Software Supply Chain Security Engineer

State Street

Confirmed live yesterday Trusted

Quick summary

Work type
On-site
Location
Quincy, MAToronto, Ontario, CanadaAustin, TXAtlanta, GA
Salary
$90,000–$157,500 / yr
Posted
44 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $176k
This role $124k
$75k most similar roles pay here $230k

This role pays less than 91% of similar roles. Most pay $147,250–$204,275 — the shaded band above. At the midpoint, this role pays about $124k versus about $176k for comparable roles.

Based on 240 similar postings.

Employer

About State Street

State Street Corporation is one of the world''s largest custodian banks and asset managers, providing investment servicing, investment management, and investment research to institutional investors. Industry: Financial Services & Asset Custody

State Street currently has 176 open roles on FindRole.

Listed pay typically runs $120,000–$202,500 across 172 roles with salary data.

Most-posted roles

View all roles at State Street

At a glance

TL;DR · Software Supply Chain Security Engineer

The Software Supply Chain Security Engineer joins the Cyber Security Architecture & Engineering team to execute a security strategy focused on deploying secure-by-default open source artifacts across the enterprise. This role involves partnering with engineering leads to implement DevSecOps and AppSec principles, onboarding application teams to security tools, and managing artifact caches like JFrog Artifactory. The candidate will develop documentation, provide technical support for projects, and deliver metrics via dashboards. Key responsibilities include securing software supply chains and automating processes within CI/CD pipelines. Required skills include experience with Java, .Net, Python, Node.js, Azure, and AWS. Candidates should possess knowledge of SLSA principles, Infrastructure as Code, Ansible, Terraform, or Kubernetes. The role addresses the critical challenge of securing the software development lifecycle and managing artifact sources of truth in a hybrid cloud environment.

What you'll do

  • Execute the enterprise software supply chain security strategy for secure open source artifacts.
  • Implement DevSecOps and AppSec principles and processes in partnership with engineering leads.
  • Onboard application teams to security tools and troubleshoot integration issues with vendors.
  • Manage artifact caches and ensure secure sourcing from repositories like Maven Central and PyPI.
  • Automate security processes within CI/CD pipelines using infrastructure as code and orchestration tools.
  • Develop and maintain technical documentation for supply chain security and DevSecOps workflows.
  • Create and communicate security metrics and reporting via automated dashboards.
  • Continuously improve and optimize existing DevSecOps and software supply chain security tools.

What we're looking for

  • At least 6 years of relevant experience across development, CI/CD, software supply chain security, and application security.
  • Proven expertise in AppSec, software supply chain security implementation, and governance.
  • Experience with secure software development lifecycle (SSDLC) and automating security processes within CI/CD pipelines.
  • Experience managing artifact caches like JFrog Artifactory and familiarity with Maven Central, PyPI, and SLSA principles.
  • Proficiency in programming languages such as Java, .Net, Python, or Node.js.
  • Experience with cloud technologies (Azure, AWS) and automation tools like Ansible, Terraform, or Kubernetes.
  • Possession of a current information security certification, such as CISSP or Security+.
  • Strong communication skills to partner with engineering teams and influence the adoption of security best practices.

More like this

Similar roles

Software Supply Chain Security Engineer

State Street

Quincy, MA 7 days ago $120,000$202,500
AppSec DevSecOps CI/CD Software Supply Chain Security JFrog Artifactory Maven Central PyPI SLSA Java Python .Net Node.js AWS Azure Ansible Terraform Kubernetes Infrastructure as Code Agile
10+ yrs exp

Supply Chain Security Lead

State Street

Quincy, MA 44 days ago $120,000$217,500
AppSec Software Supply Chain Security DevSecOps CI/CD SBOM JFrog Artifactory Maven Central PyPI SLSA Java Python .Net Node.js AWS Azure Ansible Terraform Kubernetes Infrastructure as Code Agile
10+ yrs exp

Application Security Engineer

State Street

Quincy, MA +4 13 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp

Application Security Engineer

State Street

Quincy, MA 44 days ago $100,000$167,500
AppSec DevSecOps SAST SCA DAST CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC Container Security
6+ yrs exp

Application Security Engineer

State Street

Quincy, MA +3 44 days ago $120,000$202,500
AppSec ADR DevSecOps SAST DAST SCA RASP WAAP API Security OWASP Top 10 Java Python .NET Node.js AWS Azure Ansible Terraform Kubernetes CI/CD Infrastructure as Code
6+ yrs exp