Role at a glance
- Job function
-
Software Engineering & IT Cybersecurity
- Salary
- $125K – $215K/yr
- Location
- Quincy, Massachusetts, United States
- Work arrangement
- On-site
- Employment
- Full-time
- Education
- Bachelor's
Spotted an issue?
We’ll check it against the original posting.
About the role
Original posting provided by State Street
Who we are looking for
State Street seeks to recruit an External Attack Surface Management (EASM) / Persistent Perimeter Assurance Analyst for its Global Cybersecurity organization, operating within the Cyber Fusion Center. The Perimeter Assurance team will lead the persistent discovery, monitoring and reduction of State Street’s internet-facing attack surface, and will be an operational leader ensuring the smooth execution of the perimeter assurance mission.
This role involves alignment and the ability to foster cross-functional relationships, while partnering with teams (Cyber Defense Centre (CDC), Vulnerability Mgmt) on driving and leading the continuous assessment, triage and remediation of external exposures across the corporate networks, subsidiaries and affiliates.
Join us in evolving our defensive capabilities to protect State Street, its customers and partners from ever-evolving and sophisticated threat actors. State Street’s Cyber Fusion Center is responsible for detecting and responding to various cyber threats 24/7, 365.
This role will be fully on-site in one of State Street’s offices in Quincy, MA; Boston, MA; or Kilkenny, Ireland.
What will you be responsible for
Owning the persistent External Attack Surface Management (EASM) capability – maintaining a live inventory of internet-facing assets, domains, certificates, cloud exposure and shadow IT across the State Street corporate estate, subsidiaries and affiliates.
Operating continuous EASM/external scanning across the perimeter, and partner on the structured triage of critical and high findings through to remediation and closure.
Maintaining and creating documentation regarding perimeter assurance and exposure-management processes to ensure timely discovery, triage, validation, remediation and evidence of closure.
Assist with the coordinated disclosure and bug bounty programme, acting as the operational bridge between external researchers and internal remediation owners.
Representing and articulating the perimeter assurance position and interests in meetings and presentations, including but not limited to partners, metrics, audits and leadership – including monthly service reviews with evidence of SLA review and challenge.
Leading the evaluation and lifecycle management of EASM and perimeter-scanning tooling, including build-vs-buy assessment of new and not-yet-purchased capabilities against a weighted scorecard.
Support building a high performance culture and continuously enhancing the perimeter assurance and exposure-management process.
Training and mentoring Cyber Fusion Center personnel and creating an environment which drives knowledge sharing with teams across the Fusion Center globally.
What we value
These skills will help you succeed in this role:
Experience working in cyber security SOC / IT operations function.
Hands-on experience operating EASM and/or external vulnerability scanning platforms at enterprise scale.
Proven ability to triage, prioritize and drive remediation of critical and high-severity external vulnerabilities against defined SLAs.
Working knowledge of bug bounty / responsible disclosure operations and coordination with external researchers.
Ability to think critically, analyze data and synthesize it for decision making.
Exceptional written and verbal communication skills, including the ability to translate technical exposure into executive and board-level narrative.
Knowledge of adversarial tactics, techniques and procedures (TTPs) and industry standard frameworks (NIST, MITRE ATT&CK).
Knowledge of IT architecture and operations (computing, network, storage & cloud), and of edge / zero-trust concepts.
Strong working knowledge of security technologies including but not limited to SIEM, EDR/EPP, AV, ID/PS, HIPS, Web Proxy/Content filtering, AD, PKI and DNS.
Understanding of RACI-based governance, escalation design and control ownership within a regulated financial-services environment.
Education & Preferred Qualifications
Bachelor’s in Cyber Security, Information Technology, Computer Science or relevant experience / certifications.
Additional Requirements
CISSP, CISM, CIPM, OSCP, GCIH or applicable certification in the security field, is a plus.
Financial Services experience a plus.
Regulatory / audit experience a plus.
Are you the right candidate? Yes!
We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don’t necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.
Salary Range:
$125,000 - $215,000 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
About the company
State Street
Large Enterprise
State Street is a leading financial services and bank holding company, headquartered in Boston, Massachusetts. With a strong focus on investment management and servicing solutions, State Street supports institutional investors worldwide by providing services such as asset management, investment research, and trading. Renowned for its commitment to innovation and sustainability, State Street leverages advanced technology and data analytics to enhance investment strategies and customer experiences. The company prioritizes diversity and inclusion within its workforce, reflecting its dedication to fostering a dynamic and collaborative environment.