Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.
State Street • Quincy, Massachusetts, United States
Salary: $120,000 - $202,500 / year
Role & seniority: Senior Security Testing Analyst
Stack/tools: cybersecurity disciplines (security operations, incident response, detection engineering, threat intelligence, penetration testing); threat-led testing concepts; MITRE ATT&CK framework; cross-team coordination; technical project management
Plan, execute, and analyze regulatory and internal security testing activities
Evaluate testing outcomes with a threat mindset; translate results into actionable risk mitigations
Coordinate with internal/external testing teams and drive remediation planning and validation
4+ years in operational cybersecurity roles
Experience across security operations, incident response, detection engineering, threat intelligence, or penetration testing
Familiarity with threat-led testing concepts; knowledge of adversary tactics and MITRE ATT&CK
Strong technical project management and issue ownership; ability to work across organizational boundaries
Financial services or regulated industry experience
Advanced degree in information systems, data science, or related field
Relevant cybersecurity certifications
Threat-led penetration testing experience
Location & work type: Primary location indicated; exact location not specified. Likely hybrid/onsite depending on role; consult posting for specifics.
Who we are looking for We are seeking a Senior Security Testing Analyst to support and strengthen State Street’s intelligence‑led security testing and assurance activities. This role is ideal for a cybersecurity professional who brings a strong threat mindset, experience across security disciplines, and the ability to translate complex testing results into actionable insights. The analyst will work closely with internal and external testing teams, technology stakeholders, and business partners to ensure security testing outcomes meaningfully reduce risk, meet regulatory expectations, and drive informed decision‑making across the enterprise. What you will be responsible for As a Senior Security Testing Analyst you will Support the planning, execution, and analysis of regulatory and internal security testing activities Analyze unique testing requirements, design practical solutions, coordinate with stakeholders, and manage execution risks Evaluate testing outcomes with a strong “threat mindset,” applying knowledge of adversary behavior, security controls, and architectural considerations Develop insights and outputs that drive action by technology teams and business units Coordinate with internal and external security testing teams to support finding owners through analysis, remediation planning, and validation testing to confirm effective risk mitigation What we value These skills will help you succeed in this role A collaborative team player with foundational cybersecurity knowledge and the ability to work across organizational boundaries to deliver meaningful outcomes Prior experience in one or more cybersecurity disciplines, such as security operations, incident response, detection engineering, cyber threat intelligence, or penetration testing Familiarity with threat‑led penetration testing concepts (preferred but not required) Technical fluency with adversary tactics and frameworks such as MITRE ATT&CK Strong technical project management skills and a demonstrated ability to own issues end‑to‑end Financial services or regulated industry experience is preferred but not required Education & Preferred Qualifications At least 4 years of experience in operational cybersecurity roles Demonstrated experience with technical project management and issue ownership Background spanning security operations, incident response, detection engineering, threat intelligence, or penetration testing Experience with threat‑led penetration testing preferred but not required Advanced degree in information systems, data science, or a related field is desired but not required Relevant cybersecurity certifications are a plus but not required
For a full overview, visit https: //hrportal.ehr.com/statestreet/Home. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at StateStreet.com/careers Read our CEO Statement