Lead Penetration Test Engineer

🔥 16 hours ago

🌐 United States, Canada – Remote

infoinfo

🏄 California, Colorado, +7 more states – Remote

infoinfo

💵 $135k - $200k / year

⏰ Full Time

🟠 Senior

⚙️ Software Development Engineer in Test (SDET)

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of S&P Global

S&P Global

10,000+ employees

Founded 1860

💼 Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

S&P Global is a leading provider of market intelligence, ratings, analytics, and benchmark indices. The company offers comprehensive insights across various domains including finance, commodities, mobility, and sustainability. Renowned for its data-driven solutions, S&P Global assists organizations in navigating complex market trends, evaluating credit risk, and understanding the implications of artificial intelligence and energy transitions. Its diverse offerings, such as S&P Global Market Intelligence, S&P Global Ratings, and S&P Dow Jones Indices, provide critical data and analytics to businesses, government entities, and investors worldwide.

📋 Description

• Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using manual and automated techniques • Develop custom scripts, tools, and methodologies to enhance penetration testing and automate security testing in CI/CD pipelines • Apply cloud-specific offensive techniques, including IAM abuse, container and serverless exploitation, and cloud misconfiguration testing • Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security • Perform DAST, SAST, and SCA security assessments • Lead and participate in attack simulations and tabletop exercises • Research emerging threats, attack vectors, and adversarial techniques • Design and execute threat assessments using intelligence feeds and threat actor analysis • Present penetration testing and security assessment findings to technical and non-technical stakeholders • Provide remediation guidance and risk mitigation strategies

🎯 Requirements

• Minimum 8 years of experience in information security with a strong focus on penetration testing, application security, and vulnerability management • Hands-on experience with Burp Suite, Nessus, Metasploit, and Nmap • Knowledge of OWASP Top 10, MITRE ATT&CK, and PTES methodologies • Expertise identifying and exploiting infrastructure and web application vulnerabilities, including XSS, SQL Injection, and IDOR • Familiarity with CVE, CVSS, and CWE frameworks • Strong scripting or programming skills in Bash, Python, Go, PowerShell, or JavaScript • Experience with DAST, SAST, SCA, credential scanning, and CI/CD security integration • Ability to communicate technical findings through clear reports and brief cross-functional teams and executives • At least one recognized offensive security certification: OSCP, OSCE3, OSEP, GXPN, GPEN, or CREST CRT/CCT • Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent experience • US candidates must have indefinite right to work in the US • Canada candidates must have indefinite right to work in Canada

🏖️ Benefits

• Health care coverage designed for the mind and body • Generous time off • Continuous learning resources • Competitive pay • Retirement planning • Continuing education program with company-matched student loan contribution • Financial wellness programs • Family benefits for partners and children • Retail discounts • Referral incentive awards

Apply Now

Similar Jobs

🔥 19 hours ago

Xcelerate Solutions

1001 - 5000

💼 Consulting

🔒 Cybersecurity

🏢 Enterprise

QA Test Engineer testing secure enterprise web applications for GovCon technology provider Xcelerate Solutions. Automating UI, API, database, and CI/CD validation while ensuring accessibility and compliance.

🔥 19 hours ago

Xcelerate Solutions

1001 - 5000

💼 Consulting

🔒 Cybersecurity

🏢 Enterprise

QA Test Engineer testing secure enterprise web platforms for Xcelerate Solutions, a federal technology services company. Automating web, API, database, accessibility, and compliance testing.

🔥 19 hours ago

Capgemini

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Test Lead managing SAP S/4HANA transformation quality for Capgemini, a global technology transformation partner. Defining testing strategy, leading teams, coordinating UAT, and driving defect management.

🕒 Yesterday

Planned Systems International

1001 - 5000

💼 Consulting

🎖️ Defense

📦 Logistics

Senior Test Automation Engineer automating Eggplant testing for PSI’s VA healthcare IT services. Supporting IV&V, clinical workflows, defect management, and software modernization for Veterans Affairs.

🕒 Yesterday

Planned Systems International

1001 - 5000

💼 Consulting

🎖️ Defense

📦 Logistics

Senior Test Automation Engineer automating clinical software testing for PSI’s Veterans Affairs healthcare IT programs. Building Eggplant scripts, frameworks, and validation processes for VA systems.