State Street

Financial Services

AdvancedDefensive-ApplicationsSecurityEngineer

$120–203k Boston, Massachusetts, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Advanced Defensive -Applications Security Engineer at State Street. Skills: Application Security Engineering, Secure Development Lifecycle, Cybersecurity Architecture, Risk Assessment. Interpret architecture diagrams. Enhance security of systems”

What You'll Achieve.

Reduce vulnerabilities; Prevent effective attacks

Industry & Context.

Financial Services
Problems you'll solve

Determine impacts if vulnerabilities exploited; Determine application teams' lifecycle support requirements

What They're Looking For.

Must Have

Minimum of 5 years of experience in full-stack application development across the entire application life cycle, Experience designing and deploying payment systems, classified systems, or other critical environments, Experience in embedding technical security policies, principles, and standards within applications and network segments, Experience developing automated testing to ensure systems are functioning properly or are secure, Experience advising development teams on various issues, Experience presenting to and advising executives, Knowledge of secure software development, deployment, and maintenance, Knowledge of agentic AI systems, and their use in system and application development, Knowledge of computer network protocols, Knowledge of system design tools and techniques, Knowledge of server administration and principles and practices, Knowledge of database systems, Knowledge of Identity Access Management principles including application and API authentication, OAuth2. 0, and JWT tokens, Knowledge of encryption algorithms (e. g. , RC4, AES, PQC), Knowledge of key management, Knowledge of secure system architecture principles and designs, Knowledge of secure software engineering principles and practices, Knowledge of enterprise information technology (IT) architecture principles, practices and reference models, Knowledge of systems engineering processes, principles and practices, Knowledge of cyber security threat actors TTPs, tradecraft, and noteworthy attacks, Knowledge of cybersecurity principles and practices, including defense in depth, Awareness of compliance, including aligning detection strategy with global financial regulations, ISO 27001, EU GDPR, PCI-DSS, EU DORA, SOX, NIST CSF, US OCC Part 30 Safety and Soundness Standards, and financial compliance frameworks, Knowledge of application and network segment security reviews and threat modeling, including code reviews and dynamic testing, Knowledge of managing and performing application security vulnerability management, Knowledge of implementing security controls into cloud environments, Knowledge of human error probabilities (HEPs) and performance shaping factors

Nice to Have

Postgraduate degree in computer science, information security, engineering, data science, mathematics, or another relevant field, Experience working with information security teams such as fusion centers, security operations centers, vulnerability assessment, vulnerability threat management, security incident management, cyber “hunt, ” and big data analysis, Experience working with law enforcement agencies and external audit organizations for investigations, audits, and similar activities, Self-starter, self-motivated, and able to work independently with little oversight while managing a large, globally distributed team, Highly polished presentation skills, with the ability to simply and convincingly present technical issues to non-technical audiences, Able to develop and operate within a set financial budget

What You'll Do.

Interpret architecture diagrams

Enhance security of systems

Develop cybersecurity designs

Determine vulnerability impacts

Determine lifecycle support requirements

Implement cybersecurity policies

Implement automated measures

Develop cybersecurity risk profiles

Create system prototypes

Determine hardware/software adequacy

Design backup and failover capabilities

Create system testing procedures

Develop system security design documents

Develop system recovery plans

How You'll Work.

Team & Collaboration

Work collaboratively across the team; Advise development teams; Present to executives

Communication Scope

Present technical issues to non-technical audiences

Full Job Description

**Who we are looking for** The **Advanced Defensive – Application Security Engineers** is a member of a small team tasked with securing the firm's most critical network environments and applications. The Advance Defensive – Application Security Engineer is responsible for secure design, development, and testing of systems and the evaluation of system security throughout the system’s development life cycle. You must be ready to work collaboratively across the team, learning new skills and forging new procedures, relationships, and methods. Remote work options will be considered for highly skilled candidates. **What you will be responsible for** * Interpret architecture diagrams and controls to enhance the security of new and existing systems. * Develop application and system cybersecurity designs to meet specific operational needs and environmental factors (e.g., access controls, automated applications, networked operations, high integrity and availability requirements, multilevel security/processing of multiple classification levels, and processing Sensitive Compartmented Information). * Determine the impacts if vulnerabilities or exploited or a system is compromised. * Determine the application teams’ lifecycle support requirements. * Implement application cybersecurity policies using policy as code, automation, and documented and verified manual procedures. * Implement automated measures to determine the effectiveness of system cybersecurity measures. * Develop cybersecurity risk profiles for systems. * Work with developers to create system prototypes using UAT and prototype models. * Determine if hardware, operating systems, and software adequately addresses a system’s cybersecurity requirements. * Design and ensure implementation of system backup and failover capabilities. * Create system testing and validation procedures and documentation. * Develop system security design documents. * Develop system recovery and continuity plans. * Test recovery and continuity

Free ATS check

Applying for this Advanced Defensive -Applications Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about State Street?

Real rants from real employees. Read before you apply.

Read Company Rants →