Lead Penetration Test Engineer

🕒 September 10

🌐 United States, Canada – Remote

infoinfo

🏄 California, Colorado, +7 more states – Remote

infoinfo

💵 $135k - $200k / year

⏰ Full Time

🟠 Senior

⚙️ Software Development Engineer in Test (SDET)

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of S&P Global

S&P Global

10,000+ employees

Founded 1860

💼 Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

S&P Global is a leading provider of market intelligence, ratings, analytics, and benchmark indices. The company offers comprehensive insights across various domains including finance, commodities, mobility, and sustainability. Renowned for its data-driven solutions, S&P Global assists organizations in navigating complex market trends, evaluating credit risk, and understanding the implications of artificial intelligence and energy transitions. Its diverse offerings, such as S&P Global Market Intelligence, S&P Global Ratings, and S&P Dow Jones Indices, provide critical data and analytics to businesses, government entities, and investors worldwide.

📋 Description

• Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments • Perform re-testing, vulnerability scanning, and threat assessments across diverse environments • Develop custom scripts, tools, and methodologies to improve penetration testing and automate security testing in CI/CD pipelines • Apply cloud offensive techniques including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing • Collaborate with engineering and development teams on vulnerability analysis, remediation plans, and application security • Perform DAST, SAST, and SCA security assessments • Lead and participate in attack simulations and tabletop exercises • Research emerging threats, attack vectors, and adversarial techniques • Design and execute threat assessments using intelligence feeds and threat actor analysis • Present findings to technical and non-technical stakeholders • Provide remediation guidance and risk mitigation strategies

🎯 Requirements

• Minimum 8 years of experience in information security focused on penetration testing, application security, and vulnerability management • Hands-on experience with Burp Suite, Nessus, Metasploit, and Nmap • Knowledge of OWASP Top 10, MITRE ATT&CK, and PTES • Expertise identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR • Familiarity with CVE, CVSS, and CWE • Strong scripting or programming skills in Bash, Python, Go, PowerShell, or JavaScript • Experience with DAST, SAST, SCA, credential scanning, and CI/CD security integration • Ability to communicate technical findings through actionable reports and brief cross-functional teams and executives • At least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT • Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent experience • US-based candidates must have indefinite right to work in the US; Canada-based candidates must have indefinite right to work in Canada

🏖️ Benefits

• Health care coverage designed for the mind and body • Generous time off • Continuous learning resources and career development • Competitive pay • Retirement planning • Continuing education program with company-matched student loan contribution • Financial wellness programs • Family benefits and perks • Retail discounts • Referral incentive awards

Apply Now

Similar Jobs

🕒 September 4

Revecore

1001 - 5000

🏥 Healthcare

☁️ SaaS

🤝 B2B

Senior QA Automation Engineer leading automated testing for Revecore’s hospital revenue recovery technology. Building frameworks, integrating CI/CD tests, and mentoring QA engineers.

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

⚙️ Software Development Engineer in Test (SDET)

🕒 September 4

Lantheus

501 - 1000

💊 Pharmaceuticals

🏥 Healthcare

🤖 Artificial Intelligence

Solution Architect building enterprise automation and AI-enabled workflows for Lantheus, a radiopharmaceutical company. Establishing its Automation Center of Excellence across regulated business functions.

🕒 September 2

Reveleer

51 - 200

🏥 Healthcare

⚕️ Healthcare Insurance

☁️ SaaS

SDET automating web, API, and performance testing for Reveleer’s healthcare value-based care platform. Building AI-enhanced quality controls for compliant, reliable releases.

🕒 August 31

Claroty

501 - 1000

🍽️ Food & Beverage

🏭 Manufacturing

📦 Logistics

Senior QA Automation Engineer automating tests for Claroty’s cyber-physical security platform. Validating cloud-native, federal, and air-gapped deployments for US government environments.

🇺🇸 United States – Remote

💵 $150k - $165k / year

⏰ Full Time

🟠 Senior

⚙️ Software Development Engineer in Test (SDET)

🕒 August 31

eHealth, Inc.

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

Senior SDET automating API and web application testing for eHealth’s health insurance marketplace. Building test frameworks, CI/CD pipelines, and defect-resolution workflows.

🇺🇸 United States – Remote

💵 $129.7k - $162.1k / year

💰 Post-IPO Equity on 2021-01

⏰ Full Time

🟠 Senior

⚙️ Software Development Engineer in Test (SDET)