×
Register Here to Apply for Jobs or Post Jobs. X

Lead InfoSec Engineer, DevSecOps

Job in New York, New York County, New York, 10261, USA
Listing for: S&P Global, Inc.
Full Time position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer
Salary/Wage Range or Industry Benchmark: 170000 - 230000 USD Yearly USD 170000.00 230000.00 YEAR
Job Description & How to Apply Below
Location: New York

Overview

About the Role:

Grade Level (for internal use): 11 S&P Global's technology platforms continue to expand in scale, cloud adoption, and regulatory exposure. To support secure delivery across multiple product lines, there is a critical need for a senior Dev Sec Ops  role that embeds security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Responsibilities

and Impact
  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development.
  • Build and maintain internal Dev Sec Ops  tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms.
  • Champion developer-first security experiences by designing "paved road" security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining strong security posture.
  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks.
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness.
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping.
  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall Dev Sec Ops  maturity across the organization.
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level.
Qualifications Basic

Required Qualifications
  • 8+ years of experience in software engineering, Dev Ops, or Dev Sec Ops  roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks.
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or Open Shift) and infrastructure-as-code tools like Terraform, Cloud Formation, or Pulumi.
  • Strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms.
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in Dev Sec Ops  or security engineering roles.
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python, Go, or similar for automation and platform development.
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders.
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority.
  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies.
Additional

Preferred Qualifications
  • Advanced Dev Sec Ops  platform experience including building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, Checkmarx, Veracode, or equivalent security testing solutions.
  • Cloud security expertise with experience using cloud security platforms (CSPM, CNAPP), secrets management solutions such as Hashi Corp Vault or cloud-native services, and zero trust or identity-centric security architectures.
  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments.
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary