System Security Engineer, AVP
Top focus
Who we are looking for The State Street Cyber Architecture & Engineering team is looking for a System Security Engineer . The Security Architecture & Governance Engineering team delivers architectural solutions, platforms, pipelines, and security tooling to secure State Street’s digital footprint.
We are looking for engineers who have experience with secure configuration management practices and system hardening standards. The candidate will also have experience with development in one or more scripting languages and have experience with systems integrity assurance.
The ideal candidate will show eagerness to learn and grow in all aspects of technical solutioning and will design, implement, and support agile solutions and processes leveraged by a large number of applications and infrastructure platforms hosted in our environments.
Why This Role Is Important to Us As our technology estate continues to grow across cloud, on-premises, and hybrid environments, maintaining secure, consistent, and compliant system configurations is essential to protecting critical business services.
Misconfigurations remain one of the leading causes of security incidents, making proactive configuration management and system hardening a foundational component of our cybersecurity strategy. The Systems Security Engineer plays a critical role in establishing and enforcing secure configuration baselines across servers, operating systems, cloud workloads, and platform services.
By leveraging infrastructure automation, scripting, and compliance-as-code tools such as InSpec, the engineer helps transform security requirements into scalable, repeatable, and measurable controls. This role partners closely with infrastructure, cloud, platform, and engineering teams to embed security into operational processes, reduce manual effort, improve audit readiness, and strengthen the organization's overall security posture.
What You Will Be Responsible For Ensure Security Configuration best practices are implemented and adhered to. Establish Secure Baseline configurations for all State Street ITAM assets. Deliver tasks based on project objectives; technically support projects through to completion.
Ensure deliverables are completed within target timeframes and are consistently of high-quality, documented and support transition of operational activities. Develop custom solutions using technologies like Chef Inspec, shell scripting, etc, for hardening and monitoring non-standard systems.
Conduct risk assessments based on the NIST framework for critical assets. Develop security guidelines, policies and procedures pertaining to the Secure Configuration framework. You will work collaboratively with other engineers and promote software and platform configuration best practices across the organization by designing solutions with monitoring, auditing, reliability, and security at their core and be active in evaluating and recommending new technologies.
Work with our team, stakeholders, and teaming partners throughout the systems implementation lifecycle to understand the enterprise requirements and develop the holistic technical solution that is both unique and best positioned. What We Value Proven technical solutioning experience with current and emerging technologies including, but not limited to: Agile Development, DevOps, System Hardening, DevSecOps, Cybersecurity.
Excellent verbal and written communication skills across internal and external organizations. Ability to prioritize and manage several projects or priorities simultaneously. Strong interpersonal skills and the ability to interface with all levels of personnel (executive to entry level).
Education & Preferred Qualifications Bachelor’s degree in IT, computer science, or related field with 10+ years of relevant professional experience. Deep experience with cloud DevOps tooling and expertise in container native systems and associated security and scaling considerations – ability to work with and build tooling that works in a multi/hybrid cloud environment with modern CI/CD, IaC, DataOps, and DevSecOps best practices.
Experience working or developing Kubernetes autoscaling tools and deep experience with container and cloud security principles. Experience with Information Security: applying STIGs, IAVAs, CIS hardening guidelines and maintaining/updating security documentation and systems security plans.
Security+ or other cybersecurity or network security certification. Experience using common automation tools such as Ansible, Chef, or Terraform. Experience with one or more common programming languages such as Python, Perl, etc. Work Requirement Hybrid: Expected to work from base office location 4 days in a week Shift: Standard business hours with flexibility to support global stakeholders across multiple time zones About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability.
We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers Read our CEO Statement