Security Testing Delivery Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Senior Security Testing Delivery Lead to help drive the execution, coordination, and operational management of State Street’s regulatory security testing and assurance activities. This role is ideal for a strong technical program leader who can bring structure, discipline, and momentum to complex cybersecurity remediation and validation efforts. The analyst will work closely with testing teams, remediation owners, Lines of Defense, and program stakeholders to keep testing activities aligned, on track, and effectively governed across multiple concurrent workstreams.
This individual will serve as a key partner in managing the day-to-day operations of the team, ensuring progress is transparent, blockers are addressed quickly, and stakeholders remain aligned on priorities, testing outcomes, and remediation implications. The role requires someone who is highly organized, comfortable working through ambiguity, confident managing challenging stakeholders, and able to connect detailed execution activities to broader regulatory and program management objectives.
What you will be responsible for
As a Senior Security Testing Delivery Lead, you will:
- Support the end-to-end coordination of regulatory cybersecurity remediation testing activities, from planning through execution, reporting, and follow-up
- Drive day-to-day team execution by facilitating stand-ups, managing dependencies, removing blockers, and maintaining visibility into delivery progress across active workstreams
- Own and maintain Jira and Confluence spaces used to track testing progress, action items, stakeholder decisions, and key program artifacts
- Coordinate closely with remediation owners, Lines of Defense, and program management stakeholders to ensure testing activities remain aligned with broader remediation timelines and regulatory commitments
- Manage stakeholder engagement related to test plans, testing feedback, and validation reports, including navigating complex or challenging partner groups
- Prioritize and load balance testing demand across team resources to support efficient execution and timely delivery
- Coordinate overlap between regulatory retesting efforts and Network Penetration Testing findings, including managing handoffs and ensuring appropriate follow-up when tangential findings are identified
Requirements
- Strong project management and execution skills, with the ability to drive multiple complex workstreams simultaneously
- Ability to bring structure, discipline, and transparency to fast-moving cybersecurity and regulatory efforts
- Experience tracking delivery through tools such as Jira and Confluence, with strong attention to detail and follow-through on actions and dependencies
- Ability to identify risks, escalate issues appropriately, and proactively clear blockers to maintain momentum
- Strong organizational and prioritization skills, including the ability to load balance work and optimize team capacity across competing demands
- Comfortable managing challenging stakeholders and influencing teams across organizational boundaries to achieve timely outcomes
- Familiarity with cybersecurity testing or regulatory-driven security programs is preferred
- Financial services or other regulated industry experience is preferred but not required, * At least 4 years of experience in technical program management, cybersecurity program delivery, security testing coordination, or related operational roles
- Demonstrated experience managing complex cross-functional initiatives involving technical teams, risk stakeholders, and program governance partners
- Experience with Jira, Confluence, and other workflow or program tracking tools
- Experience supporting cybersecurity, technology risk, audit, or remediation programs is preferred
- Familiarity with penetration testing, threat-led penetration testing, or security assurance activities is preferred but not required
- Bachelor’s degree in information systems, cybersecurity, business, or a related field is preferred
- Relevant project management, risk, or cybersecurity certifications are a plus but not required
Benefits & conditions
$120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans., We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
About the company
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
How to create a test plan for software testing
What is a Test Plan: Guide to Test Planning