About this role
Offensive Security Senior Analyst
Hyderabad, Telangana Full time Posted Today Job requisition id 331953
About the Role
Grade Level (for internal use): 11 The Team: Our Offensive Security team fosters a culture of inclusiveness, teamwork, knowledge sharing, relentless learning, integrity and fun. Operating under the tagline "Offense sharpens defense," we strengthen our ability to detect, disrupt, and withstand cyber threats through red and collaborative purple team operations. We value continuous growth and believe that by challenging our defenses and assumption, we build a more resilient security posture for S&P Global.
Responsibilities and Impact:
- Conduct red team engagements to simulate advanced persistent threats and real-world attack scenarios against S&P Global's infrastructure and applications
- Execute purple team exercises by collaborating with defensive security teams to enhance detection & prevention capabilities, incident response procedures and cyber resiliency against the threat actors that target S&P Global
- Design and conduct breach and attack simulations to identify security gaps, improve detection capabilities and validate existing security controls
- Develop custom attack tools and methodologies to test security resilience and stay ahead of emerging threat landscapes
- Partner with development and infrastructure teams to provide actionable remediation guidance and security recommendations
What We're Looking For:
Basic Required Qualifications:
- Excellent communications skills, able to effectively translate technical concepts to non-technical individuals
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent work experience
- 5+ years of hands-on experience in offensive security, purple teaming or red team operations
- Proficiency with Red Teaming frameworks and tools, both commercial and open-source
- Strong knowledge of core concepts such as network protocols, operating systems (Windows, Linux, Mac), Entra/AD, cloud platforms (AWS, Azure or GCP and associated services), databases, middleware, email and web applications
- Experience with scripting and programming languages such as Python, PowerShell, Bash, JavaScript, or similar for automation and tool development
- Experience with leveraging Artificial Intelligence through all phases of the attack chain
- Familiarity with Cyber Threat Intelligence, Threat Actors, and emulating their Tactics, Techniques and Procedures (TTPs) as well as solid knowledge of the MITRE ATT&CK framework
- Relevant security certifications such as GIAC RTP, RTO, OSCP, GPEN or equivalent industry-recognized credentials
- A strong desire for continuous learning and a tenacious attitude
- Demonstrated ability to manage responsibilities independently while contributing positively to cross-functional team objectives
Additional Preferred Qualifications:
- Experience with SIEM technologies, Identity & Access Management systems, and defensive security platforms (EDR, Next-Gen Firewalls, IDS/IPS, WAF, proxies, CDR) including associated bypass and evasion techniques
- Knowledge of DevSecOps practices and experience integrating security testing into CI/CD pipelines
What’s In It For You?
Our Mission: Advancing Essential Intelligence.
Our People: We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all.
From finding new ways to measure sustainability to analyzing energy transition across the supply chain to building workflow solutions that make it easy to tap into insight and apply it. We are changing the way people see things and empowering them to make an impact on the world we live in. We’re committed to a more equitable future and to helping our customers find new, sustainable ways of doing business. Join us and help create the critical insights that truly make a difference.
Our Values: Integrity, Discovery, Partnership
Recruitment Fraud Alert: If you receive an email from a spglobalind.com domain or any other regionally based domains, it is a scam and should be reported to the appropriate contact. S&P Global never requires any candidate to pay money for job applications, interviews, offer letters, pre-employment training or for equipment/delivery of equipment. Stay informed and protect yourself from recruitment fraud by reviewing guidelines, fraudulent domains, and how to report suspicious activity.
Equal Opportunity Employer S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment.
If you need an accommodation during the application process due to a disability, please send a message through the appropriate channel and your request will be forwarded to the appropriate person.
US Candidates Only: Know Your Rights: Workplace discrimination is illegal
About S&P Global S&P Global enables businesses, governments, and individuals with trusted data, expertise and technology to make decisions with conviction. We are advancing essential intelligence through world-leading benchmarks, data, and insights that customers need in order to plan confidently, act decisively, and thrive in a rapidly changing global landscape.
Follow Us
S&P Candidate Privacy Policy
© 2026 Workday, Inc. All rights reserved.