SSH & Machine Identity Engineer

State Street

Berwyn (PA)

On-site

USD 120,000 - 203,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401K with company match
Life/Medical/Dental/Vision insurance
Paid time off (PTO)
Employee Assistance Program
Performance-based incentives
Tax-advantaged savings plans

Job summary

State Street is seeking a senior engineer to own the enterprise SSH governance, including the planned SSH Certificate Authority, key lifecycle management, and machine identity automation. You will lead design, drive onboarding of SSH use cases, and collaborate with infrastructure, cloud and security teams to strengthen controls across the organization.

You will connect SSH governance with broader cryptographic services strategy, develop automation, and support audit and risk inquiries, shaping

Qualifications

  • 7+ years of cybersecurity, infrastructure, Linux, identity, PKI or privileged access engineering experience.
  • Strong understanding of SSH, SSH keys, SSH certificates, Linux/Unix access patterns and privileged access controls.
  • Experience with certificate authorities, PKI concepts, machine identity management and secrets management platforms.
  • Experience automating identity, access or infrastructure workflows using scripts, APIs or orchestration tools.
  • Strong knowledge of enterprise risk, audit evidence, operational controls and security standards.
  • Strong ability to influence across multiple technology teams and drive adoption of new security capabilities.

Responsibilities

  • Lead engineering and implementation of the enterprise SSH Certificate Authority capability.
  • Define SSH certificate, SSH key lifecycle, trust and access patterns across the organization.
  • Drive SSH key discovery, ownership mapping, remediation and lifecycle governance.
  • Develop automation for SSH certificate issuance, rotation, revocation and reporting.
  • Partner with infrastructure, Linux, cloud, privileged access and application teams to onboard SSH use cases.
  • Align SSH capabilities with broader machine identity management, PKI and crypto operations strategies.
  • Support vaults/secrets management integration points where SSH credentials or keys require stronger control.
  • Define operational runbooks, monitoring requirements and escalation paths for SSH-related services.
  • Support audit, risk and regulatory inquiries related to SSH controls and machine identities.
  • Contribute to the long-term vision for centralized crypto operations support.

Skills

SSH concepts
SSH certificates
Linux/Unix access patterns
Privileged access controls
Automation scripting

Education

7+ years in cybersecurity/infra/Linux/identity/PKI or privileged access

Tools

HashiCorp Vault

Job description

Who We Are Looking For

This role will provide dedicated engineering ownership for enterprise SSH capabilities, including the planned SSH Certificate Authority, SSH key lifecycle management, machine identity governance and automation across the organization. We are looking for a senior engineer who can lead the design and adoption of SSH CA capabilities and establish stronger ownership, standards and automation for SSH across the enterprise. The role should connect SSH governance with the broader machine identity and cryptographic services strategy.

Who We Are Looking For

This role will provide dedicated engineering ownership for enterprise SSH capabilities, including the planned SSH Certificate Authority, SSH key lifecycle management, machine identity governance and automation across the organization. We are looking for a senior engineer who can lead the design and adoption of SSH CA capabilities and establish stronger ownership, standards and automation for SSH across the enterprise. The role should connect SSH governance with the broader machine identity and cryptographic services strategy.

What You Will Be Responsible For
  • Lead engineering and implementation of the enterprise SSH Certificate Authority capability.
  • Define SSH certificate, SSH key lifecycle, trust and access patterns across the organization.
  • Drive SSH key discovery, ownership mapping, remediation and lifecycle governance.
  • Develop automation for SSH certificate issuance, rotation, revocation and reporting.
  • Partner with infrastructure, Linux, cloud, privileged access and application teams to onboard SSH use cases.
  • Align SSH capabilities with broader machine identity management, PKI and crypto operations strategies.
  • Support vaults/secrets management integration points where SSH credentials or keys require stronger control.
  • Define operational runbooks, monitoring requirements and escalation paths for SSH-related services.
  • Support audit, risk and regulatory inquiries related to SSH controls and machine identities.
  • Contribute to the long-term vision for centralized crypto operations support.
What We Value
  • Strong ownership mindset with the ability to drive execution across multiple teams.
  • Practical focus on risk reduction, operational simplification, automation and measurable outcomes.
  • Ability to communicate clearly with technical teams, leadership, audit and risk stakeholders.
Education & Preferred Qualifications
  • 7+ years of cybersecurity, infrastructure, Linux, identity, PKI or privileged access engineering experience.
  • Strong understanding of SSH, SSH keys, SSH certificates, Linux/Unix access patterns and privileged access controls.
  • Experience with certificate authorities, PKI concepts, machine identity management and secrets management platforms.
  • Experience automating identity, access or infrastructure workflows using scripts, APIs or orchestration tools.
  • Strong knowledge of enterprise risk, audit evidence, operational controls and security standards.
  • Strong ability to influence across multiple technology teams and drive adoption of new security capabilities.
Salary Range

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes:

  • our retirement savings plan (401K) with company match;
  • insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages;
  • paid-time off including vacation, sick leave, short term disability, and family care responsibilities;
  • access to our Employee Assistance Program;
  • incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans);
  • eligibility for certain tax advantaged savings plans;

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SSH & Machine Identity Engineer
SSH & Machine Identity Engineer

State Street • Princeton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision
Paid time off
SSH & Machine Identity Engineer
SSH & Machine Identity Engineer

State Street • Austin (TX)

On-site
USD 120,000 - 203,000
401K with match
Medical/Dental/Vision
Paid time off
+1
SSH & Machine Identity Engineer
SSH & Machine Identity Engineer

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K plan
Insurance coverage
Paid time off
+3
SSH & Machine Identity Engineer
SSH & Machine Identity Engineer

State Street • Clifton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Insurance coverage (medical, life, etc
Paid time off
+2
Senior PKI Engineer
Senior PKI Engineer

State Street • Clifton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Insurance coverage including basiclife
Medical, dental, vision, long-term dis
+3
Senior PKI Engineer
Senior PKI Engineer

State Street • Devon (PA)

On-site
USD 120,000 - 203,000
401K with company match
Comprehensive insurance coverage
Paid time off including vacation and/​
Lead SSH & Machine Identity Engineer
Lead SSH & Machine Identity Engineer

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K plan
Insurance coverage
Paid time off
+3
Senior SSH & Machine Identity Architect
Senior SSH & Machine Identity Architect

State Street • Berwyn (PA)

On-site
USD 120,000 - 203,000
401K with company match
Life/Medical/Dental/Vision insurance
Paid time off (PTO)
+3
Senior SSH & Machine Identity Architect
Senior SSH & Machine Identity Architect

State Street • Princeton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Medical, dental, vision
Paid time off
Security Guardian -VP
Security Guardian -VP

State Street • Berwyn (PA)

On-site
USD 120,000 - 218,000
401K with company match
Life insurance
Medical, dental, vision
+3