About the Role
The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, acting as a trusted advisor and change agent. This role is crucial for managing cyber risk across State Street’s business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm’s cyber risk culture.
Responsibilities
- Provide cyber risk management oversight to lines of business and legal entities.
- Lead a team focused on cyber advisory services, application- and service-level threat models, and executing a cyber book of work.
- Deliver metrics and cyber-driven content to support business decision-making.
- Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.
- Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.
- Collaborate with key stakeholders to identify information assets and assess protection needs requirements for the entire line of business and legal entity.
- Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required.
- Own application- and service-level threat models.
- Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.
- Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums.
- Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership.
- Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis.
Requirements
- Strong technical background with the ability to understand emerging technologies, their purpose, security requirements, and benefits.
- Strong cyber controls analyst capable of correlating the firm’s cyber risk taxonomy to applicable business processes.
- Ability to conclude on residual cyber risks aligned to business functions and critical business services with practitioner-level depth in at least two focus areas.
- Understanding of threats and risk mitigations.
- Ability to perform cyber risk assessments at the application, platform, and system levels.
- Ability to recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness.
- Demonstrate practitioner-level depth across several cyber technical skills domains.
- Ability to assess areas against a proficiency scale and answer probing questions and coach others.
- Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.
- Demonstrate an understanding of model risk, frontier models, and the risk management around them.
- Show strong technical expertise in at least two focus areas across Multi-Cloud, AI, Machine Learning, Blockchain, Software Supply Chain, and Quantum Computing.
- Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.
- Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.
- Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001).
- Understanding of issue management, triage, remediation tracking, and residual-risk scoring.
- Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.
- Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.
- Translate technical risk into clear, actionable business terms for both technical and non-technical audiences.
- Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.
- Experience working with dashboards and data-mining tools to build cyber risk profiles.
- Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.
- Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.
Skills
- Cyber risk management
- Threat modeling
- Cyber advisory services
- Risk assessment
- Information security
- Risk management
- Cyber incident and response management
- Cyber controls analysis
- Cyber reporting
- Cloud security (Azure, AWS, hybrid, multi-cloud)
- Networking and network security
- Security architecture
- Operating systems security
- Cryptography
- Encryption
- Key management
- Vulnerability management
- Cyber resiliency
- Incident response
- Data classification
- Data protection
- Secure communication protocols
- Identity and Access Management (IAM)
- Privileged Access management
- Secure SDLC
- Secure engineering
- DevSecOps
- Third-party risk management
- Supply chain security
- Security operations
- Security monitoring
- SIEM
- Generative AI risk
- Model risk management
- AI risk management
- Machine Learning
- Blockchain
- Software Supply Chain security
- Quantum Computing
- Agentic AI
- Agile methodology
- Data mining
- NIST CSF 2.0
- NIST SP 800-53
- ISO 27001
- Analytical skills
- Communication skills (written and verbal)
- Research skills
- Organizational skills
- Interpersonal skills
- Active listening
- Teamwork
Location
- State Street
Work Type
- Full-time
Experience Level
- Vice President
- 5+ years working with business leadership across enterprise projects
Education Level
- Bachelor’s degree in Computer Science, or a related technical field — or equivalent work-aligned experience.
- CISSP or CISM required.
- CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued.
- Emerging-tech / AI security certification a strong plus
Salary/Compensations
- $120,000 - $202,500 Annual
Benefits
- Retirement savings plan (401K) with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
About the Company
- Institutional investors rely on State Street to help them manage risk, respond to challenges, and drive performance and profitability.
- State Street is committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- Benefits include inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks.
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
