Lead InfoSec Engineer, DevSecOps

OSTTRANew York, NY

About The Position

S&P Global's technology platforms continue to expand in scale, cloud adoption, and regulatory exposure. To support secure delivery across multiple product lines, there is a critical need for a senior DevSecOps role that embeds security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Requirements

  • 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift) and infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi
  • Strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms
  • Bachelor's degree in Computer Science , Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python, Go, or similar for automation and platform development
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies

Nice To Haves

  • Advanced DevSecOps platform experience including building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, Checkmarx , Veracode, or equivalent security testing solutions
  • Cloud security expertise with experience using cloud security platforms (CSPM, CNAPP), secrets management solutions such as HashiCorp Vault or cloud-native services, and zero trust or identity-centric security architectures
  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials

Responsibilities

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
  • Champion developer-first security experiences by designing "paved road" security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining strong security posture
  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall DevSecOps maturity across the organization
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level

Benefits

  • Competitive pay
  • Retirement planning
  • Continuing education program with a company-matched student loan contribution
  • Financial wellness programs
  • Health care coverage designed for the mind and body
  • Generous time off
  • Access a wealth of resources to grow your career and learn valuable new skills
  • Perks for partners and little ones
  • Retail discounts
  • Referral incentive awards
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service