All jobs

Security Engineer - Red Team

Statestreet20h ago
United StatesHybridFull-time

Top focus

Security EngineerCloud Security Engineer
  • Wo we are looking for The Security Engineer will support authorized cybersecurity testing and assessment activities designed to evaluate security controls, identify weaknesses
  • support the continuous improvement of cybersecurity capabilities. The role will work with stakeholders across the organization to perform assessments, document results
  • support remediation efforts in accordance with approved policies and procedures. The Security Engineer will participate in a variety of offensive security engagements designed to evaluate security controls, identify weaknesses
  • assess organizational resilience. The engineer will work closely with stakeholders across the organization to conduct assessments, communicate results
  • support continuous improvement of cybersecurity capabilities. This role is intended for a developing to intermediate offensive security professional who can execute assigned testing activities, communicate findings effectively
  • continue building expertise across multiple security domains. What You Will Be Responsible For
  • Support authorized offensive security assessments and testing activities across a variety of technology environments.
  • Perform hands-on testing across applications, infrastructure, identity, cloud, endpoint, and network environments under approved scope and supervision.
  • Execute authorized testing activities designed to evaluate security controls and organizational resilience.
  • Use security assessment tools and methodologies in accordance with approved testing procedures.
  • Ability to collaborate effectively with Red Team peers, defensive security teams, technology stakeholders, and risk partners.
  • Prepare technical reports, assessment documentation, executive summaries, and remediation recommendations for stakeholders.
  • Collaborate with stakeholders to support risk reduction and continuous improvement initiatives.
  • Identify security control gaps and help translate technical observations into practical remediation recommendations.
  • Participate in peer review, report quality improvement, and continuous improvement of Red Team procedures, templates, and documentation.
  • Maintain awareness of emerging threats, vulnerabilities, offensive techniques, and defensive control patterns relevant to enterprise environments.
  • Communicate clearly with technical and non-technical stakeholders while handling sensitive information responsibly. What We Value These skills will help you succeed in this role
  • Hands-on curiosity and a strong desire to grow as an offensive security practitioner.
  • Working knowledge of penetration testing, adversary emulation, and security assessment methodologies.
  • Familiarity with common security domains including identity and access management, endpoint security, network security, cloud security, application security, and vulnerability management.
  • Ability to follow defined procedures, operate safely, and escalate questions or concerns when scope, authorization, or risk is unclear.
  • Strong analytical skills and the ability to connect technical findings to business and security risk.
  • Clear written communication, including the ability to document testing steps, evidence, findings, and remediation guidance.
  • Ability to collaborate effectively with Red Team peers, defensive security teams, technology stakeholders, and risk partners.
  • Commitment to professional conduct, discretion, and careful handling of confidential or sensitive information.
  • Willingness to contribute to team process improvements, documentation, tooling, and repeatable operating practices. Education & Preferred Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent hands-on security experience.
  • 1-2 years of experience in penetration testing, security assessments, offensive security, or related cybersecurity activities.
  • Working knowledge of networks, operating systems, cloud technologies, and common security controls.
  • Familiarity with penetration testing methodologies, threat-informed testing, or adversary simulation concepts.
  • Ability to script or automate tasks using common scripting languages.
  • Strong written and verbal communication skills.
  • Relevant cybersecurity certifications are preferred but not required. Salary Range: $90,000 - $157,500 Annual The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ. Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match
  • insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
  • paid-time off including vacation, sick leave, short term disability, and family care responsibilities
  • access to our Employee Assistance Program
  • incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans)
  • and, eligibility for certain tax advantaged savings plans. For a full overview, visit https://hrportal.ehr.com/statestreet/Home . About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at StateStreet.com/careers Read our CEO Statement Job Application Disclosure: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Required skills

Security
Posted on JobRush — the end-to-end AI job-search platform.