security team focuses on protecting our clients and users from modern security threats. Our mission is to safeguard systems and data by developing innovative solutions to the industry's most complex security challenges. We are passionate problem solvers with deep security expertise.
Responsibilities and Impact:
We are seeking a Lead Penetration Test Engineer with extensive experience in penetration testing and offensive security. The ideal candidate will conduct penetration tests, re-testing, vulnerability scanning, and threat assessments across diverse environments. This role requires strong offensive security skills combined with cloud and application security expertise to identify vulnerabilities and develop effective mitigation strategies.
A successful candidate will excel in the following areas:
Penetration Testing & Vulnerability Assessments
• Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
• Develop custom scripts, tools, and methodologies to enhance penetration testing capabilities and automate security testing within CI/CD pipelines.
• Apply cloud-specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing.
Vulnerability Management & Remediation
• Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security across development and production lifecycles.
• Perform detailed security assessments using DAST, SAST, and SCA tools to ensure continuous validation and improvement of security controls.
Attack Simulations & Research
• Lead and participate in attack simulations and tabletop exercises to validate security controls and improve organizational response capabilities.
• Research emerging threats, attack vectors, and adversarial techniques to inform offensive and defensive strategies.
• Partner with internal teams to design and execute threat assessments based on intelligence feeds and threat actor analysis.
Security Communication & Reporting
• Communicate and present penetration testing and security assessment findings to both technical and non-technical stakeholders.
• Provide actionable remediation guidance and risk mitigation strategies to strengthen the organization's overall security posture.
What We're Looking For
Basic Required Qualifications
• Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent experience.
• Minimum 8 years of experience in information security with a strong focus on penetration testing, application security, and vulnerability management.
• Hands-on experience with penetration testing tools (e.g., Burp Suite, Nessus, Metasploit, Nmap) and methodologies (e.g., OWASP Top 10, MITRE ATT&CK, PTES).
• Expertise in identifying and exploiting common infrastructure and web application vulnerabilities (e.g., XSS, SQL Injection, IDOR).
• Familiarity with vulnerability classification and scoring frameworks (CVE, CVSS, CWE).
• Strong scripting or programming skills (e.g., Bash, Python, Go, PowerShell, JavaScript).
• Experience performing security assessments (DAST, SAST, SCA, credential scanning) and integrating security testing into CI/CD pipelines.
• Ability to translate complex technical findings into clear, actionable reports and confidently brief cross-functional teams and executives.
• At least one recognized offensive security certification (OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT).
Preferred Qualifications
• Experience with cloud security across AWS, Azure, or GCP.
• Knowledge of AI/ML security and adversarial testing methods, including evaluating LLMs and other models for manipulation, evasion, and data integrity risks.
• Demonstrated involvement in the infosec community (e.g., open-source projects, bug bounties, CVE research, conference talks, or security publications).
• Experience applying the MITRE ATT&CK Framework to offensive security operations and threat emulation.
• Familiarity with secure software development practices and the software development lifecycle.
• Experience with Java application technologies, deployment frameworks, and associated security best practices.
• Ability to work collaboratively across teams while independently owning deliverables and maintaining accountability to deadlines.
Right to work requirements for US based out candidates:
This role is open only for candidates with indefinite right to work within the US.
Compensation/Benefits Information (US Applicants Only): S&P Global states that the anticipated base salary range for this position is $135,000 USD – $200,000 USD. Final base salary for this role will be based on the individual's geographical location as well as experience and qualifications for the role.
In addition to base compensation, this role is eligible to receive additional S&P Global benefits. For more information on the benefits we provide to our employees, please click here.
Right to work requirements for Canada based out Candidates:
This role is open for candidates with indefinite right to work within Canada.
Compensation/Benefits Information: (This section is only applicable to Canadian Candidates:) S&P Global states that the anticipated range of compensation for this position is 135,000 CAD to 180,000 CAD. Final compensation for this role will be based on the individual's performance, geographic location, as well as experience level, skill set, training, licenses, and certifications.
About S&P Global Ratings At S&P Global Ratings, our analyst-driven credit ratings, research, and sustainable finance opinions provide critical insights that are essential to translating complexity into clarity so market participants can uncover opportunities and make decisions with conviction. By bringing transparency to the market through high-quality independent opinions on creditworthiness, we enable growth across a wide variety of organizations, including businesses, governments, and institutions.
S&P Global Ratings is a division of S&P Global (NYSE: SPGI). S&P Global is the world's foremost provider of credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets. With every one of our offerings, we help many of the world's leading organizations navigate the economic landscape so they can plan for tomorrow, today. For more information, visit
Our Mission:
Advancing Essential Intelligence.
Our People:
We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all. From finding new ways to measure sustainability to analyzing energy transition across the supply chain to building workflow solutions that make it easy to tap into insight and apply it. We are changing the way people see things and empowering them to make an impact on the world we live in. We're committed to a more equitable future and to helping our customers find new, sustainable ways of doing business. Join us and help create the critical insights that truly make a difference.
Our Values:
Integrity, Discovery, Partnership
Throughout our history, the world's leading organizations have relied on us for the Essential Intelligence they need to make confident decisions about the road ahead. We start with a foundation of integrity in all we do, bring a spirit of discovery to our work, and collaborate in close partnership with each other and our customers to achieve shared goals.
Benefits:
We take care of you, so you can take care of business. We care about our people. That's why we provide everything you—and your career—need to thrive at S&P Global. Our benefits include:
- Health & Wellness: Health care coverage designed for the mind and body.
- Flexible Downtime: Generous time off helps keep you energized for your time on.
- Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
- Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company-matched student loan contribution, and financial wellness programs.
- Family Friendly Perks: It's not just about you. S&P Global has perks for your partners and
- ...What you'll be doing: The Automotive Test Engineer is responsible for delivering a stable and representative test environment to perform automated testing and functional integration of distributed features. This engineer should be capable of working with various Engineering...Suggested
- ...hundreds of ambulatory care locations. Based in Detroit, Henry Ford is one of the nation’s most respected academic medical centers and is leading the Future of Health: Detroit, a $3 billion investment anchored by a reimagined Henry Ford academic healthcare campus. Learn more...SuggestedFull timeShift work
- .... We are committed to being America's best first job. Let's talk. Make your move. See a day in the life of a Guest Experience Lead at McDonald's Requirements: We believe in letting you do you. If you're looking for a part-time job that supports your full-...SuggestedFull timePart timeLocal area
- ...Job Title: Validation / Performance Testing Engineer Location: Auburn Hills, MI Position Type: Contract Duration... ...over the road test trip execution for assigned programs. *Lead the communications and reporting of issues which include status...SuggestedContract workWork experience placement
- ...Job Title: Test Automation Engineer Dearborn, MI The pay range for this role is $90,000- $95000 Essential Job Functions... ...as appropriate to communicate progress with onshore test lead. Job Summary: This position is for an...Suggested
- ...via OTA, wire flashing, and/or USB in a vehicle (fleet updates) • Experience performing stress, functional, feature, and core hotfix testing for various modules in a targeted time frame and runs. • Validation experience in over-the-air updates for components 3G/4G TCUs,...
- ...Responsibilities Kforce has a client that is seeking a Performance Test Engineer in Lansing, MI.Summary:The ideal candidate should have... ...: Performance Test Engineer will design and lead comprehensive performance testing strategies aligned with business...Hourly payContract work
- ...DTS is looking for Performance Test Engineer for our direct client position in Farmington Hills / Okemos, MI Job Responsibilities: Design and lead comprehensive performance testing strategies to validate system behavior under load, stress, and peak conditions. Align these...
$80k - $110k
...fill ASAP. Salary $80-110K - Can't work remote. Location: Dearborn, MI Manual - IVI (Infotainment) testing Engineer : • Automotive domain knowledge with Infotainment Testing experience (Mandatory) • Candidate should have work experience on...Work experience placementImmediate startRemote work$106.6k - $165.7k
...at minimum [or other frequency dictated by the business if more than 3 days]. The Role The Senior Wireless Test Engineer - Cellular Systems will lead lab and field validation of GM's 4G and 5G cellular connectivity, ensuring robust voice, data, and safety-critical...H1bLocal areaRemote workWork from homeRelocationRelocation packageFlexible hours- ...Performance Test Engineer Job Location: Charlotte NC/ Detroit MI Job Type: Contract Rate: Depend on Experience Job Authorization... ...team, other Testing Eng. Svcs team members. ~ Skilled at leading meetings, documenting test results, status updates, etc. ~ Flexibility...Contract workWork experience placementWork at office
- ...Brilar is an industry-leading commercial landscape maintenance and snow management company... ...that trucks, heavy equipment, and small engines operate safely and efficiently, with minimal... ...Ability to pass a pre-employment drug test and consent to random, reasonable suspicion...Hourly payFull time
- ...Position Summary The Lead Artist will be the example to all other technicians by providing best in class services in his/her technical domain to LifeSpa Members and Guests. They will hire and coach the LifeSpa team to ensure they are financially successful as well...Hourly pay
- ...Responsibilities Take responsibility for developing and delivering a key element of the organization's data management system. Lead the implementation of data and analytics strategy by developing a data insights integration approach and process aligned to key...Local area
- ...Robotics Test & Validation Engineer Location: Warren, MI/ Mountain View, CA (Onsite) Duration: Full-time only Must Have Technical/Functional Skills • 5+ years of experience in robotics testing and validation. • Strong background in HIL testing and simulation...Full timeImmediate startRelocation
$40 - $42 per hour
...Insight Global is looking for 2 Robotics Test & Validation Engineer in the Warren, Michigan area. The engineer will develop innovative test frameworks for robotics, including hardware-in-the-loop (HIL), simulation-driven validation, and continuous safety monitoring. The...- ...the team in compliance with food safety standards and regulations and working in a safe manner aligning to 200% accountability. Leading team members to ensure ordering, receiving, stocking, pricing, and product display are completed, where applicable. Actively creating...Weekly pay
- ...The System Test Engineer ensures the elicitation of the requirements/KPI's, the test coverage of the System and System Architecture Requirements... ...test and the relevant System release. reports to the Test Lead or System Validation Technical Project Manager....Work at office
$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Berkley. These... ...Our Program Helps Step-by-step hiring guidance Practice tests Interview preparation Job tools and support Apply for TSA...Shift workNight shiftWeekend work- ...Lead Medical Assistant Location: Southfield, MI Lead the Frontline of Patient Care at EPIC Health At EPIC Health, we are committed... ...and validate competency for clinical procedures, point-of-care testing, injections, specimen collection, and workflow processes....Work at office
- ...Overview Life at Medxcel: Where purpose meets opportunity Medxcel is here to lead the transformation of healthcare facilities management by incorporating a new approach to providing services. Created by healthcare, for healthcare, we have a dedicated focus...Full timeShift work
- ...delivered across multiple locations. You'll empower teams, optimize systems, and ensure every patient interaction reflects excellence. Lead Systems That Save Lives You'll guide imaging operations across several sites, ensuring everything runs smoothly—from scheduling to...Bi-weekly pay
- Work Where You MatterAt Dollar General, our mission is Serving Others! We value each and every one of our employees. Whether you are looking to launch a new career in one of our many convenient Store locations, Distribution Centers, Store Support...
- ...ArcelorMittal R&D seeks a FT Sr. Engineer, Automotive Product Applications in Southfield, MI, responsible to develop and promote designs for weight and cost reduction to achieve competitive solutions for vehicle applications. Reqs: Master degree or equiv. in Indust...Work at office1 day per week
- ...Job Description Job Description Online Pickup Lead Location: Livonia, MI Type: Full-Time | Store Opening in 2026! Lead with Care. Serve with Purpose. At Meijer, we believe in helping people live better lives. As a family-founded company, we take pride...Weekly payFull timeLocal area
- ...supplier audits and process capability studies to ensure compliance with DENSO-specific requirements. • Collaborate with design and engineering teams to ensure quality of new components and software development process. • Drive root cause analysis and corrective actions...
$49.31k - $62.3k
...Lead Program Support Specialist This is a hybrid role and will require 3 days per week in office in Troy, MI or West Chicago, IL. The Lead Program Support Specialist is responsible for responding to correspondence addressed to the GM Executive Office related to...Temporary workFreelanceLocal areaFlexible hours3 days per week- ...Job Description Job Description United Precision Products is hiring a Quality Engineer to support our aerospace fastener manufacturing operation in Dearborn Heights, MI. We are a 100% aerospace manufacturer specializing in internal engine fasteners, double-ended...Full timeMonday to FridayAfternoon shift
- ...high-performing development and validation engineers with engine, transmission, and drive unit... ..., and executing subsystem level tests in a world class testing and development... ...identifying opportunities for data reduction, and leading the migration of lab-based activities to...
- ...The ICT Shift Lead (Offshift) is a proximity based, technical operations role responsible for ensuring stable, uninterrupted ICT support during 2nd and 3rd shifts across Stellantis Assembly, Stamping, and Powertrain manufacturing operations. This role serves as the primary...Full timeContract workImmediate startShift workNight shiftWeekend workDay shiftAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Penetration Test Engineer. Be the first to apply!




