Security Engineer

State Street
United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$90,000.0 - $157,500.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management Network Security Red Team (Cyber Security) Software Vulnerability Management Scripting Software Security Information Technology

Job description

The Security Engineer will support authorized cybersecurity testing and assessment activities designed to evaluate security controls, identify weaknesses, and support the continuous improvement of cybersecurity capabilities. The role will work with stakeholders across the organization to perform assessments, document results, and support remediation efforts in accordance with approved policies and procedures.

The Security Engineer will participate in a variety of offensive security engagements designed to evaluate security controls, identify weaknesses, and assess organizational resilience. The engineer will work closely with stakeholders across the organization to conduct assessments, communicate results, and support continuous improvement of cybersecurity capabilities.

This role is intended for a developing to intermediate offensive security professional who can execute assigned testing activities, communicate findings effectively, and continue building expertise across multiple security domains.

What You Will Be Responsible For Support authorized offensive security assessments and testing activities across a variety of technology environments. Perform hands-on testing across applications, infrastructure, identity, cloud, endpoint, and network environments under approved scope and supervision. Execute authorized testing activities designed to evaluate security controls and organizational resilience. Use security assessment tools and methodologies in accordance with approved testing procedures. Ability to collaborate effectively with Red Team peers, defensive security teams, technology stakeholders, and risk partners. Prepare technical reports, assessment documentation, executive summaries, and remediation recommendations for stakeholders. Collaborate with stakeholders to support risk reduction and continuous improvement initiatives. Identify security control gaps and help translate technical observations into practical remediation recommendations. Participate in peer review, report quality improvement, and continuous improvement of Red Team procedures, templates, and documentation. Maintain awareness of emerging threats, vulnerabilities, offensive techniques, and defensive control patterns relevant to enterprise environments. Communicate clearly with technical and non-technical stakeholders while handling sensitive information responsibly.

Requirements

Hands-on curiosity and a strong desire to grow as an offensive security practitioner. Working knowledge of penetration testing, adversary emulation, and security assessment methodologies. Familiarity with common security domains including identity and access management, endpoint security, network security, cloud security, application security, and vulnerability management. Ability to follow defined procedures, operate safely, and escalate questions or concerns when scope, authorization, or risk is unclear. Strong analytical skills and the ability to connect technical findings to business and security risk. Clear written communication, including the ability to document testing steps, evidence, findings, and remediation guidance. Ability to collaborate effectively with Red Team peers, defensive security teams, technology stakeholders, and risk partners. Commitment to professional conduct, discretion, and careful handling of confidential or sensitive information. Willingness to contribute to team process improvements, documentation, tooling, and repeatable operating practices., Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent hands-on security experience. 1-2 years of experience in penetration testing, security assessments, offensive security, or related cybersecurity activities. Working knowledge of networks, operating systems, cloud technologies, and common security controls. Familiarity with penetration testing methodologies, threat-informed testing, or adversary simulation concepts. Ability to script or automate tasks using common scripting languages. Strong written and verbal communication skills. Relevant cybersecurity certifications are preferred but not required.

Benefits & conditions

$90,000 - $157,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans., We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

About the company

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all