1

Security Phishing Engineer Jobs (NOW HIRING)

You'll also help respond to security operations alerts and run our security awareness phishing ... As the Security Engineer, you'll be able to: * Run Coterie's recurring user access reviews under ...

Showing results 21-40

Security Phishing Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do security phishing engineer jobs pay per year?

As of Sep 11, 2026, the average yearly pay for security phishing engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What is a security phishing engineer?

Security Phishing Engineers are cybersecurity professionals who specialize in designing and executing simulated phishing attacks within an organization. Their main goal is to test and improve employees' awareness and response to phishing threats by mimicking real-world cyberattack scenarios. Through these controlled exercises, they help organizations identify vulnerabilities and educate staff on how to recognize and avoid malicious phishing attempts. This role is crucial for strengthening an organization's overall security posture.

What are the key skills and qualifications needed to thrive as a security phishing engineer, and why are they important?

To thrive as a Security Phishing Engineer, you need expertise in cybersecurity principles, threat analysis, and social engineering tactics, often backed by a degree in computer science or a related field. Familiarity with phishing simulation platforms, incident response tools, and certifications such as CEH or CISSP are commonly required. Strong analytical thinking, attention to detail, and effective communication skills are vital for identifying threats and educating teams. These competencies are crucial for proactively defending organizations against phishing attacks and fostering a culture of cybersecurity awareness.

How does a security phishing engineer typically collaborate with other departments to improve organizational security awareness?

A Security Phishing Engineer works closely with IT, Human Resources, and Compliance teams to design and execute simulated phishing campaigns and training initiatives. They coordinate with these departments to ensure that training materials are relevant, accessible, and tailored to the unique needs of various employee groups. Regular debrief sessions and data sharing help identify trends and areas for improvement, fostering a proactive security culture across the organization. Effective collaboration also ensures that feedback from different departments is incorporated into future security awareness strategies.

What is the difference between Security Phishing Engineer vs Security Analyst?

AspectSecurity Phishing EngineerSecurity Analyst
CertificationsCertified Ethical Hacker (CEH), CompTIA Security+CompTIA Security+, CISSP
Work EnvironmentFocus on phishing detection, email security, and user trainingBroader security monitoring, incident response, and risk assessment
Industry UsageTech companies, financial institutions, cybersecurity firmsAll industries, including government, healthcare, and finance

While both roles involve cybersecurity, a Security Phishing Engineer specializes in identifying and preventing phishing attacks through technical measures and user education. A Security Analyst has a broader scope, monitoring overall security posture, analyzing threats, and responding to incidents. The roles often overlap but differ mainly in focus and specific responsibilities.

What are popular job titles related to Security Phishing Engineer jobs?

For Security Phishing Engineer jobs, the most frequently searched job titles are:

Infographic showing various Security Phishing Engineer job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Product Security Engineer / Architect - Email Security

Princeton, NJ • Hybrid

State Street Global Advisors
Finance and Insurance • 1 - 5K employees

$120K - $202K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Who we are looking for

We are seeking aProduct Security Engineer / Architect - Email Securityreporting into the Defensive Engineering leadership team within Global Cyber Security (GCS). You will lead the strategy, architecture, and engineering of enterprise email security capabilities, protecting the organization against phishing, business email compromise (BEC), account takeover, malware, and emerging threats.

Why this role is important to us

The team you will be joining is part of Defensive Engineering within Global Cyber Security, a function that is critical to the company's cybersecurity strategy. Email remains one of the primary attack vectors used by threat actors to target organizations. This role will help drive the technologies, controls, and security capabilities needed to protect the firm's communication channels and reduce cyber risk.

What you will be responsible for

As aProduct Security Engineer / Architect - Email Security, you will:

  • Define and drive the enterprise email security strategy, architecture, and roadmap.
  • Lead the evaluation, implementation, and continuous improvement of email security technologies and controls.
  • Partner with theGTS Email Platform team, which owns and operates the enterprise email infrastructure, to design and deploy security capabilities across the email ecosystem.
  • Collaborate with theCyber Defense Center (CDC)to enhance detection, investigation, and response capabilities for phishing, business email compromise (BEC), account takeover, and other email-borne threats.
  • Work with Threat Intelligence, Identity Security, and Incident Response teams to identify emerging threats and improve defensive controls.
  • Lead product evaluations, proof-of-concepts, and vendor assessments for email security technologies.
  • Drive integration of email security solutions with security monitoring, analytics, and response platforms.
  • Develop security standards, architectural patterns, and implementation guidance for email security controls.
  • Track and report key metrics related to email threat protection, phishing resilience, and risk reduction.
  • Serve as a subject matter expert for enterprise email security initiatives.
What we value

These skills will help you succeed in this role:

  • Experience with enterprise email security technologies such asMicrosoft Defender for Office 365, Proofpoint, Abnormal Security, Mimecast, Cisco Secure Email, or similar platforms.
  • Strong understanding of phishing, business email compromise (BEC), account takeover, malware, social engineering, and email-based threats.
  • Knowledge of email security technologies includingSPF, DKIM, DMARC, SMTP security, and email authentication frameworks.
  • Experience designing and implementing enterprise-scale email security controls and architectures.
  • Experience integrating email security platforms with SIEM, SOAR, identity, endpoint, and threat intelligence solutions.
  • Strong analytical, problem-solving, automation, and scripting skills.
  • Excellent communication and stakeholder management skills.
Education & Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, security engineering, or security architecture.
  • 5+ years of hands-on experience with email security technologies and threat protection solutions.
  • Experience working in financial services or other regulated industries preferred.
  • Relevant certifications such as CISSP, CCSP, GIAC, or Microsoft Security certifications preferred.
Additional Requirements
  • Experience developing security strategies, roadmaps, and architecture standards.
  • Familiarity with emerging AI-driven phishing, impersonation, and social engineering threats.
  • Strong collaboration skills and ability to work across Cyber Security, GTS, and Engineering organizations.
  • Ability to translate security risks into actionable technical solutions.
Work Requirement
  • Hybrid work model in accordance with company policy.
  • Ability to collaborate effectively with global teams across multiple time zones.
  • Standard business hours with flexibility to support critical security incidents and initiatives when required.

Salary Range:

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.