S&P Global
Lead,InformationSecurity
Neural analysis suggests this role is
optimal for Lead candidates.
“Lead, Information Security at S&P Global. Skills: Application Security, DevSecOps, Cloud Security, AI Security. Responsible AI. Secure AI development”
What You'll Achieve.
Increase value in products through security posture; Show customers information is well protected; Reduce risk; Improve and ensure security throughout product lifecycle; Proactively address risks; Enhance security posture of development projects; Identify and assess potential security threats early; Facilitate design of robust security controls; Ensure applications are resilient; Improve protection, visibility and transparency; Increase security awareness; Empowering them to make an impact
Industry & Context.
Identify and assess potential security threats; Proactively address risks; Enhance security posture; Identify, prioritize, and drive remediation
What They're Looking For.
Must Have
AI and Agentic AI Security reviews, Cloud Security, Dynamic vulnerability assessments (DAST), Static vulnerability assessments (SAST), Software composition analysis (SCA), Mobile vulnerability Assessments (MVA), Penetration Testing, Product engagement, DevSecOps, CI/CD Pipeline, deployment automation, security controls, cloud architectures, networks, monitoring, technical security policies, cloud security, network security, secure coding practices, Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), AWS security specific certificates, GCP security specific certificates, Azure security specific certificates
Nice to Have
AWS, GCP, Azure
What You'll Do.
Secure AI development
Agentic AI system development
Build SecDevOps program
Champion security practices
Design secure coding practices
Implement threat modeling
Manage application security performance
Engage with business units
Identify security vulnerabilities
Document security standards
Facilitate educational opportunities
Provide technical guidance
How You'll Work.
Team & Collaboration
Engage closely with product teams; Collaborate with cross-functional teams; Partner with each other; Collaborate with customers
Communication Scope
Excellent communication skills; Interpersonal skills
Process & Methodology
Drive remediation of security vulnerabilities, Drive adoption of security practices
Full Job Description
# **About the Role:** **Grade Level (for internal use):** 11 About the Role: The Team: The SPGI Market Intelligence InfoSec team works to increase value in our products through strong security posture. When we can show our customers their information is well protected with us, they are more apt to bring new opportunities. Additionally, our work to reduce risk contributes to the value returned to our customers and shareholders. We engage closely with product teams to deliver security practices, capabilities, and advisory services to continually improve and ensure security is incorporated throughout the product lifecycle. Responsibilities and Impact: * Responsible AI * Secure AI and Agentic AI system development * Build and drive a coherent, scalable application security and SecDevOps program across the division, ensuring alignment with the corporate security strategy, capabilities, and policies. * Champion the adoption of security practices within the DevOps cycle to proactively address risks and enhance the security posture of development projects. * Design and promote secure coding practices, training and assets for application development teams. * Implement threat modeling practices to identify and assess potential security threats early in the development lifecycle. This proactive approach will facilitate the design of robust security controls, ensuring that applications are resilient against emerging threats. * Manage and report on application security performance, metrics, and KPIs. Required Qualifications: Hands on Experience & ability to run: * AI and Agentic AI Security reviews * Cloud Security * Dynamic vulnerability assessments (DAST) * Static vulnerability assessments (SAST) – Code reviews * Software composition analysis (SCA) * Mobile vulnerability Assessments (MVA) – IOS & Android * Penetration Testing * Product engagement * Engage closely with business units to understand their security requirements and align security capabilities accordingly. * Identi
Applying for this Lead, Information Security role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about S&P Global?
Real rants from real employees. Read before you apply.