- Location
- IND-BLR-Divyasree Technopolis, India · Bucharest - Iuliu Maniu Boulevard
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Source
- Workday
Description
Role Summary
LSEG is seeking a Senior Security Specialist to join our Cyber Security – Security Testing team as a penetration testing subject matter expert (SME). This engagement-focused, technical role plans, scopes and drives penetration tests across a wide range of systems and applications, providing technical oversight, assurance and consulting expertise throughout the engagement lifecycle assuring quality and delivering measurable risk reduction across applications, infrastructure, cloud and networks, while working closely with internal teams and third-party testing vendors.
Key Responsibilities
Security Testing Engagement Oversight
- Oversee penetration testing engagements throughout the lifecycle, ensuring comprehensive coverage and quality.
- Ensure engagements are appropriately scoped; interview application teams and review architecture to agree scope with all stakeholders.
- Define per-engagement prerequisites, assumptions, constraints and dependencies.
- Identify prerequisites and blockers to punctual delivery and drive their resolution.
- Provide technical oversight during the execution phase.
- Interface with and manage third-party vendors who deliver security testing engagements.
Technical Governance & Quality Assurance
- Act as the technical authority and SME for penetration testing engagements.
- Review testing methodologies, coverage and attack paths to ensure effectiveness.
- Review penetration testing reports produced by team members and third parties -eliminate false positives and ensure accurate, appropriately rated findings.
- Peer review retest evidence and validate remediation outcomes.
Vulnerability Reporting & Remediation
- Conduct overview/debrief sessions before and after engagements to ensure clarity and understanding.
- Ensure reporting of security testing activities is tailored to the intended audience.
- Engage with technical and business stakeholders to convey testing outcomes clearly.
- Support technical teams to understand findings and cyber security concepts.
- Advise remediation efforts, compensating controls and risk mitigation solutions; support risk acceptance/exception processes where required.
Practice Improvement & Evangelism
- Drive initiatives to improve internal penetration testing practices with new ideas or processes and contribute to the development of internal security testing tools.
- Compile and maintain runbooks, checklists, methodologies and frameworks to improve coverage and scale.
- Advocate the benefits of the various cyber security service offerings and refer stakeholders to the appropriate internal teams where gaps are identified.
Reporting & Metrics
- Contribute to relevant KPIs, KRIs and other metrics, and to the team's operating model improvement.
- Stay current with security trends, testing tools, exploit techniques and industry news.
Competencies
- Technical: Apply deep penetration testing knowledge to scope, review, challenge and assure testing approaches, methodologies, coverage and findings across applications, infrastructure and cloud.
- Risk Management: Accurately risk-rate findings, validate remediation, and advise on compensating controls and risk acceptance in line with organisational standards.
- Leadership: Direct engagement delivery and quality across internal and vendor-delivered testing; coach testers and share subject matter expertise.
- Analytical: Apply structured thinking and evidence to assess testing outcomes, challenge assumptions and drive continuous improvement in coverage and practice.
- Communication: Translate technical findings into clear, audience-appropriate reporting for technical teams and business stakeholders, and align teams around engagement outcomes.
Required Skills & Experience
- Strong working knowledge of penetration testing across Web Applications, APIs, Thick Client and infrastructure - enough to scope, review and challenge testing approaches and results.
- Solid grasp of application security, network protocols, operating systems and cloud/containerised environments (AWS, Azure, GCP, Docker, Kubernetes) to judge testing coverage and accurately risk-rate findings.
- Familiarity with industry tooling (e.g. Burp Suite) and testing standards (OWASP, PTES) to benchmark internal and vendor-delivered engagements.
- Proven record of driving and overseeing security engagements - scoping complex work, agreeing Rules of Engagement, and managing and quality-assuring third-party testing vendors.
- Ability to review penetration testing reports, eliminate false positives, and ensure findings are accurate and appropriately prioritised.
- Ability to identify, assess and communicate technical and project risks, and translate findings into clear reporting for technical and business stakeholders.
- Ability to align testing outcomes with agreed objectives and timelines and advise on remediation and risk acceptance.
- Plus: experience in large, regulated enterprise environments (financial services an advantage); Threat Modelling; relevant certifications (OSCP, GPEN, GWAPT, CREST).
We're proud to have been recognised as a Great Place to Work® in India ‘25
Career Stage:
Senior AssociateLondon Stock Exchange Group (LSEG) Information:
Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.
LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.
Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.
Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.
We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone’s race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.
You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.
LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.
Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it’s used for, and how it’s obtained, your rights and how to contact us as a data subject.
If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.