S&P Global, Inc

Lead InfoSec Engineer, DevSecOps

S&P Global, Inc$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in software engineering, DevOps, or DevSecOps roles in regulated environments
  • Practical expertise in cloud platforms (AWS, Azure, Google Cloud) and container technologies (Docker, Kubernetes)
  • Strong foundation in application security including OWASP Top 10 and security testing tools
  • Bachelor's in Computer Science, Engineering, Cybersecurity or equivalent experience
  • Ability to develop and maintain internal tooling using scripting languages (Python, Go)
  • Excellent communication skills to articulate security risks and solutions
  • Proven collaboration skills within engineering teams and driving security initiatives

Responsibilities

  • Embed automated security controls in CI/CD pipelines for secure development
  • Build and maintain internal DevSecOps tooling for enterprise engineering teams
  • Champion developer-friendly security patterns and self-service tooling
  • Drive cloud-native security architecture in AWS and Azure environments
  • Evaluate and integrate best-in-class security tools for application and pipeline needs
  • Translate regulatory requirements into automated engineering controls for compliance
  • Provide technical leadership and mentorship to enhance DevSecOps maturity
  • Lead vulnerability management and security design reviews for applications and environments

Benefits

  • Eligibility for annual incentive plan
  • Access to additional S&P Global employee benefits
Full Job Description
About the Role:

Grade Level (for internal use):

11

S&P Global's technology platforms continue to expand in scale, cloud adoption, and regulatory exposure. To support secure delivery across multiple product lines, there is a critical need for a senior DevSecOps role that embeds security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Responsibilities and Impact:

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development

  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms

  • Champion developer-first security experiences by designing "paved road" security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining strong security posture

  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks

  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness

  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping

  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall DevSecOps maturity across the organization

  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level

What We're Looking For:

Basic Required Qualifications:

  • 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks

  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift) and infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi

  • Strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms

  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles

  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python, Go, or similar for automation and platform development

  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders

  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority

  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies

Additional Preferred Qualifications:

  • Advanced DevSecOps platform experience including building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, Checkmarx, Veracode, or equivalent security testing solutions

  • Cloud security expertise with experience using cloud security platforms (CSPM, CNAPP), secrets management solutions such as HashiCorp Vault or cloud-native services, and zero trust or identity-centric security architectures

  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments

  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials

Compensation/Benefits Information: (This section is only applicable to US candidates) 

S&P Global states that the anticipated base salary range for this position is $100,000 to $130,000. Final base salary for this role will be based on the individual’s geographic location, as well as experience level, skill set, training, licenses and certifications. 

In addition to base compensation, this role is eligible for an annual incentive plan. 

This role is eligible to receive additional S&P Global benefits. For more information on the benefits we provide to our employees, please click .  

About S&P Global, Inc

S&P Global Market Intelligence is an exclusive analysis and in-depth data in real time for the banking.

S&P Global, Inc Careers

Join the dynamic team at S&P Global, Inc, a leader in providing transparent and innovative financial intelligence and analytics. As a global powerhouse, we are at the forefront of shaping the financial industry, making this an ideal time to advance your career with us. Work You’ll Do At S&P Global, Inc, you will be part of a culture that thrives on diversity, leadership, and professional excellence. Our team is committed to fostering an environment where innovation and growth are not just encouraged but are part of everyday activities. Transform your career with opportunities that place you at the intersection of data, technology, and market insights. Our professionals lead the industry in delivering cutting-edge solutions that address the challenges of today’s global markets. Join our team and collaborate with some of the brightest minds in the industry. With over 20,000 dedicated professionals worldwide, S&P Global, Inc offers a unique platform for professional growth and networking. S&P Global, Inc Jobs and Employment Opportunities We are continuously expanding our team and looking for talented individuals who are eager to drive innovation and lead change. Explore job opportunities in various fields, from financial services to data analysis, and contribute to our mission of providing essential intelligence. Do Innovative Work Be part of a company that values the skills and knowledge of its employees. At S&P Global, Inc, innovation is at the core of what we do. We offer a range of positions that allow you to apply your expertise and push the boundaries of what is possible in the financial sector. Internship Programs Kickstart your career with an internship at S&P Global, Inc. Our internships provide invaluable workplace experience and a chance to develop key skills that will aid you in your professional journey. Interns at S&P Global, Inc are crucial team members, working on projects that directly impact our business and clients. Benefits and Growth S&P Global, Inc is dedicated to the growth and development of its employees. We offer comprehensive benefits designed to enhance your life and well-being. From advanced career development programs to leadership training, we provide the tools necessary for you to succeed. Stay Connected Join Our Team Search open positions that match your skills and interests. We are looking for passionate, curious, and solution-driven team players. Whether you are starting your career or looking to take it to the next level, S&P Global, Inc offers a range of job opportunities and career paths. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at S&P Global, Inc. S&P Global, Inc is not just a company—it’s a place where you can make a difference. Join us and help shape the future of the financial world.
Learn more about S&P Global, Inc
Size
22,850 employees
Market Cap
$107.6 billion
Industry
Net Income
$2.3 billion
Founded
1888
5 Year Trend
+7.9%
Revenue
$7.4 billion
NASDAQ

Similar Jobs

More Jobs at S&P Global, Inc

More Information Technology Jobs

Find similar Lead InfoSec Engineer, DevSecOps jobs: