
Red Team Engineer
- Threat Intelligence
- Network Security
- Incident Response
- Penetration Testing
- Technical Writing
- Pension
Who we are looking for
As a member of the Red Team within the Global Cyber Security group, the Red Team Engineer will serve as a core technical contributor for adversary-emulation, threat-informed security testing, and controlled offensive security operations. The engineer will execute activities in accordance with State Street's standards and procedures, risk-acceptance requirements, and regulatory expectations, ensuring all work is conducted within approved environments, scopes, and authorization pathways. The role also requires disciplined documentation practices so that assessment decisions, activities, evidence, findings, and outcomes are clear, traceable, and audit-ready.Â
The Red Team Engineer will conduct comprehensive, intelligence‑driven assessments of enterprise applications, critical infrastructure components, and associated operational and technical security controls. These assessments evaluate not only the security posture of targeted systems but also the effectiveness of the organization’s detection, prevention, response, and governance capabilities.Â
The Red Team Engineer will collaborate with technical experts across applications, platforms, and infrastructure, security leadership, and process stakeholders, threat intelligence and defensive analytics teams, security operations personnel, and business system owners to ensure testing scenarios reflect realistic adversary behaviors and enterprise risks. The role requires strong technical expertise and broad knowledge of core security control domains, including identity and access management, data protection, secure software development, cloud and infrastructure security, endpoint and detection technologies, network security, and enterprise vulnerability and threat management. Familiarity with security monitoring, detection engineering, and incident response processes further supports the evaluation of organizational defenses.Â
Â
Why this role is important to us
The Red Team Engineer will collaborate with technical experts across applications, platforms, and infrastructure, security leadership, and process stakeholders, threat intelligence and defensive analytics teams, security operations personnel, and business system owners to ensure testing scenarios reflect realistic adversary behaviors and enterprise risks. The role requires strong technical expertise and broad knowledge of core security control domains, including identity and access management, data protection, secure software development, cloud and infrastructure security, endpoint and detection technologies, network security, and enterprise vulnerability and threat management. Familiarity with security monitoring, detection engineering, and incident response processes further supports the evaluation of organizational defenses.
What you will be responsible for
- Execute authorized adversary‑emulation activities to assess defenses, security controls, and organizational resilience.Â
- Perform targeted security assessments across applications, infrastructure, cloud platforms, and enterprise technologies.Â
- Collaborate with cybersecurity, technology, and risk stakeholders to develop realistic, threat‑informed testing scenarios.Â
- Evaluate detection and response capabilities and support improvement through coordinated purple‑team activities.Â
- Operate within defined approval processes, scopes, authorization boundaries, and safe‑testing protocols.Â
- Develop or adapt tools and techniques to support realistic testing, ensuring secure and compliant usage.Â
- Produce clear, accurate, and audit-ready assessment documentation and reporting, and support remediation to reduce identified risks and strengthen defenses.Â
- Create and maintain assessment documentation, including approved scope and authorization records, test plans, procedures, evidence, findings, and final reports, as applicable to the engagement.Â
- Organize and retain assessment records in approved repositories so that key decisions, execution evidence, and outcomes can be retrieved and explained during control reviews, audits, and regulatory examinations.Â
- Support audit and assurance activities by responding to evidence requests, explaining the documented execution of Red Team processes, and addressing identified documentation gaps.Â
What we value
These skills will help you succeed in this role
- Strong proficiency in offensive security techniques, including infrastructure, application, and cloud‑focused penetration testing.Â
- Deep understanding of adversary behaviors and attack frameworks (e.g., MITRE ATT&CK) to inform realistic testing scenarios.Â
- Familiarity with modern security tooling, assessment utilities, and red‑team‑oriented testing methodologies.Â
- Ability to develop or adapt scripts and tools using common scripting languages.Â
- Broad technical knowledge across networks, operating systems, identity systems, cloud services, and security controls.Â
- Demonstrated analytical ability to identify core issues, interpret risk, and propose practical, evidence‑driven solutions.Â
- Strong organizational, time‑management, and prioritization skills in dynamic and high‑pressure environments.Â
- Ability to work independently while collaborating effectively with technical and non‑technical stakeholders.Â
- Commitment to maintaining awareness of emerging threats, vulnerabilities, and offensive security trends.Â
- High attention to detail and consistent delivery of accurate, complete, and high-quality technical documentation and work products.Â
- Exceptional written and verbal communication skills, including the ability to document complex technical activities clearly and explain them to technical, risk, audit, and non-technical stakeholders.Â
- Proven ability to handle sensitive information responsibly and operate with discretion and professionalism.Â
- Demonstrated ability to produce structured, evidence-based documentation that is complete, consistent, traceable, and suitable for independent review.Â
- Experience working in a regulated or audited environment and collaborating constructively with risk, compliance, control, or audit stakeholders.Â
- Strong records-management discipline, including the ability to maintain version control and store supporting records in approved repositories.Â
Education & Preferred Qualifications
- Bachelor’s degree or equivalent hands‑on security experience.Â
- 2–4 years in penetration testing or red‑team activities.Â
- Broad experience with networks, operating systems, cloud, and security controls.Â
- Familiarity with threat‑informed testing and attack frameworks.Â
- Experience collaborating with defensive teams to validate detections.Â
- Ability to script or automate tasks using common languages.Â
- Strong technical writing and reporting skills across technical, risk, audit, and non-technical audiences.Â
- Demonstrated experience authoring or maintaining security assessment plans, procedures, evidence packages, findings, and executive or technical reports.Â
- Experience supporting internal audit, external audit, regulatory examination, control assurance, or similar evidence-review activities is strongly preferred.Â
Salary Range:
$125,000 - $215,000 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visithttps://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs atStateStreet.com/careers
Read ourCEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Red Team Engineer · SSBT