Who we are looking forState Street's Cyber Data & Analytics (CyberDNA) team is seeking a Security Data Solutions Engineer to shape the next generation of cybersecurity data, analytics, and AI-powered solutions. Partnering closely with Global Cyber Security teams, Infrastructure Teams, and Enterprise Continuity Services, this team develops advanced data platforms, intelligent automation solutions, and engineering capabilities that enable cybersecurity teams to make faster, AI-driven decisions and strengthen the firm's ability to detect, prevent, and respond to evolving cyber threats.
Why this role is important to usThrough innovation in AI, analytics, and automation, CyberDNA team plays a critical role in protecting State Street, its clients, and its partners from increasingly sophisticated global threat actors. High-quality security telemetry is the foundation for effective threat detection, incident response, threat hunting, cyber analytics, automation, risk management, and regulatory reporting.
As a Security Data Solutions Engineer, you will bridge cybersecurity, data engineering, and product management disciplines to ensure security data products deliver measurable business value. You will partner with security operations, detection engineering, platform engineering, cloud, infrastructure, and application teams to design and implement scalable security data solutions that support SIEM, AI-driven analytics, automation, and next-generation cyber defense capabilities.
This role is ideal for an experienced professional who understands both the technical requirements of security log telemetry and the business objectives of cybersecurity programs, and who can translate complex requirements into production-scale designs & data solutions.
What you will be responsible forAs a Security Data Solutions Engineer, you will:
- Serve as the subject matter expert for security data solutions supporting SIEM, Security Analytics, Detection Engineering, Threat Hunting, and AI-enabled cybersecurity use cases.
- Partner with cybersecurity stakeholders to define data requirements, success criteria, onboarding priorities, roadmaps, and measurable outcomes for security data products.
- Design and implement enterprise-scale security telemetry solutions supporting on-premises, cloud, SaaS, and hybrid environments.
- Analyze source systems, log schemas, metadata requirements, retention needs, and downstream analytics requirements to define onboarding and normalization strategies.
- Design optimal workflows for onboarding of security data from applications, cloud platforms, identity systems, infrastructure, network devices, databases, endpoints, and security tools.
- Design scalable ingestion, routing, transformation, enrichment, normalization, and validation patterns for SIEM and cybersecurity data platforms.
- Ensure security telemetry meets requirements for quality, completeness, timeliness, consistency, governance, and operational reliability.
- Collaborate with architects, engineers, and product managers to prioritize capabilities and deliver solutions that align with cybersecurity and business objectives.
- Working with Product managers, define product roadmaps, feature requirements, user stories, acceptance criteria, and delivery milestones for security data initiatives.
- Lead cross-functional workshops with business and technical stakeholders to identify opportunities for improving cybersecurity visibility and operational efficiency.
- Establish data quality metrics, service-level objectives, operational KPIs, data governance and process governance controls for security data products
- Spearhead the implementation of AI, automation, and self-service workflow capabilities that improve cybersecurity outcomes and reduce operational effort.
- Influence strategic direction of cybersecurity data platforms, data engineering processes, and analytics capabilities.
- Provide technical leadership for complex cybersecurity data integration and modernization initiatives.
What we valueThese skills will help you succeed in this role
- Deep understanding of SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, Elastic, Chronicle, or similar technologies.
- Proven experience designing data driven solutions using technologies such as Databricks, Snowflake, Kafka, Spark and logging agents like Cribl, OpenTelemetry, FluentBit, or equivalent platforms.
- Hands-on experience & Strong understanding of data engineering concepts including ETL/ELT, streaming pipelines, data lakes, data warehouses, and data governance.
- Hands-on experience developing, validating, and deploying machine learning models and scalable data pipelines within production environments
- Strong knowledge of cybersecurity telemetry, log management, event correlation, data normalization, enrichment, and detection engineering requirements.
- Demonstrated product management experience with the ability to develop roadmaps, prioritize features, define business value, and manage stakeholder expectations.
- Experience with cloud-native architectures across AWS, Azure, and Google Cloud environments.
- Ability to analyze complex problems, evaluate trade-offs, and recommend pragmatic solutions balancing business and technical requirements.
- Strong understanding of cybersecurity use cases including incident response, threat detection, threat hunting, vulnerability management, identity security, and cloud security.
- Experience working within Agile, DevSecOps, and product-driven delivery models.
- Exceptional communication, collaboration, and stakeholder management skills.
- Ability to influence technical and business leaders across multiple organizations.
Education & Preferred Qualifications- Bachelor's degree in computer science, Cybersecurity, Information Technology, Engineering, Data Engineering, Information Systems, or a related technical discipline.
- 8+ years of experience in cybersecurity, data engineering, AI/ML, security analytics, SIEM engineering, product design, or related technical fields.
- 5+ years of hands-on experience designing and implementing enterprise-scale data products, data lakes, Lakehouse and data warehouse solutions.
- Advanced expertise in Python, SQL, Spark, Kafka, Databricks, Snowflake, Splunk and cloud-native data platforms to design, build, and optimize scalable batch and real-time data pipelines.
- Demonstrated experience managing complex cybersecurity data integration programs and stakeholder requirements.
- Hands-on experience with SIEM platforms and the data onboarding, normalization, and operational processes required to support them.
- Strong understanding of data modeling, data architecture, APIs, event streaming, cloud-native services, and modern analytics platforms.
- Familiarity with cybersecurity frameworks including NIST CSF, MITRE ATT&CK, CIS Controls, and Zero Trust architectures.
- Master's degree in computer science, Cybersecurity, Engineering, Data Science, Business Administration, or related discipline.
- Industry certifications such as CISSP, CISM, CCSP, Splunk Certified Architect, Splunk Certified Consultant, Microsoft Security Certifications, AWS Certifications, Databricks Certifications, or equivalent.
- Experience delivering cybersecurity data products within highly regulated industries such as financial services, healthcare, or critical infrastructure.
- Experience supporting AI/ML, Security Lakehouse, Agentic AI, Security Copilot, or advanced cyber analytics initiatives.
Work Requirement- Work shift is 8 AM - 5 PM local time with occasional Level 3 escalation resolution to support operational incidents
- This hybrid role includes an in-office presence requirement of 2-4 days per week, consistent with the organization's hybrid work policy.
Salary Range: $120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.