Product Security Engineer Architect Email Security

Job Description

Company: State Street

## About the Role

We are looking for a Product Security Engineer / Architect – Email Security to join the Defensive Engineering leadership team within Global Cyber Security (GCS). In this role, you will lead the strategy, architecture, and engineering of enterprise email security capabilities, protecting the organization against phishing, business email compromise (BEC), account takeover, malware, and emerging threats. Email remains one of the primary attack vectors used by threat actors, and this position is critical to driving the technologies, controls, and security capabilities needed to protect our communication channels and reduce cyber risk.

## What You’ll Be Doing

– Define and drive the enterprise email security strategy, architecture, and roadmap.

– Lead the evaluation, implementation, and continuous improvement of email security technologies and controls.

– Partner with the GTS Email Platform team to design and deploy security capabilities across the email ecosystem.

– Collaborate with the Cyber Defense Center (CDC) to enhance detection, investigation, and response for phishing, BEC, account takeover, and other email-borne threats.

– Work with Threat Intelligence, Identity Security, and Incident Response teams to identify emerging threats and improve defensive controls.

– Lead product evaluations, proof-of-concepts, and vendor assessments for email security technologies.

– Drive integration of email security solutions with security monitoring, analytics, and response platforms.

– Develop security standards, architectural patterns, and implementation guidance.

– Track and report key metrics related to email threat protection, phishing resilience, and risk reduction.

– Serve as a subject matter expert for enterprise email security initiatives.

## What We Value

You should have experience with enterprise email security technologies such as Microsoft Defender for Office 365, Proofpoint, Abnormal Security, Mimecast, Cisco Secure Email, or similar platforms. A strong understanding of phishing, BEC, account takeover, malware, social engineering, and email-based threats is essential. Knowledge of SPF, DKIM, DMARC, SMTP security, and email authentication frameworks is also required. You should have experience designing and implementing enterprise-scale email security controls and architectures, and integrating email security platforms with SIEM, SOAR, identity, endpoint, and threat intelligence solutions. Strong analytical, problem-solving, automation, and scripting skills are important, along with excellent communication and stakeholder management abilities.

## Education & Experience

A Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience) is required. You must have 8+ years of experience in cybersecurity, security engineering, or security architecture, and at least 5+ years of hands-on experience with email security technologies and threat protection solutions. Experience in financial services or other regulated industries is preferred. Relevant certifications such as CISSP, CCSP, GIAC, or Microsoft Security certifications are also preferred.

## Additional Requirements

You should have experience developing security strategies, roadmaps, and architecture standards. Familiarity with emerging AI-driven phishing, impersonation, and social engineering threats is a plus. Strong collaboration skills and the ability to work across Cyber Security, GTS, and Engineering organizations are essential. You must be able to translate security risks into actionable technical solutions.

## Work Arrangement & Benefits

This role follows a hybrid work model in accordance with company policy. You’ll need to collaborate effectively with global teams across multiple time zones. Standard business hours apply, with flexibility to support critical security incidents and initiatives when required. The salary range for this position is $120,000 – $202,500 annually, based on the primary location. Employees are eligible for a comprehensive benefits program including a 401(k) with company match, insurance coverage (basic life, medical, dental, vision, long-term disability, and optional coverages), paid time off (vacation, sick leave, short-term disability, family care), an Employee Assistance Program, incentive compensation (annual performance-based awards), and tax-advantaged savings plans. For more details, visit the full benefits overview.

Source: Bandana.com