About the Role
This role leads the modernization of our security engineering control landscape, acting as a program manager and GRC strategist within the Defensive Engineering organization. It bridges security engineering, risk, compliance, and audit teams to ensure security controls are measurable, effective, and aligned with business and regulatory requirements.
Responsibilities
- Lead strategic initiatives to modernize and mature the security engineering control landscape across multiple cybersecurity domains.
- Define control objectives, success criteria, KPIs, and metrics that measure control effectiveness, coverage, and risk reduction.
- Partner with engineering, risk, compliance, legal, and audit teams to drive control implementation, remediation, and continuous improvement.
- Translate regulatory, audit, and risk requirements into technical roadmaps and executable engineering programs.
- Drive complex cross-functional programs from strategy through execution while providing executive-level reporting and governance.
Requirements
- Experience leading large-scale cybersecurity, risk, compliance, or security transformation programs.
- Strong understanding of security controls, governance frameworks, regulatory requirements, and risk management practices.
- Ability to bridge technical engineering teams with risk, compliance, and audit stakeholders.
- Strong program management, executive communication, stakeholder management, and decision-making skills.
- Experience in financial services or other highly regulated industries preferred.
- Ability to influence and drive outcomes across engineering, risk, compliance, and executive stakeholders.
- Experience developing governance frameworks, control libraries, KPIs, KRIs, and executive reporting.
- Knowledge of cybersecurity operations, security engineering, and enterprise security controls.
Skills
- Product Management
- Program Management
- GRC Strategy
- Security Controls
- Risk Management
- Compliance
- Audit
- NIST
- CIS Controls
- ISO 27001
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- 10+ years of experience in cybersecurity, product management, program management, risk management, or governance functions.
- Principal level experience
Education Level
- Bachelor's degree in Computer Science, Information Security, Engineering, Business, or a related field.
- CISSP, CISM, CRISC, PMP, or equivalent certifications preferred.
Salary/Compensations
- $120,000 - $202,500 Annual
Benefits
- Retirement savings plan (401K) with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
About the Company
- Institutional investors rely on State Street to help them manage risk, respond to challenges, and drive performance and profitability.
- Committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- Offers inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks.
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
- It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
