Staff Perimeter Security Defense Engineer

State Street
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $202,500.0
Working hours
Regular working hours
Job source

Tech stack

Access Network Application Programming Interfaces (APIs) Application Firewall Cloud Computing Cyber Security DDoS Mitigation Virtual Private Networks (VPN) Network Security Remote Access Technology Zero Trust Network Access Web Application Security Security Information and Event Management
+6 more
Systems Integration Information Technology Cybercrime Palo Alto Networks Cloudflare Cyber Warfare

Job description

  • Define and drive the enterprise perimeter security strategy, architecture, and roadmap.
  • Lead the evaluation, implementation, and continuous improvement of perimeter security controls and technologies.
  • Partner with Network Engineering, Infrastructure, Cloud, and Application teams to design and deploy secure network and internet-facing architectures.
  • Collaborate with the Cyber Defense Center (CDC) to enhance detection, investigation, threat hunting, and response capabilities for network and perimeter-based attacks.
  • Lead security initiatives involving next-generation firewalls, web application firewalls (WAF), DDoS protection, secure web gateways, remote access security, API protection, and Zero Trust technologies.
  • Drive integration of perimeter security platforms with SIEM, SOAR, threat intelligence, and security analytics solutions.
  • Develop security standards, architecture patterns, and implementation guidance for perimeter security technologies.
  • Lead proof-of-concepts, product evaluations, and vendor assessments for network and perimeter security solutions.
  • Track and report key metrics related to threat prevention, attack surface reduction, control effectiveness, and risk reduction.
  • Serve as a subject matter expert for perimeter security and defensive engineering initiatives.

Requirements

  • Experience with perimeter security technologies such as Zscaler, Palo Alto Networks, Cloudflare, F5, or similar platforms.
  • Strong understanding of network security, perimeter defense, segmentation, secure access, and Zero Trust architectures.
  • Experience securing internet-facing applications, APIs, and remote access services.
  • Familiarity with technologies such as WAF, DDoS protection, ZTNA, SSE, SASE, VPN, and network access controls.
  • Experience integrating security platforms with SIEM, SOAR, and threat intelligence solutions.
  • Strong analytical, troubleshooting, automation, and problem-solving skills.
  • Excellent communication and stakeholder management skills., * Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, network security, security engineering, or security architecture.
  • 5+ years of hands-on experience designing and implementing perimeter security technologies and controls.
  • Experience working in financial services or other regulated industries preferred.
  • Relevant certifications such as CISSP, CCSP, PCNSE, CCNP Security, or equivalent preferred.

Additional Requirements

  • Experience developing security strategies, roadmaps, and architecture standards.
  • Experience assessing emerging threats and translating risks into security controls and engineering priorities.
  • Familiarity with cloud and hybrid network security architectures.
  • Strong collaboration skills and ability to work across Cyber Security, Infrastructure, Cloud, and Engineering organizations.

Work Requirement

  • Hybrid work model in accordance with company policy.
  • Ability to collaborate effectively with global teams across multiple time zones.
  • Standard business hours with flexibility to support critical security incidents and initiatives when required.

Benefits & conditions

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans., We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

About the company

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:56 min

Configuring server-side rendering and Cloudflare deployment

Francesco Napoletano Francesco Napoletano · WWC 2024

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:21 min

Deploying serverless logic directly to Cloudflare Workers

Edoardo Dusi · LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all