LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Join Canary Wharfian
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Senior Security Specialist

ExperiencedNo visa sponsorship

Posted 12 days ago

No clicks

**Senior Security Specialist** As a Senior Security Specialist, you'll plan, oversee, and drive penetration tests across diverse systems and applications. Your role involves managing testing engagements, ensuring quality, and providing technical oversight. Key skills needed include extensive penetration testing knowledge, application security expertise, and experience with AWS, Azure, and GCP. Past success in managing third-party vendors and driving security engagements is crucial. Risk management, leadership, and analytical skills are also vital. Familiarity with OWASP, PTES, and industry tooling is a plus. Join our team to make a significant impact in a global financial markets infrastructure provider. Full-time position in Bucharest, initially remote.

Compensation
Not specified INR

Currency: INR

City
Not specified
Country
India

Full Job Description

Role Summary

LSEG is seeking a Senior Security Specialist to join our Cyber Security Security Testing team as a penetration testing subject matter expert (SME). This engagement-focused, technical role plans, scopes and drives penetration tests across a wide range of systems and applications, providing technical oversight, assurance and consulting expertise throughout the engagement lifecycle assuring quality and delivering measurable risk reduction across applications, infrastructure, cloud and networks, while working closely with internal teams and third-party testing vendors.

Key Responsibilities

Security Testing Engagement Oversight

  • Oversee penetration testing engagements throughout the lifecycle, ensuring comprehensive coverage and quality.
  • Ensure engagements are appropriately scoped; interview application teams and review architecture to agree scope with all stakeholders.
  • Define per-engagement prerequisites, assumptions, constraints and dependencies.
  • Identify prerequisites and blockers to punctual delivery and drive their resolution.
  • Provide technical oversight during the execution phase.
  • Interface with and manage third-party vendors who deliver security testing engagements.

Technical Governance & Quality Assurance

  • Act as the technical authority and SME for penetration testing engagements.
  • Review testing methodologies, coverage and attack paths to ensure effectiveness.
  • Review penetration testing reports produced by team members and third parties -eliminate false positives and ensure accurate, appropriately rated findings.
  • Peer review retest evidence and validate remediation outcomes.

Vulnerability Reporting & Remediation

  • Conduct overview/debrief sessions before and after engagements to ensure clarity and understanding.
  • Ensure reporting of security testing activities is tailored to the intended audience.
  • Engage with technical and business stakeholders to convey testing outcomes clearly.
  • Support technical teams to understand findings and cyber security concepts.
  • Advise remediation efforts, compensating controls and risk mitigation solutions; support risk acceptance/exception processes where required.

Practice Improvement & Evangelism

  • Drive initiatives to improve internal penetration testing practices with new ideas or processes and contribute to the development of internal security testing tools.
  • Compile and maintain runbooks, checklists, methodologies and frameworks to improve coverage and scale.
  • Advocate the benefits of the various cyber security service offerings and refer stakeholders to the appropriate internal teams where gaps are identified.

Reporting & Metrics

  • Contribute to relevant KPIs, KRIs and other metrics, and to the team's operating model improvement.
  • Stay current with security trends, testing tools, exploit techniques and industry news.

Competencies

  • Technical: Apply deep penetration testing knowledge to scope, review, challenge and assure testing approaches, methodologies, coverage and findings across applications, infrastructure and cloud.
  • Risk Management: Accurately risk-rate findings, validate remediation, and advise on compensating controls and risk acceptance in line with organisational standards.
  • Leadership: Direct engagement delivery and quality across internal and vendor-delivered testing; coach testers and share subject matter expertise.
  • Analytical: Apply structured thinking and evidence to assess testing outcomes, challenge assumptions and drive continuous improvement in coverage and practice.
  • Communication: Translate technical findings into clear, audience-appropriate reporting for technical teams and business stakeholders, and align teams around engagement outcomes.

Required Skills & Experience

  • Strong working knowledge of penetration testing across Web Applications, APIs, Thick Client and infrastructure - enough to scope, review and challenge testing approaches and results.
  • Solid grasp of application security, network protocols, operating systems and cloud/containerised environments (AWS, Azure, GCP, Docker, Kubernetes) to judge testing coverage and accurately risk-rate findings.
  • Familiarity with industry tooling (e.g. Burp Suite) and testing standards (OWASP, PTES) to benchmark internal and vendor-delivered engagements.
  • Proven record of driving and overseeing security engagements - scoping complex work, agreeing Rules of Engagement, and managing and quality-assuring third-party testing vendors.
  • Ability to review penetration testing reports, eliminate false positives, and ensure findings are accurate and appropriately prioritised.
  • Ability to identify, assess and communicate technical and project risks, and translate findings into clear reporting for technical and business stakeholders.
  • Ability to align testing outcomes with agreed objectives and timelines and advise on remediation and risk acceptance.
  • Plus: experience in large, regulated enterprise environments (financial services an advantage); Threat Modelling; relevant certifications (OSCP, GPEN, GWAPT, CREST).

We're proud to have been recognised as a Great Place to Work in India 25

Career Stage:

Senior Associate

London Stock Exchange Group (LSEG) Information:

Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.

Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.

Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.

We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyones race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.

You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.

LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.

Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what its used for, and how its obtained, your rights and how to contact us as a data subject.

If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.

Location: IND-BLR-Divyasree Technopolis, Bucharest - Iuliu Maniu Boulevard

Time Type: Full time

Senior Security Specialist

Compensation

Not specified INR

City: Not specified

Country: India

London Stock Exchange logo
Other

12 days ago

No clicks

at London Stock Exchange

ExperiencedNo visa sponsorship

**Senior Security Specialist** As a Senior Security Specialist, you'll plan, oversee, and drive penetration tests across diverse systems and applications. Your role involves managing testing engagements, ensuring quality, and providing technical oversight. Key skills needed include extensive penetration testing knowledge, application security expertise, and experience with AWS, Azure, and GCP. Past success in managing third-party vendors and driving security engagements is crucial. Risk management, leadership, and analytical skills are also vital. Familiarity with OWASP, PTES, and industry tooling is a plus. Join our team to make a significant impact in a global financial markets infrastructure provider. Full-time position in Bucharest, initially remote.

Full Job Description

Role Summary

LSEG is seeking a Senior Security Specialist to join our Cyber Security Security Testing team as a penetration testing subject matter expert (SME). This engagement-focused, technical role plans, scopes and drives penetration tests across a wide range of systems and applications, providing technical oversight, assurance and consulting expertise throughout the engagement lifecycle assuring quality and delivering measurable risk reduction across applications, infrastructure, cloud and networks, while working closely with internal teams and third-party testing vendors.

Key Responsibilities

Security Testing Engagement Oversight

  • Oversee penetration testing engagements throughout the lifecycle, ensuring comprehensive coverage and quality.
  • Ensure engagements are appropriately scoped; interview application teams and review architecture to agree scope with all stakeholders.
  • Define per-engagement prerequisites, assumptions, constraints and dependencies.
  • Identify prerequisites and blockers to punctual delivery and drive their resolution.
  • Provide technical oversight during the execution phase.
  • Interface with and manage third-party vendors who deliver security testing engagements.

Technical Governance & Quality Assurance

  • Act as the technical authority and SME for penetration testing engagements.
  • Review testing methodologies, coverage and attack paths to ensure effectiveness.
  • Review penetration testing reports produced by team members and third parties -eliminate false positives and ensure accurate, appropriately rated findings.
  • Peer review retest evidence and validate remediation outcomes.

Vulnerability Reporting & Remediation

  • Conduct overview/debrief sessions before and after engagements to ensure clarity and understanding.
  • Ensure reporting of security testing activities is tailored to the intended audience.
  • Engage with technical and business stakeholders to convey testing outcomes clearly.
  • Support technical teams to understand findings and cyber security concepts.
  • Advise remediation efforts, compensating controls and risk mitigation solutions; support risk acceptance/exception processes where required.

Practice Improvement & Evangelism

  • Drive initiatives to improve internal penetration testing practices with new ideas or processes and contribute to the development of internal security testing tools.
  • Compile and maintain runbooks, checklists, methodologies and frameworks to improve coverage and scale.
  • Advocate the benefits of the various cyber security service offerings and refer stakeholders to the appropriate internal teams where gaps are identified.

Reporting & Metrics

  • Contribute to relevant KPIs, KRIs and other metrics, and to the team's operating model improvement.
  • Stay current with security trends, testing tools, exploit techniques and industry news.

Competencies

  • Technical: Apply deep penetration testing knowledge to scope, review, challenge and assure testing approaches, methodologies, coverage and findings across applications, infrastructure and cloud.
  • Risk Management: Accurately risk-rate findings, validate remediation, and advise on compensating controls and risk acceptance in line with organisational standards.
  • Leadership: Direct engagement delivery and quality across internal and vendor-delivered testing; coach testers and share subject matter expertise.
  • Analytical: Apply structured thinking and evidence to assess testing outcomes, challenge assumptions and drive continuous improvement in coverage and practice.
  • Communication: Translate technical findings into clear, audience-appropriate reporting for technical teams and business stakeholders, and align teams around engagement outcomes.

Required Skills & Experience

  • Strong working knowledge of penetration testing across Web Applications, APIs, Thick Client and infrastructure - enough to scope, review and challenge testing approaches and results.
  • Solid grasp of application security, network protocols, operating systems and cloud/containerised environments (AWS, Azure, GCP, Docker, Kubernetes) to judge testing coverage and accurately risk-rate findings.
  • Familiarity with industry tooling (e.g. Burp Suite) and testing standards (OWASP, PTES) to benchmark internal and vendor-delivered engagements.
  • Proven record of driving and overseeing security engagements - scoping complex work, agreeing Rules of Engagement, and managing and quality-assuring third-party testing vendors.
  • Ability to review penetration testing reports, eliminate false positives, and ensure findings are accurate and appropriately prioritised.
  • Ability to identify, assess and communicate technical and project risks, and translate findings into clear reporting for technical and business stakeholders.
  • Ability to align testing outcomes with agreed objectives and timelines and advise on remediation and risk acceptance.
  • Plus: experience in large, regulated enterprise environments (financial services an advantage); Threat Modelling; relevant certifications (OSCP, GPEN, GWAPT, CREST).

We're proud to have been recognised as a Great Place to Work in India 25

Career Stage:

Senior Associate

London Stock Exchange Group (LSEG) Information:

Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.

LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.

Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.

Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.

We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyones race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.

You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.

LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.

Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what its used for, and how its obtained, your rights and how to contact us as a data subject.

If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.

Location: IND-BLR-Divyasree Technopolis, Bucharest - Iuliu Maniu Boulevard

Time Type: Full time