EASM / Persistent Perimeter Assurance Analyst, Vice President
State Street
- Location
- Quincy
- Employment
- Full Time
- Work model
- On-Site
- Level
- Staff
- Posted
- Sep 11, 2026
Skills
About this role
Who we are looking for State Street seeks to recruit an External Attack Surface Management (EASM) / Persistent Perimeter Assurance Analyst for its Global Cybersecurity organization , operating within the Cyber Fusion Center. The Perimeter Assurance team will lead the persistent discovery, monitoring and reduction of State Street’s internet-facing attack surface, and will be an operational leader ensuring the smooth execution of the perimeter assurance mission. This role involves alignment and the ability to foster cross-functional relationships, while partnering with teams ( Cyber Defense Centre (CDC) , Vulnerability Mgmt ) on driving and leading the continuous assessment, triage and remediation of external exposures across the corporate networks, subsidiaries and affiliates. Join us in evolving our defensive capabilities to protect State Street, its customers and partners from ever-evolving and sophisticated threat actors. State Street’s Cyber Fusion Center is responsible for detecting and responding to various cyber threats 24/7, 365. This role will be fully on-site in one of State Street’s offices in Quincy, MA; Boston, MA; or Kilkenny, Ireland. What will you be responsible for Owning the persistent External Attack Surface Management (EASM) capability – maintaining a live inventory of internet-facing assets, domains, certificates, cloud exposure and shadow IT across the State Street corporate estate, subsidiaries and affiliates. Operating continuous EASM/ external scanning across the perimeter, and partner on the structured triage of critical and high findings through to remediation and closure. Maintaining and creating documentation regarding perimeter assurance and exposure-management processes to ensure timely discovery, triage, validation, remediation and evidence of closure. Assist with the coordinated disclosure and bug bounty programme , acting as the operational bridge between external researchers and internal remediation owners. Representing and articulating the perimeter assurance position and interests in meetings and presentations, including but not limited to partners, metrics, audits and leadership – including monthly service reviews with evidence of SLA review and challenge. Leading the evaluation and lifecycle management of EASM and perimeter-scanning tooling, including build-vs-buy assessment of new and not-yet-purchased capabilities against a weighted scorecard. Support building a high performance culture and continuously enhancing the perimeter assurance and exposure-management process. Training and mentoring Cyber Fusion Center personnel and creating an environment which drives knowledge sharing with teams across the Fusion Center globally.
What we value
These skills will help you succeed in this role: Experience working in cyber security SOC / IT operations function. Hands-on experience operating EASM and/or external vulnerability scanning platforms at enterprise scale. Proven ability to triage, prioritize and drive remediation of critical and high-severity external vulnerabilities against defined SLAs. Working knowledge of bug bounty / responsible disclosure operations and coordination with external researchers. Ability to think critically, analyze data and synthesize it for decision making. Exceptional written and verbal communication skills, including the ability to translate technical exposure into executive and board-level narrative. Knowledge of adversarial tactics, techniques and procedures (TTPs) and industry standard frameworks (NIST, MITRE ATT&CK). Knowledge of IT architecture and operations (computing, network, storage & cloud), and of edge / zero-trust concepts . Strong working knowledge of security technologies including but not limited to SIEM, EDR/EPP, AV, ID/PS, HIPS, Web Proxy/Content filtering, AD, PKI and DNS. Understanding of