S&P Global
Lead InfoSec Engineer DevSecOps
Job Description
Salary: £100,000 - 130,000 per year
Requirements:- We require 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments, with strong hands-on experience securing CI/CD pipelines and modern application stacks.
- We require practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies such as Docker, Kubernetes, or OpenShift, and infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi.
- We require a strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms.
- We require a bachelors degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience in DevSecOps or security engineering roles.
- We require proven ability to build and maintain internal tooling, with experience in scripting languages such as Python, Go, or similar for automation and platform development.
- We require excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders.
- We require strong collaboration and influence capabilities, with demonstrated success working embedded within engineering teams and driving security adoption without direct authority.
- We require experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies.
- Preferred: advanced DevSecOps platform experience, including building or extending internal developer platforms and security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, Checkmarx, Veracode, or equivalent security testing solutions.
- Preferred: cloud security expertise with experience using cloud security platforms (CSPM, CNAPP), secrets management solutions such as HashiCorp Vault or cloud-native services, and zero trust or identity-centric security architectures.
- Preferred: financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and implementing security controls in highly regulated environments.
- Preferred: professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials.
- We embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing to enable secure-by-default development.
- We build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms.
- We champion developer-first security experiences by designing paved-road security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining a strong security posture.
- We drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks.
- We evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness.
- We support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping.
- We provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall DevSecOps maturity across the organization.
- We lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level.
- AWS
- Azure
- CI/CD
- Cloud
- DevSecOps
- DevOps
- Docker
- Embedded
- Git
- Support
- Kubernetes
- OWASP
- OpenShift
- Pulumi
- Python
- Security
- Terraform
More:
We are S&P Global, a team of more than 35,000 people worldwide, driven by curiosity and a shared belief in Essential Intelligence. Our mission is advancing Essential Intelligence to help build a more prosperous future, and we work across sustainability, energy transition, and workflow solutions that help customers make better decisions. We value integrity, discovery, and partnership, and we offer a connected, engaged workplace with opportunities based on skills, experience, and contributions. This full-time role is based in New York, NY or London, UK. For eligible U.S. candidates, the anticipated base salary range is $100,000 to $130,000, plus eligibility for an annual incentive plan and additional benefits including health and wellness coverage, generous time off, learning resources, retirement and financial wellness support, family-friendly perks, and other employee benefits.
last updated 35 week of 2026
Interested in this role?
Submit your application now
How to Apply
About S&P Global
S&P Global
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£115,000
This role
£85,000
UK median
This salary is 35% above the UK median for Lead roles (£85,000/yr).
Based on 2024–2025 UK technology sector benchmarks