Endpoint Security Product Lead
State Street
- Location
- Boston
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 11, 2026
Skills
About this role
Who we are looking for We are looking for a VP, Endpoint Product Security Lead reporting into the Defensive Engineering leadership team within Global Cyber Security (GCS). This role will lead the Endpoint Product Security team and define the strategy, roadmap, and maturity of enterprise endpoint security capabilities. The role will build a shared and embedded product model with GTS Endpoint Platform leaders , aligning Cyber Security requirements with GTS platform priorities to deliver shared security outcomes across the enterprise. Why this role is important to us The team you will be joining is part of Defensive Engineering within Global Cyber Security, a function that is critical to the company’s cybersecurity strategy. Endpoints remain a significant attack surface for unauthorized software, malicious content, credential theft, and other cyber threats. This role will lead the team responsible for advancing endpoint security maturity through proactive controls, strong product management, measurable outcomes, and close partnership with GTS. What you will be responsible for As a VP, Endpoint Product Security Lead , you will: Lead, develop, and manage a team of endpoint product security professionals, setting clear priorities, expectations, and accountability. Define and drive the enterprise endpoint security strategy, product roadmap, and maturity plan. Build a shared product operating model with GTS Endpoint Platform leaders that aligns priorities, roadmaps, ownership, and success measures. Treat the GTS Endpoint Platform organization as a key customer and partner, ensuring security capabilities are practical, scalable, and embedded within endpoint platform services. Establish shared outcomes and metrics across GCS and GTS for endpoint security coverage, policy enforcement, control effectiveness, exceptions, and risk reduction. Drive the adoption and maturity of capabilities such as application control, browser security, endpoint hardening, attack surface reduction, and endpoint resilience. Establish endpoint security requirements, configuration standards, policy baselines, and secure-by-design practices. Assess control coverage and effectiveness, identify security gaps, and prioritize improvements based on threat, risk, and business impact. Lead security product evaluations, proof-of-concepts, vendor assessments, and platform lifecycle planning. Collaborate with the Cyber Defense Center to improve endpoint telemetry, visibility, investigation, and incident response capabilities. Partner with Infrastructure, Desktop Engineering, Server, Cloud, and other technology teams to embed security throughout the endpoint lifecycle. Maintain product documentation, control evidence, and supporting materials for risk, audit, and regulatory requirements. Serve as the product owner and senior subject matter expert for enterprise endpoint security capabilities.
What we value
These skills will help you succeed in this role: Proven experience leading and developing technical or cybersecurity teams. Strong experience with enterprise endpoint security technologies, controls, and architectures. Experience building effective partnerships and shared product models across Cyber Security and Technology organizations. Ability to align security requirements with platform engineering priorities and operational needs. Experience developing security product strategies, roadmaps, technical standards, and maturity plans. Strong understanding of endpoint threats and preventative controls across workstations, servers, browsers, and virtual environments. Experience with application control, browser security, endpoint hardening, attack surface reduction, and endpoint resilience. Knowledge of frameworks and practices such as NIST CSF, CIS Controls, CIS Benchmarks, MITRE ATT&CK, and Zero Trust. Experience defining meaningful metrics, measuring control effectiveness, and driving remediation of security gaps. Strong leadership, product management,