Senior Staff SaaS Security Engineer
Job Description
State Street is hiring a Senior Staff SaaS Security Engineer to strengthen defensive engineering capabilities within Global Cyber Security. This hybrid role focuses on building and operating security foundations across the enterprise SaaS ecosystem, with emphasis on visibility, governance, and protection.
You will help deploy, integrate, and operationalize SaaS security platforms and controls, working closely with application owners and platform teams to onboard SaaS applications and drive remediation of identified risks.
What You’ll Do
- Lead deployment, integration, and operationalization of SaaS Security Posture Management (SSPM), SaaS threat protection, and governance capabilities across enterprise SaaS platforms.
- Partner with application owners, platform teams, and security stakeholders to onboard SaaS applications, implement security controls, and remediate risks.
- Design and maintain SaaS security integrations, including API-based telemetry collection, and develop automation workflows for continuous visibility into SaaS posture and threats.
- Create and maintain SaaS security standards, architecture documentation, operational procedures, and implementation guidelines.
- Track and report key SaaS security metrics such as application coverage, posture findings, threat exposure, and remediation progress.
What You’ll Need
- Hands-on experience with SSPM, CASB, SaaS security, or SaaS threat protection platforms such as Obsidian Security.
- Strong understanding of SaaS-to-SaaS, identity-to-SaaS, and agent-to-SaaS threats, including account takeover, OAuth abuse, privilege escalation, data exposure, and unauthorized application access.
- Experience onboarding enterprise SaaS applications and implementing security controls through APIs, automation, and governance frameworks.
- Knowledge of OAuth, OpenID Connect (OIDC), SAML/SSO, and API permission models, with familiarity in modern SaaS security architectures.
- Strong analytical, problem-solving, automation, and scripting skills.
- Experience securing enterprise SaaS ecosystems and managing application risk at scale.
- Experience working with modern SaaS platforms, APIs, automation frameworks, and cloud-native security technologies.
- Knowledge of emerging AI and agentic technologies and their impact on SaaS security is a plus.
- Ability to collaborate effectively with global teams across multiple time zones.
- Hybrid work model in accordance with company policy.
- Standard business hours with flexibility to support critical incidents and deployments when required.
Technologies
- SaaS Security Posture Management (SSPM)
- CASB
- Obsidian Security
- OAuth
- OpenID Connect (OIDC)
- SAML/SSO
- API permission models
- API-based telemetry collection
- Automation workflows
- AI
- Agentic technologies
Education and Experience
- Minimum experience: 5 years
- Education: Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience
Compensation and Benefits
- Salary range: $120,000 - $202,500 per year
- 401K with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to the Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans)
- Eligibility for certain tax advantaged savings plans
Location: Boston, MA (hybrid)