S&P Global, Inc

Lead InfoSec Engineer, Vulnerability Management

S&P Global, Inc$125K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in operational security, focusing on vulnerability management or related fields
  • Expertise in vulnerability assessment frameworks like CVE and CVSS
  • Strong application security background with risk assessment capabilities
  • Familiarity with application security testing tools such as DAST/SAST
  • Bachelor's degree in Computer Science or equivalent experience
  • Proven leadership skills in driving cross-functional initiatives
  • Strong analytical and communication skills, presenting to both technical and executive audiences
  • Relevant security certifications (CISSP, CISM, CEH, GCIH)

Responsibilities

  • Lead vulnerability management lifecycle enterprise-wide across various environments
  • Drive collaboration among application teams, IT managers, and stakeholders for timely vulnerability remediation
  • Develop reporting programs to provide visibility into security posture and risk trends to leadership
  • Mentor junior security professionals and contribute to program maturity
  • Support compliance and audit activities within security frameworks
  • Establish KPIs for vulnerability remediation and ensure accountability in security outcomes

Benefits

  • Participation in an annual incentive plan
  • Comprehensive employee benefits package
Full Job Description
About the Role:

Grade Level (for internal use):

11

The Team:

Our Information Security team is a growing corporate enterprise function that operates cross-divisionally to enable business success through proactive security practices. We're transforming our approach from reactive response to proactive risk management, building technology-enabled environments that support innovation while maintaining a strong security posture. As a collaborative team, we partner across all divisions to ensure security becomes an enabler rather than a barrier to business objectives.

Responsibilities and Impact:

  • Lead enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments, providing strategic oversight and risk-based prioritization to protect critical business assets

  • Drive cross-functional collaboration with application teams, IT managers, and business stakeholders to ensure timely vulnerability remediation while balancing security requirements with business priorities

  • Develop comprehensive reporting and metrics programs using multiple data sources to provide executive leadership with clear visibility into organizational security posture and risk trends

  • Mentor and guide junior security professionals while contributing to program maturity through process improvements, governance frameworks, and tooling strategy development

  • Support regulatory compliance and audit activities by ensuring alignment with enterprise security policies, industry standards, and emerging technology risk management requirements

  • Establish and monitor key performance indicators for vulnerability remediation, creating accountability frameworks that drive measurable improvements in security outcomes

What We're Looking For:

Basic Required Qualifications:

  • 7+ years of operational security experience in vulnerability management, application security testing, or technical project management within large-scale, distributed enterprise environments

  • Deep expertise in vulnerability assessment frameworks including CVE, CVSS, CWE, and experience with enterprise vulnerability management platforms such as Qualys, Tanium, Rapid7, or similar solutions

  • Strong application security knowledge with ability to assess risk, map vulnerabilities to exploitation techniques, and translate complex technical findings into actionable business recommendations

  • Experience with application security testing tools including DAST/SAST platforms such as Fortify, Checkmarx, Veracode, or equivalent application security testing solutions

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology or equivalent professional experience in information security roles

  • Proven leadership and influence capabilities with demonstrated ability to drive cross-functional initiatives and stakeholder alignment without direct authority

  • Excellent analytical and communication skills with the ability to present security risks and recommendations to both technical teams and executive audiences

  • Relevant information security certifications such as CISSP, CISM, CEH, GCIH, or equivalent industry-recognized credentials

Additional Preferred Qualifications:

  • Advanced vulnerability management expertise with experience leading complex assessments across on-premises and cloud environments, including network, application, and configuration scanning with a deep understanding of remediation strategies

  • Proficiency in security reporting and analytics tools such as Power BI, Tableau, or similar platforms for developing executive-level dashboards and security metrics visualization

  • Strong knowledge of information security frameworks including NIST Cybersecurity Framework, ISO 27001, and risk management methodologies with experience supporting audit and regulatory compliance activities

  • Foundational understanding of emerging technologies including cloud platforms, AI/ML systems, and associated security risks such as model vulnerabilities and data protection considerations

Compensation/Benefits Information: (This section is only applicable to US candidates) 

S&P Global states that the anticipated base salary range for this position is $125,000 to $145,000. Final base salary for this role will be based on the individual’s geographic location, as well as experience level, skill set, training, licenses and certifications. 

In addition to base compensation, this role is eligible for an annual incentive plan. 

This role is eligible to receive additional S&P Global benefits. For more information on the benefits we provide to our employees, please click here.  

About S&P Global, Inc

S&P Global Market Intelligence is an exclusive analysis and in-depth data in real time for the banking.

S&P Global, Inc Careers

Join the dynamic team at S&P Global, Inc, a leader in providing transparent and innovative financial intelligence and analytics. As a global powerhouse, we are at the forefront of shaping the financial industry, making this an ideal time to advance your career with us. Work You’ll Do At S&P Global, Inc, you will be part of a culture that thrives on diversity, leadership, and professional excellence. Our team is committed to fostering an environment where innovation and growth are not just encouraged but are part of everyday activities. Transform your career with opportunities that place you at the intersection of data, technology, and market insights. Our professionals lead the industry in delivering cutting-edge solutions that address the challenges of today’s global markets. Join our team and collaborate with some of the brightest minds in the industry. With over 20,000 dedicated professionals worldwide, S&P Global, Inc offers a unique platform for professional growth and networking. S&P Global, Inc Jobs and Employment Opportunities We are continuously expanding our team and looking for talented individuals who are eager to drive innovation and lead change. Explore job opportunities in various fields, from financial services to data analysis, and contribute to our mission of providing essential intelligence. Do Innovative Work Be part of a company that values the skills and knowledge of its employees. At S&P Global, Inc, innovation is at the core of what we do. We offer a range of positions that allow you to apply your expertise and push the boundaries of what is possible in the financial sector. Internship Programs Kickstart your career with an internship at S&P Global, Inc. Our internships provide invaluable workplace experience and a chance to develop key skills that will aid you in your professional journey. Interns at S&P Global, Inc are crucial team members, working on projects that directly impact our business and clients. Benefits and Growth S&P Global, Inc is dedicated to the growth and development of its employees. We offer comprehensive benefits designed to enhance your life and well-being. From advanced career development programs to leadership training, we provide the tools necessary for you to succeed. Stay Connected Join Our Team Search open positions that match your skills and interests. We are looking for passionate, curious, and solution-driven team players. Whether you are starting your career or looking to take it to the next level, S&P Global, Inc offers a range of job opportunities and career paths. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at S&P Global, Inc. S&P Global, Inc is not just a company—it’s a place where you can make a difference. Join us and help shape the future of the financial world.
Learn more about S&P Global, Inc
Size
22,850 employees
Market Cap
$107.6 billion
Industry
Net Income
$2.3 billion
Founded
1888
5 Year Trend
+7.9%
Revenue
$7.4 billion
NASDAQ

Similar Jobs

More Jobs at S&P Global, Inc

More Information Technology Jobs

Find similar Lead InfoSec Engineer, Vulnerability Management jobs: