Who we are looking forWe are looking for a
Security Product Manager, Perimeter Defense reporting directly to the Head of Defensive Engineering.
You will define and drive the strategy, roadmap, governance, and security outcomes for Perimeter Defense. Working across Security, GTS, application teams, and infrastructure teams, you will help ensure the organization's perimeter is continuously understood, assessed, protected, and improved.
This role is focused on bringing together multiple security capabilities and stakeholders to deliver measurable security outcomes and reduce perimeter risk.
Why this role is important to usThe team you will be joining is a part of
Global Cyber Security, Defensive Engineering, a function that is vital to protecting the firm, its clients, and its critical business services from cyber threats.
As the organization's technology landscape continues to evolve, maintaining visibility into internet-facing assets and ensuring appropriate security controls are in place is increasingly important. This role helps establish a consistent approach to perimeter security by bringing together capabilities such as attack surface management, vulnerability management, web application protection, responsible disclosure, bug bounty programs, and security testing to improve the overall security posture.
What you will be responsible forAs a
Security Product Manager, Perimeter Defense, you will:
- Define and maintain the strategy, roadmap, and security outcomes for the Perimeter Defense product.
- Establish visibility into perimeter-facing assets, including applications, infrastructure, domains, APIs, cloud services, and other externally accessible technologies.
- Identify gaps in security coverage and partner with the appropriate teams to drive improvements.
- Partner with GTS product owners and engineering teams to ensure security requirements and priorities are reflected in platform roadmaps.
- Help drive continuous assurance through attack surface management, vulnerability management, security testing, and related security capabilities.
- Define onboarding requirements and security standards for new perimeter-facing services and technologies.
- Establish metrics, reporting, and governance processes to measure effectiveness and communicate risk and progress to leadership.
- Support audit, regulatory, risk, and control assurance activities related to perimeter security.
What we valueThese skills will help you succeed in this role:
- Strong communication, collaboration, and stakeholder management skills.
- Ability to translate security risks and requirements into practical business and technology outcomes.
- Understanding of cybersecurity concepts such as vulnerability management, perimeter security, application security, cloud security, or attack surface management.
- Experience coordinating initiatives across multiple teams and stakeholders.
- Strong analytical, problem-solving, and decision-making skills.
Education & Preferred Qualifications- Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field, or equivalent experience.
- Experience in cybersecurity, technology, risk management, product management, or related disciplines.
- Familiarity with security technologies and controls such as vulnerability management, firewalls, web application security, cloud security, or related areas.
- Relevant cybersecurity or product management certifications are a plus.
Additional Requirements- Ability to work effectively across global teams and multiple stakeholder groups.
- Strong written and verbal communication skills.
- Interest in security, product management, and driving measurable business outcomes.
Work Requirement- Hybrid work model in accordance with company policy.
- Flexibility to support global teams across multiple time zones as needed.
Salary Range: $120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.