Penetration Testing Engineer- VP

STATE STREET CORPORATION

Austin (TX)

Hybrid

USD 120,000 - 203,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401K with company match
Insurance coverage: life/medical/dent/

Job summary

State Street Corporation is seeking a Senior Penetration Testing Engineer to join a top-tier Penetration Testing Team within Threat Intelligence and Assurance. The role is highly technical, hands-on, and focuses on applying rigorous testing approaches across complex systems in a regulated banking environment.

You will design, lead, and execute internal and third‑party testing for web, API, and network domains, while driving improvement in secure design and implementation.

Qualifications

  • 5+ years in penetration testing in high-security environments.
  • Experience managing third‑party penetration testing vendors.
  • Deep expertise in application testing (web, APIs, mobile) and enterprise network paths.
  • Knowledge of modern architectures (cloud-native, microservices, CI/CD).
  • Ability to translate findings into risk-based remediation guidance.
  • Nice to have: experience using AI/LLM tools for testing.

Responsibilities

  • Design and manage third‑party network penetration tests with scoping and QA.
  • Lead end‑to‑end application penetration testing (web, API) with retesting.
  • Perform advanced testing across authn/authz, injection, API abuse, and crypto misuse.
  • Establish and enforce testing standards for internal and external teams.
  • Deliver regulator‑ready reports with remediation guidance.
  • Lead AI/LLM‑enabled testing and assess enterprise AI deployments.
  • Partner with engineering to validate remediation and reduce recurrence.

Skills

Penetration testing
Application testing
Network testing
Vendor management
Cloud-native architectures

Education

BS/MS degree
Security certifications

Tools

AI/LLM tools

Job description

Who We Are Looking For

We are seeking a Senior Penetration Testing Engineer to join State Street’s Penetration Testing Team, reporting to the Penetration Testing Team Manager. This role sits within the Threat Intelligence and Assurance organization and is a deeply technical engineering position with strong hands‑on expectations. You will serve as a subject matter expert in application penetration testing, executing detailed assessments and contributing to the design and oversight of network penetration testing performed in partnership with third‑party providers. The focus of this role is on building and applying rigorous, repeatable testing approaches that evaluate security control effectiveness and real‑world exploitability across complex systems. Operating in a highly regulated banking environment, you will ensure testing outputs are technically sound, evidence‑based, and aligned to risk and audit expectations. You will work closely with engineering and infrastructure teams to analyze root causes, validate fixes, and drive improvements in secure system design and implementation.

What you will be responsible for
  • Design and manage third‑party network penetration tests, including scoping, vendor selection, rules of engagement, quality assurance, and validation of results.
  • Lead end‑to‑end application penetration testing across internal and third‑party providers (web, API), including scoping, execution, exploitation, and retesting.
  • Perform advanced testing across authn/authz, business logic, injection, API abuse, crypto misuse, and access control weaknesses.
  • Establish and enforce testing standards for both internal teams and external vendors to ensure consistency, depth, and regulatory defensibility.
  • Deliver high‑quality, regulator‑ready reporting with clear exploitability, risk context, and actionable remediation guidance.
  • Lead the use of AI/LLM‑enabled testing techniques and conduct assurance testing of enterprise AI/LLM deployments (e.g., prompt injection, model abuse, data exposure risks).
  • Partner with engineering and infrastructure teams to validate remediation, reduce recurrence, and strengthen secure development and deployment practices.
What we value
  • Technical depth with ownership, balancing hands‑on expertise with accountability for end‑to‑end outcomes across internal and external testing.
  • Strong judgment and vendor oversight, ensuring third‑party testing meets enterprise standards and delivers meaningful assurance.
  • Practical, risk‑focused mindset, prioritizing real‑world exploitability and business impact.
  • Clear, concise communication, producing executive‑ready outputs and actionable technical guidance.
  • Collaboration and partnership, working closely with engineering, infrastructure, and risk stakeholders.
  • Innovation and adaptability, particularly in applying AI/LLM techniques to offensive security challenges.
  • Continuous improvement, enhancing methodologies, playbooks, and testing consistency across internal and third‑party efforts.
Education & Preferred Qualifications
  • 5+ years in penetration testing with strong experience across both application and network testing in high‑security/highly regulated environments.
  • Experience managing third‑party penetration testing vendors, including quality validation and outcome assurance.
  • Deep expertise in application penetration testing (web, APIs, mobile) and solid understanding of enterprise network attack paths.
  • Strong knowledge of modern architectures (cloud‑native, microservices, identity platforms, CI/CD pipelines).
  • Ability to translate technical findings into actionable, risk‑based remediation guidance and influence stakeholders.
  • Nice to have: experience using AI/LLM tools to perform network and application penetration testing and configuration/security reviews.
  • Education/Certifications (desired, not mandatory): BS/MS in relevant field; OSCP/OSEP/OSWE, GPEN/GXPN, GWAPT, PNPT, GCPN, or similar.
Additional requirements

Hybrid Schedule based on location

Salary Range: $120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Benefits
  • our retirement savings plan (401K) with company match
  • insurance coverage including basic life, medical, dental, vision, long‑term disability, and other optional additional coverages
  • paid‑time off including vacation, sick leave, short‑term disability, and family care responsibilities
  • access to our Employee Assistance Program
  • incentive compensation including eligibility for annual performance‑based awards (excluding certain sales roles subject to sales incentive plans)
  • eligibility for certain tax‑advantaged savings plans

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work‑life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Job Application Disclosure: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Testing Engineer- VP
Penetration Testing Engineer- VP

STATE STREET CORPORATION • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Insurance coverage: medical, dental, 6
Paid time off including vacation, sick
+3
Senior Application Security Architect
Senior Application Security Architect

STATE STREET CORPORATION • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K with company match
Medical, dental, vision insurance
Paid time off
EASM / Persistent Perimeter Assurance Analyst, Vice President
EASM / Persistent Perimeter Assurance Analyst, Vice President

STATE STREET CORPORATION • Quincy (MA)

On-site
USD 125,000 - 215,000
401K with company match
Insurance coverage: medical, dental, 1
Paid time off and volunteer days
+2
Vice President, Senior Security Testing Delivery Lead
Vice President, Senior Security Testing Delivery Lead

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K with company match
Health insurance
Paid time off
+1
Vice President, Senior Security Testing Delivery Lead
Vice President, Senior Security Testing Delivery Lead

STATE STREET CORPORATION • Quincy (MA)

On-site
USD 120,000 - 203,000
Vice President – Application Development & Architecture (Integration Services) - VP
Vice President – Application Development & Architecture (Integration Services) - VP

State Street • Quincy (MA)

On-site
USD 122,000 - 203,000
Vice President, Senior Security Testing Delivery Lead
Vice President, Senior Security Testing Delivery Lead

State Street • Princeton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Insurance coverage: life, medical, and
Dental, vision, long-term disability
+4
Application Security Engineer
Application Security Engineer

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision benefits
Paid time off
Application Security Engineer
Application Security Engineer

State Street • Clifton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Medical/dental/vision insurance
Paid time off
Application Security Engineer - ADR
Application Security Engineer - ADR

State Street • Atlanta (GA)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision coverage
Paid time off