Lead InfoSec Engineer, DevSecOps at S&P Global | London, GBR | Rezi

Lead InfoSec Engineer, DevSecOps at S&P Global

Lead InfoSec Engineer, DevSecOps

S&P Global · London, GBR

1 weeks ago

Lead InfoSec Engineer, DevSecOps

S&P Global · London, GBR

9 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

S&P Global's technology platforms are expanding in scale, cloud adoption, and regulatory exposure. This senior DevSecOps role is critical for embedding security directly into engineering platforms, CI/CD pipelines, and developer workflows to address the growing complexity of cloud-native applications and automated delivery.

Responsibilities

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, integrating security testing (SAST, DAST, SCA, container scanning).
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams.
  • Champion developer-first security experiences by designing "paved road" security patterns and self-service tooling.
  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes and infrastructure-as-code.
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs.
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls.
  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert.
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments.
  • Participate in threat modeling and architecture reviews.

Requirements

  • 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments.
  • Strong hands-on experience securing CI/CD pipelines and modern application stacks.
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud.
  • Experience with containerization technologies (such as Docker, Kubernetes, or OpenShift).
  • Experience with infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi.
  • Strong understanding of application security concepts including OWASP Top 10 and secure coding practices.
  • Experience with security testing tools such as SAST, DAST, and SCA platforms.
  • Proven ability to build and maintain internal tooling.
  • Experience in scripting languages such as Python, Go, or similar for automation and platform development.
  • Excellent technical communication skills.
  • Strong collaboration and influence capabilities.
  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies.
  • Advanced DevSecOps platform experience including building or extending internal developer platforms and security tooling.
  • Experience with SAST/DAST/SCA platforms such as Snyk, Checkmarx, Veracode, or equivalent.
  • Cloud security expertise with experience using cloud security platforms (CSPM, CNAPP).
  • Experience with secrets management solutions such as HashiCorp Vault or cloud-native services.
  • Experience with zero trust or identity-centric security architectures.
  • Financial services or regulated industry experience.
  • Knowledge of compliance frameworks and audit requirements.
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent.

Skills

  • DevSecOps
  • CI/CD
  • SAST
  • DAST
  • SCA
  • Container Scanning
  • AWS
  • Azure
  • Kubernetes
  • Docker
  • OpenShift
  • Terraform
  • CloudFormation
  • Pulumi
  • OWASP Top 10
  • Secure Coding Practices
  • Python
  • Go
  • Git
  • Agile Development Methodologies
  • CSPM
  • CNAPP
  • HashiCorp Vault

Experience Level

  • 8+ years of experience
  • Senior

Education Level

  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience

Salary/Compensations

  • $100,000 to $130,000

Benefits

  • Annual incentive plan
  • Health care coverage designed for the mind and body
  • Generous time off
  • Access to resources for career growth and learning
  • Competitive pay
  • Retirement planning
  • Continuing education program with a company-matched student loan contribution
  • Financial wellness programs
  • Perks for families
  • Retail discounts
  • Referral incentive awards

About the Company

  • Advancing Essential Intelligence.
  • More than 35,000 strong worldwide, driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future.
  • Changing the way people see things and empowering them to make an impact on the world.
  • Committed to a more equitable future and to helping customers find new, sustainable ways of doing business.
  • Integrity, Discovery, Partnership.
  • The world's leading organizations have relied on us for the Essential Intelligence they need to make confident decisions.
  • We start with a foundation of integrity in all we do, bring a spirit of discovery to our work, and collaborate in close partnership with each other and our customers to achieve shared goals.

Equal Opportunity

  • S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law.
  • Only electronic job submissions will be considered for employment.
  • If you need an accommodation during the application process due to a disability, please send an email to: EEO.Compliance@spglobal.com and your request will be forwarded to the appropriate person.