Talent Apply
Log in
All jobs
SG

Lead Security Engineer

S&P Global
Gdansk, Poland
On-site

About this role

Lead Security Engineer in S&P Global Market Intelligence's security engineering team. You will lead offensive security activities across product portfolios, directing regional strategy and partnering with senior product and engineering leaders to identify, prioritize, and remediate security risks.

What You'll Do

  • Lead and oversee hands-on application and cloud penetration testing across assigned product portfolios, focusing on real-world exploitability and business risk while directing security engineering strategy for the region
  • Plan, conduct, and supervise red team activities in accordance with approved scope, authorization, and Rules of Engagement defined by Corporate Offensive Security, ensuring team compliance and operational excellence
  • Drive adoption of AI-assisted testing techniques across security teams to improve coverage, efficiency, and testing quality while establishing best practices
  • Engage directly with senior product and engineering leadership to explain attack paths, prioritize findings, and facilitate timely, durable remediation while building organizational security capabilities
  • Establish validation processes for remediation effectiveness, ensuring exploit paths are fully closed and do not regress, while mentoring team members on advanced security assessment techniques
  • Transform findings and remediation efforts into educational programs and strategic guidance to drive stronger proactive security posture in alignment with Corporate and Divisional security teams, contributing to enterprise offensive security standards, playbooks, and threat scenarios while producing executive-level reports that communicate exploitability, impact, and remediation status to senior leadership

What We're Looking For

  • 10+ years of experience in penetration testing, red teaming, application security, or offensive security engineering with demonstrated leadership experience in managing security teams or strategic initiatives
  • Strong expertise in web, API, and cloud-native security testing across multiple environments, including authentication, authorization, and identity abuse scenarios with ability to architect comprehensive security assessment programs
  • Experience testing modern architectures including microservices, CI/CD platforms, containerization technologies, and SaaS security frameworks
  • Advanced scripting and development experience in programming languages to support exploit development, automation, and security tooling at enterprise scale
  • Deep knowledge of security frameworks including OWASP Top 10, CWE/SANS Top 25, and secure development practices with proven ability to establish governance processes within formal red team programs
  • Exceptional written and verbal communication skills with demonstrated ability to convey complex security risks to executive leadership, technical teams, and business stakeholders across all organizational levels

Nice to Have

  • Advanced offensive security certifications or equivalent professional experience demonstrating mastery in penetration testing and red team leadership
  • Experience testing AI-enabled or agentic systems with ability to develop security assessment frameworks for emerging technologies and guide organizational adoption strategies
  • Proven experience with threat modeling and secure architecture review including ability to influence enterprise security architecture decisions and mentor teams on advanced security design principles
  • Demonstrated success in building and scaling security programs across multiple business units or geographic regions with experience driving organizational security culture transformation

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →