Senior SIEM & Security Platforms Engineer , Assistant Vice president
AI in this role
Who We Are Looking For
State Street's Cyber Data & Analytics (CyberDNA) team is seeking a Platform Operations Engineer to help shape the next generation of cybersecurity data, analytics, and AI-powered platforms. Partnering closely with Global Cyber Security, Infrastructure Teams, and Enterprise Continuity Services, this team develops advanced data platforms, intelligent automation solutions, and engineering capabilities that enable cybersecurity teams to make faster, data-driven decisions and strengthen the firm's ability to detect, prevent, and respond to evolving cyber threats. Through innovation in AI, analytics, and automation, CyberDNA plays a critical role in protecting State Street, its clients, and its partners from increasingly sophisticated global threat actors.
The successful candidate will bring a strong interest in platform operations, hands-on technical support, and a willingness to learn enterprise cybersecurity technologies, including SIEM, AI-SOC, data routing, and Security Lakehouse platforms. This role will support the day-to-day monitoring, troubleshooting, incident response, change activities, and platform administration needed to maintain service stability, availability, and reliability. Success requires a foundational understanding of production support, IT service management, operational procedures, documentation, and continuous improvement in a regulated enterprise environment.
What You Will Be Responsible For
Support the administration, reliability, and day-to-day operations of enterprise platform administration for enterprise cybersecurity technologies, including SIEM, AI-SOC, telemetry routing, and Security Lakehouse platforms.
Support platform reliability, availability, performance, and operational readiness through proactive monitoring, incident management, and continuous improvement.
Support cybersecurity teams including Detection Engineering, Threat Intelligence, Threat Hunting, Forensics, and SOC/Cyber Defense operations.
Support platforms such as Splunk, Enterprise Security, Cribl, Databricks, Elastic, and other cybersecurity analytics technologies.
Support platform upgrades, migrations, modernization initiatives, and operational transformation programs.
Monitor and support major incident response, root cause analysis, problem management, and change execution activities.
Monitor and support platform health, telemetry ingestion, data quality, storage utilization, and service performance across cybersecurity data platforms.
Support and maintain operational standards, governance, SOPs, monitoring procedures, and ITIL-aligned support processes.
Support compliance with cybersecurity, audit, regulatory, and operational control requirements.
Support continuously improves operational standards, governance, documentation, monitoring procedures, SOPs, and support models aligned to ITIL, change management, and Log Telemetry Monitoring control requirements, while measuring success through operational metrics and service performance indicators.
Provide 24x7x365 operational support through an on-call rotation, collaborating with globally distributed engineering and operations teams to maintain platform reliability and service continuity.
What We Value
These skills will help you succeed in this role
Strong experience administering and supporting enterprise-scale cyber security platforms including technologies such as Splunk, QRadar, Elastic, and similar security operations solutions.
Deep understanding of security monitoring, threat detection, incident response, correlation searches, notable event management, data models, and risk-based alerting methodologies.
Hands-on expertise to support telemetry and data pipeline solutions such as Cribl Stream, including data routing, transformation, filtering, enrichment, and optimization of machine data at scale.
Experience integrating security and operational telemetry into Databricks or similar data lakehouse platforms to support advanced analytics, reporting, machine learning, and AI-driven use cases.
Strong knowledge of cloud-based infrastructure and platform operations, preferably on AWS & Azure , combined with solid Linux/Unix administration, troubleshooting, and performance tuning skills.
Proficiency in scripting, automation, and version control practices to improve operational efficiency, automate repetitive tasks, enhance monitoring capabilities, and increase platform reliability.
Working knowledge of ServiceNow, Jira, and Confluence, with experience supporting incident, problem, change, service request, Agile delivery, and technical documentation processes.
Solid understanding of ITIL principles, operational best practices, service management disciplines, governance frameworks, and compliance requirements in a large enterprise environment.
Exceptional communication and stakeholder management skills, with the ability to effectively communicate technical concepts and operational risks to both technical and non-technical audiences.
Strong organizational and collaboration skills, with the ability to coordinate across geographically distributed teams, manage competing priorities, and successfully drive operational outcomes.
Experience supporting highly available, mission-critical platforms within complex enterprise environments, demonstrating a strong commitment to operational excellence, resiliency, and continuous improvement.
Ability to thrive in a fast-paced, global operations environment while maintaining a strong customer focus and driving high-quality service delivery.
Education & Preferred Qualifications
Bachelor’s degree in Computer Science, Engineering, Information Systems, or a related field.
5+ years of platform engineering and platform/infrastructure operations experience.
3+ years of experience with public cloud (AWS, Azure, OCI) & DevOps and ability to manage cloud-native platforms
5+ years of experience in supporting SIEM platforms like Splunk, Datadog, Qradar, Elastic, Cribl, Databricks and AI-SOC solutions
Relevant certifications preferred, such as AWS, Splunk, ITIL, CISSP, or related technology/security certifications.
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
How we rate this
Senior SIEM & Security Platforms Engineer , Assistant Vice president at State Street rates 28 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a workflow you automated with AI tools, end to end.
- Walk me through how you've used Databricks in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: AI Automation and Databricks. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step