State Street

Financial Services

SecurityContentEngineer

$120–218k Quincy, Massachusetts, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Security Content Engineer at State Street. Skills: Security Content Engineering, Threat Detection, SIEM, EDR, Cybersecurity. Develop and implement new detection content for both cloud-based and on-prem systems while ensuring a high level of fidelity.. Determine the best method for achieving detection content objectives to ensure efficiency and avoid duplication.”

What You'll Achieve.

Create, test, enhance, and document threat detection capabilities to determine the presence of certain cyber activity.; Evolve our threat management capabilities to shape a pro-active intelligence driven fusion model to protect State Street, its customers and partners from the ever evolving and sophisticated global threat actors.; Ensure a high level of fidelity in detection content.; Ensure efficiency and avoid duplication in detection content.; Increase efficiency, fidelity, and/or possible retirement of content.

Industry & Context.

Financial Services
Problems you'll solve

Determine the best method for achieving detection content objectives to ensure efficiency and avoid duplication.; Triage, prioritize, and take appropriate action to address requests for detection content corrections and/or enhancements.; Identify opportunities to increase efficiency, fidelity, and/or possible retirement.

What They're Looking For.

Must Have

6+ years in a cyber security skill role – SIEM/EDR Content Engineer, Incident Response, SOC Tier 3 Analyst, Threat Hunter, Penetration testing, etc.

Nice to Have

Financial Services experience a plus, Software development and/or scripting experience a plus: RegEx, PERL, Python, Powershell, etc., Technical security certifications a plus – GMON, GCDA, GCIH, etc.

What You'll Do.

Develop and implement new detection content for both cloud-based and on-prem systems while ensuring a high level of fidelity.

Determine the best method for achieving detection content objectives to ensure efficiency and avoid duplication.

and take appropriate action to address requests for detection content corrections and/or enhancements.

Test and tune threat detection use cases within the Security Incident and Event Management (SIEM)

Endpoint Detection and Response (EDR) and/or other security platforms.

Monitor and maintain SIEM look up tables and various other tables from becoming stale and dated.

Monitor established content metrics

identify opportunities to increase efficiency

and/or possible retirement.

Validate and document content requirements

and other development lifecycle aspects through use of appropriate documentation libraries and development tracking tools.

Document and maintain assets

scripts and processes to test SIEM/EDR rules for reuse.

Partner with other Fusion Center teams to align detection strategy with threat model and MITRE ATT&CK framework.

Partner with purple team

IT and business professionals to validate and document threat detection goals.

Provide guidance in alert creation among various security controls such as EDR

Collaborate with various teams to learn

and maintain a library of various IT processes

and other considerations that can be leveraged to improve security capabilities across the organization.

How You'll Work.

Team & Collaboration

Partner with other Fusion Center teams to align detection strategy with threat model and MITRE ATT&CK framework.; Partner with purple team, various security, risk, IT and business professionals to validate and document threat detection goals.; Collaborate with various teams to learn, document, and maintain a library of various IT processes, naming conventions, assets, configurations, and other considerations that can be leveraged to improve security capabilities across the organization.

Communication Scope

Articulate and thorough documentation

Process & Methodology

Agile development lifecycle and methodology, Articulate and thorough documentation and lifecycle

Full Job Description

Job Description **Who we are looking for** State Street seeks to recruit a Security Content Engineer that will create, test, enhance, and document threat detection capabilities to determine the presence of certain cyber activity. Join us in evolving our threat management capabilities to shape a pro-active intelligence driven fusion model to protect State Street, its customers and partners from the ever evolving and sophisticated global threat actors. Remote work options will be considered for the highly skilled candidates. **What you will be responsible for** As Security Content Engineer you will * Develop and implement new detection content for both cloud-based and on-prem systems while ensuring a high level of fidelity. * Determine the best method for achieving detection content objectives to ensure efficiency and avoid duplication. * Triage, prioritize, and take appropriate action to address requests for detection content corrections and/or ehancements. * Test and tune threat detection use cases within the Security Incident and Event Management (SIEM), Endpoint Detection and Response (EDR) and/or other security platforms. * Monitor and maintain SIEM look up tables and various other tables from becoming stale and dated. * Monitor established content metrics, identify opportunities to increase efficiency, fidelity, and/or possible retirement. * Validate and document content requirements, search criteria, test cases, and other development lifecycle aspects through use of appropriate documentation libraries and development tracking tools. * Document and maintain assets, scripts and processes to test SIEM/EDR rules for reuse. * Partner with other Fusion Center teams to align detection strategy with threat model and MITRE ATT&CK framework. * Partner with purple team, various security, risk, IT and business professionals to validate and document threat detection goals. * Provide guidance in alert creation among various security controls such as EDR, IDS, Cloud, email ga

Free ATS check

Applying for this Security Content Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about State Street?

Real rants from real employees. Read before you apply.

Read Company Rants →