Head of Cyber & Information Security Oversight; SVP
Listed on 2025-12-15
-
IT/Tech
Cybersecurity, Information Security, IT Project Manager, IT Consultant
Head of Cyber & Information Security Oversight (SVP) Organization:
State Street
Location:Quincy, MA (On-site)
Description:About the job
SVP, Head of Cyber & Information Security Oversight
Why this role is important to us
Enterprise Technology Risk Management (ETRM) is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Cyber and Technology Risks across the enterprise.
ETRM plays an important role in the overall success of the organization, and our mission is to establish a world class Technology Risk Management program that aligns business and technology risk to enable effective decision making.
The organization is going through a significant transformation, and you will lead key cyber risk assessments on material projects and ensure the identified risks are being prudently managed.
This position will also include providing thought leadership and support to both your peers in ETRM and your stakeholders in the business and corporate areas.
You will need to periodically participate in meetings with our key regulators and provide support and advice to your stakeholders during regulatory exams and regulatory finding validations.
Who We Are Looking ForWe are looking for a proven Cyber and Information Security Risk Leader with more than 15 years of experience in the financial services and/or technology industry.
The qualified candidate will have a combination of:
- Deep Technical
Experience:
Hands‑on Cybersecurity leader in roles as a CISO or CTRO at comparable organizations with a global footprint or at a Deputy CISO level in a G‑SIB. The candidate will be well versed in identifying, assessing, managing and monitoring cyber risks across several domains such as Identity and Access, Information Protection, Threat and Vulnerability Management, Cyber Incident and Response, Application security, Secure configuration, Security Architecture and Cyber Risks related to Third parties. - Strong Business background:
Proven capability for translating this technical understanding into business risk to be able to provide guidance to and challenge senior level IT executives such as the group level State Street CIO, CISO and CTO. The individual will also serve as an advisor to the Head of ORM, Group CRO, regional CROs and the State Street Board of Directors to manage Cyber Risk adequately. - Strong Executive Presence: effectively communicate with senior executives at the EVP and C‑level, the Board and with regulators globally to foster confidence in the Bank’s risk management capabilities and to drive enhancements where needed. Candidates must demonstrate strong initiative, be able to perform well under pressure and be capable of managing multiple and diverse assignments.
The successful candidate will report into the Global Head of Technology and Cyber Risk, who reports to the Chief Operational and Technology Risk Officer within the Operational Risk Management second line function.
They will lead, guide and mentor a team of seasoned ETRM Cyber risk professionals to provide Second Line of Defense (SLoD) oversight, review and challenge on Global Cybersecurity and Global Technology Services First Line Organization.
The ETRM function is currently being enhanced, and the role is expected to provide significant expertise and experience to shape the Cybersecurity governance function, aligned to industry peers and leading practices.
What You Will Be Responsible For- Establish and Operate the global Cybersecurity Risk Oversight function in ETRM.
- Be a risk advisor and challenge function to the State Street Global CISO function and program.
- Establish State Street’s Cyber Risk Appetite, with corresponding policies and Metrics and thresholds, reporting breaches, escalating exceptions and challenging risk acceptances and provide guidance on improving the risk position to support the business.
- Be an acknowledged thought leader in the industry, with a strong understanding of attributes of an effective Cybersecurity program at peer organizations.
- Analytics and Reporting
- Establish an analytics capability to provide cyber risk insights, leveraging AI for greater effectiveness.
- Develop risk reports…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).