S&P Global
Lead InfoSec Engineer, DevSecOps
Job Description
**About the Role:**
**Grade Level (for internal use):**
11
S&P Global's technology platforms continue to expand in scale, cloud adoption, and regulatory exposure. To support secure delivery across multiple product lines, there is a critical need for a senior DevSecOps role that embeds security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.
**Responsibilities and Impact:**
+ Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
+ Build and maintain i...
**Grade Level (for internal use):**
11
S&P Global's technology platforms continue to expand in scale, cloud adoption, and regulatory exposure. To support secure delivery across multiple product lines, there is a critical need for a senior DevSecOps role that embeds security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.
**Responsibilities and Impact:**
+ Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
+ Build and maintain i...