EASM / Persistent Perimeter Assurance Analyst, Vice President

State Street

Quincy (MA)

On-site

USD 125,000 - 215,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

State Street seeks an External Attack Surface Management (EASM) / Persistent Perimeter Assurance Analyst within the Global Cybersecurity organization, located on-site in Quincy, MA (or Boston, MA).

The role drives persistent discovery, monitoring and reduction of the internet-facing attack surface while partnering with CDC and Vulnerability Mgmt teams to triage and remediate external exposures across corporate networks and subsidiaries.

Qualifications

  • Bachelor's in Cyber Security, IT, CS or equivalent field.
  • CISSP, CISM, CIPM, OSCP, GCIH or applicable certification is a plus.
  • Financial Services experience or regulatory/audit experience is a plus.
  • Experience with EASM or external vulnerability scanning at enterprise scale is preferred.
  • Strong analytical and communication skills; ability to translate exposure into executive narratives.

Responsibilities

  • Own the persistent External Attack Surface Management (EASM) capability across corporate assets, including live inventory, domains, certificates, cloud exposure and shadow IT.
  • Operate continuous EASM/external scanning and triage findings through remediation.
  • Develop and maintain perimeter assurance documentation and evidence of closure.
  • Assist with coordinated disclosure and bug bounty programs, acting as the bridge between researchers and remediation owners.
  • Present perimeter assurance status in meetings and monthly reviews with SLA evidence.
  • Lead evaluation of EASM tooling and build-vs-buy decisions against a weighted scorecard.
  • Support a high-performance culture and knowledge sharing across the Cyber Fusion Center.

Skills

EASM experience
Vulnerability triage
Cross-functional collaboration
Bug bounty coordination
Threat analysis
Executive communication
IT security frameworks

Education

Bachelor's in Cyber Security, Information Technology, Computer Science or relevant field

Tools

SIEM
EDR/EPP
DNS/PKI/AD
Web Proxy/Content filtering

Job description

Who We Are Looking For

State Street seeks to recruit an External Attack Surface Management (EASM) / Persistent Perimeter Assurance Analyst for its Global Cybersecurity organization, operating within the Cyber Fusion Center. The Perimeter Assurance team will lead the persistent discovery, monitoring and reduction of State Street's internet-facing attack surface, and will be an operational leader ensuring the smooth execution of the perimeter assurance mission.

Who We Are Looking For

State Street seeks to recruit an External Attack Surface Management (EASM) / Persistent Perimeter Assurance Analyst for its Global Cybersecurity organization, operating within the Cyber Fusion Center. The Perimeter Assurance team will lead the persistent discovery, monitoring and reduction of State Street's internet-facing attack surface, and will be an operational leader ensuring the smooth execution of the perimeter assurance mission.

This role involves alignment and the ability to foster cross-functional relationships, while partnering with teams (Cyber Defense Centre (CDC), Vulnerability Mgmt) on driving and leading the continuous assessment, triage and remediation of external exposures across the corporate networks, subsidiaries and affiliates.

Join us in evolving our defensive capabilities to protect State Street, its customers and partners from ever-evolving and sophisticated threat actors. State Street's Cyber Fusion Center is responsible for detecting and responding to various cyber threats 24/7, 365.

This role will be fully on-site in one of State Street's offices in Quincy, MA; Boston, MA; or Kilkenny, Ireland.

What Will You Be Responsible For
  • Owning the persistent External Attack Surface Management (EASM) capability – maintaining a live inventory of internet-facing assets, domains, certificates, cloud exposure and shadow IT across the State Street corporate estate, subsidiaries and affiliates.
  • Operating continuous EASM/external scanning across the perimeter, and partner on the structured triage of critical and high findings through to remediation and closure.
  • Maintaining and creating documentation regarding perimeter assurance and exposure-management processes to ensure timely discovery, triage, validation, remediation and evidence of closure.
  • Assist with the coordinated disclosure and bug bounty programme, acting as the operational bridge between external researchers and internal remediation owners.
  • Representing and articulating the perimeter assurance position and interests in meetings and presentations, including but not limited to partners, metrics, audits and leadership – including monthly service reviews with evidence of SLA review and challenge.
  • Leading the evaluation and lifecycle management of EASM and perimeter-scanning tooling, including build-vs-buy assessment of new and not-yet-purchased capabilities against a weighted scorecard.
  • Support building a high performance culture and continuously enhancing the perimeter assurance and exposure-management process.
  • Training and mentoring Cyber Fusion Center personnel and creating an environment which drives knowledge sharing with teams across the Fusion Center globally.
What We Value
  • Experience working in cyber security SOC / IT operations function.
  • Hands-on experience operating EASM and/or external vulnerability scanning platforms at enterprise scale.
  • Proven ability to triage, prioritize and drive remediation of critical and high-severity external vulnerabilities against defined SLAs.
  • Working knowledge of bug bounty / responsible disclosure operations and coordination with external researchers.
  • Ability to think critically, analyze data and synthesize it for decision making.
  • Exceptional written and verbal communication skills, including the ability to translate technical exposure into executive and board-level narrative.
  • Knowledge of adversarial tactics, techniques and procedures (TTPs) and industry standard frameworks (NIST, MITRE ATT&CK).
  • Knowledge of IT architecture and operations (computing, network, storage & cloud), and of edge / zero-trust concepts.
  • Strong working knowledge of security technologies including but not limited to SIEM, EDR/EPP, AV, ID/PS, HIPS, Web Proxy/Content filtering, AD, PKI and DNS.
  • Understanding of RACI-based governance, escalation design and control ownership within a regulated financial-services environment.
Education & Preferred Qualifications
  • Bachelor's in Cyber Security, Information Technology, Computer Science or relevant experience / certifications.
Additional Requirements
  • CISSP, CISM, CIPM, OSCP, GCIH or applicable certification in the security field, is a plus.
  • Financial Services experience a plus.
  • Regulatory / audit experience a plus.
Are you the right candidate? Yes!

We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don't necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.

Salary Range

$125,000 - $215,000 Annual The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Job ID: R-797778

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Cyber & Information Security Oversight (SVP)
Head of Cyber & Information Security Oversight (SVP)

State Street • New York (NY)

On-site
USD 225,000 - 338,000
Managing Director, Cyber Risk & Third-Party Risk Management
Managing Director, Cyber Risk & Third-Party Risk Management

State Street • Quincy (MA)

On-site
USD 170,000 - 283,000
401K match
Comprehensive benefits package
Paid time off
Secure Configuration Systems Engineer
Secure Configuration Systems Engineer

State Street • Austin (TX)

On-site
USD 90,000 - 158,000
Secure Configuration Systems Engineer
Secure Configuration Systems Engineer

State Street • Atlanta (GA)

On-site
USD 90,000 - 158,000
Application Security Engineer - ADR
Application Security Engineer - ADR

State Street • Austin (TX)

On-site
USD 120,000 - 203,000
Application Security Engineer - ADR
Application Security Engineer - ADR

State Street • Atlanta (GA)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision coverage
Paid time off
Cybersecurity, AVP - Technical Delivery Manager
Cybersecurity, AVP - Technical Delivery Manager

State Street • Quincy (MA)

Hybrid
USD 90,000 - 158,000
401K with company match
Medical insurance
Dental insurance
+2
Head of Cyber & Information Security Oversight (SVP)
Head of Cyber & Information Security Oversight (SVP)

State Street • Boston (MA)

On-site
USD 225,000 - 338,000
401(k) match
Medical/dental/vision coverage
Paid time off & volunteer days
+1
Business Information Security Officer-AVP
Business Information Security Officer-AVP

State Street • Quincy (MA)

On-site
USD 90,000 - 158,000
401(k) with company match
Health insurance
Paid time off
+2
Senior Platform Operations Engineer
Senior Platform Operations Engineer

State Street • Austin (TX)

On-site
USD 120,000 - 203,000