Who We're Looking For
The State Street Cyber Security Architecture & Engineering team is seeking an accomplished security professional with proven expertise in Application Security (AppSec), DevSecOps, Secure Software Development Lifecycle (SSDLC), Artificial Intelligence (AI), and Large Language Model (LLM) technologies. The ideal candidate will have hands-on experience implementing AI-driven security solutions, integrating AI agents into software development workflows, and applying advanced code analysis techniques to identify and remediate security vulnerabilities.
The successful candidate will be responsible for designing, implementing, and supporting the organization's Agentic AI Harness platform to enhance application security testing, vulnerability discovery, remediation guidance, and developer enablement. This role requires deep technical expertise, a strong security mindset, and a passion for applying emerging AI technologies to modernize and scale application security capabilities across the enterprise.
What You Will Be Responsible For
- Help define and execute the organization's Agentic AI Security Scanning strategy, integrating AI-powered code analysis, vulnerability discovery, and remediation capabilities into the broader Application Security and DevSecOps programs.
- Design, deploy, and support an enterprise AI Harness platform leveraging frontier models, agents, and orchestration frameworks to automate security testing activities.
- Partner with Software Engineering, Cloud Engineering, DevOps, Platform Engineering, and Security teams to integrate AI-based security capabilities into CI/CD pipelines and developer workflows.
- Evaluate, onboard, and operationalize emerging AI security technologies and platforms supporting secure software delivery.
- Develop AI agents capable of identifying security vulnerabilities, analyzing code quality, validating findings, reducing false positives, and recommending remediation actions.
- Build and maintain secure integrations with source code repositories, CI/CD platforms, vulnerability management systems, and security tooling.
- Leverage AI models to perform code review, threat modeling, secure design assessments, and security control validation across diverse technology stacks.
- Develop prompts, workflows, orchestration logic, guardrails, and governance controls to ensure accurate, secure, and responsible use of AI within application security processes.
- Collaborate with development teams to triage, prioritize, and remediate vulnerabilities identified through AI-assisted security assessments.
- Deliver dashboards, metrics, reports, and executive-level summaries demonstrating security coverage, vulnerability trends, AI platform effectiveness, and remediation outcomes.
- Establish operational procedures, standards, governance, and best practices for AI-enabled application security capabilities.
- Support audits, regulatory reviews, and risk management activities by providing evidence of AI governance, security controls, and operational processes.
- Continuously evaluate advancements in Generative AI, Agentic AI, LLMs, SLMs, and secure coding technologies to improve organizational security capabilities.
- Provide technical leadership and support strategic initiatives related to AI-driven application security transformation.
What We Value
These skills will help you succeed in this role:
- Strong software development background with technologies such as Java, .NET, Python, Go, JavaScript, Node.js, or similar platforms.
- Experience with Generative AI technologies, including LLMs, SLMs, Retrieval Augmented Generation (RAG), AI agents, prompt engineering, and model orchestration frameworks.
- Experience with frontier AI models such as GPT, Claude, Gemini, Llama, Mistral, DeepSeek, or similar technologies.
- Hands-on experience building AI-powered applications, agentic workflows, automation frameworks, or developer productivity solutions.
- Experience in Application Security disciplines including SAST, DAST, SCA, Container Security, API Security, Supply Chain Security, and Secure SDLC practices.
- Strong understanding of software vulnerabilities including OWASP Top 10, API Security Top 10, CWE, CVSS, and secure coding principles.
- Experience with cloud-native technologies and platforms including Azure, AWS, Kubernetes, and Infrastructure as Code (IaC).
- Familiarity with AI security concepts including prompt injection, model manipulation, data leakage, LLM security risks, and AI governance frameworks.
- Experience evaluating AI-generated findings, conducting root cause analysis, and developing automated remediation workflows.
- Knowledge of software supply chain security concepts including SBOMs, open-source risk management, and dependency analysis.
- Current information security certifications such as CISSP, CSSLP, Security+, GWAPT, GSEC, or equivalent are highly desirable.
- Excellent verbal and written communication skills with the ability to collaborate across technical, operational, and executive audiences.
Education & Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field with 10 to 15 years of relevant experience.
- Experience implementing or operating application security tools and DevSecOps platforms.
- Experience designing, developing, or operationalizing AI, machine learning, LLM, or automation-based solutions.
- Experience integrating AI technologies into enterprise software development or cybersecurity workflows.
- Experience partnering with development teams to influence adoption of secure coding practices, security tooling, and modern engineering solutions.
- Familiarity with AI governance, responsible AI practices, model risk management, and enterprise AI controls.
- Security+, CISSP, CSSLP, or equivalent security certification preferred.
- Experience with Agile, Scrum, and modern software engineering methodologies.
Work Requirement
Hybrid:Expected to work from base office location 4 days in a week
Shift:Standard business hours with flexibility to support global stakeholders across multiple time zones
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at
Read our