State Street

Threat Emulation and Intelligence MD

Berwyn, Pennsylvania Full time

Who we are looking for

Global Cybersecurity (GCS) protects State Street and its clients from the impact of cyber-attacks against systems by understanding the risks these attacks present and mitigating them through a robust, continuously evolving, cybersecurity program and control environment.

Fusion & Security Operations (F&SO) is one of five functions that make up GCS. F&SO works to provide real-time knowledge of cyber threats of today collectively to better prepare State Street for threats of tomorrow.

This MD role sits within Fusion & Security Operations (F&SO), the function that delivers real‑time knowledge of today’s cyber threats and prepares the bank for threats of tomorrow. This role leads the Threat Emulation (red/purple teaming and adversary simulation) and Cyber Threat Intelligence (CTI) practices end‑to‑end—designing realistic threat‑led scenarios, emulating relevant adversaries, producing actionable intelligence, and driving measurable control and detection improvements across the enterprise.

Responsibilities:

  • Build an enterprise threat emulation program with safe‑testing standards, scoping, rules of engagement, and executive approvals for production‑adjacent tests.
  • Design and execute red team exercises, adversary emulation, and tabletop simulations mapped to MITRE ATT&CK and regulatory frameworks (CBEST, iCAST, DORA/TIBER‑EU).
  • Run the full intelligence cycle to deliver strategic, operational, and tactical insights; maintain adversary profiles and campaign analysis.
  • Develop intelligence programs focused on third‑party and customer ecosystems to identify emerging risks and supply‑chain threats.
  • Oversee secure testing of critical applications, APIs, and customer‑facing platforms; ensure findings feed into SDLC and DevSecOps pipelines.
  • Govern testing of core infrastructure, networks, and cloud environments; validate hardening and detection controls.
  • Ensure readiness and execution of regulator‑mandated threat‑led testing programs; manage evidence, remediation, and audit alignment.
  • Implement continuous discovery and monitoring of external and internal attack surfaces; prioritize exposures and drive remediation.
  • Act as the primary liaison for government cybersecurity partners and industry information‑sharing groups (e.g., FS‑ISAC), representing the broader cyber organization in collaborative threat intelligence and resilience initiatives.
  • Produce strategic, operational, and tactical intelligence products (daily briefs, campaign analysis, threat actor profiles, and executive summaries).

Preferred Qualifications:

  • 15+ years in cybersecurity with deep experience in cyber threat intelligence and offensive security (red/purple teaming, adversary simulation) within complex, regulated environments.
  • Demonstrated success leading multi‑disciplinary teams and programs at enterprise scale; proven ability to manage budgets and vendor ecosystems.
  • Expert knowledge of threat‑led testing frameworks and financial‑sector regulatory programs (e.g., CBEST, iCAST, DORA/TIBER‑EU).
  • Exceptional written and verbal communication skills, with a track record of concise executive reporting and board engagement.
  • Advanced degree in cybersecurity, computer science, intelligence studies, or related field; industry certifications such as CISSP/CISM, GIAC GCTI, OSCP/OSCE or equivalent.
  • Experience standing up fusion models that integrate CTI, hunt, detection engineering, and emulation under one operating framework.
  • Exceptional communication and executive influence skills.

Location:

OSL Washington DC, USA

Salary Range:

$170,000 - $282,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.