About the Role
The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street. This role supports both traditional technology environments and emerging digital asset services, assessing blockchain and digital asset risk, and translating complex topics into clear control expectations for stakeholders. The VP BISO acts as a trusted advisor, strategic change agent, and thought leader, building trust with senior executives and influencing change to reduce residual risk.
Responsibilities
- Lead a small team to support aligned business stakeholders while focusing on increased cyber capabilities; execute a cyber book of work aligned to the business.
- Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.
- Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.
- Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required.
- Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.
- Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory.
- Prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership.
- Advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services.
- Challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience.
- Coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations.
Requirements
- Practitioner-level depth across several of the core technology and supporting process domains.
- Understand how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.
- Understanding of issue management, triage, remediation tracking, and residual-risk scoring.
- Ability to assess digital asset risks across custody, key management, wallet administration, HSM usage, cold storage, smart contracts, third parties, monitoring, incident response, operational resilience, and privileged access.
- Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.
- Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.
- Translate technical risk into clear, actionable business terms for both technical and nontechnical audiences.
- Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.
- Experience working with dashboards and data-mining tools to build cyber risk profiles.
- Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.
- Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.
- Applies sound judgment when evaluating emerging technologies and can distinguish material risk from theoretical concerns.
Skills
- Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)
- Networking and network security
- Security architecture fundamentals and control design effectiveness.
- Blockchain and distributed ledger technology fundamentals, including public and permissioned networks, transaction lifecycle concepts, digital asset infrastructure, and tokenization models.
- Digital asset custody technologies, including wallet architecture, HSMs, MPC concepts, cold storage, warm/hot wallet risk, transaction signing, and private key protection.
- Cryptography, encryption, and key management
- Patching and vulnerability management
- Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)
- Data classification and data protection
- Secure communication protocols
- Identity and Access Management (IAM) / Privileged Access concepts
- Secure SDLC, secure engineering, and DevSecOps
- Software Supply Chain Security
- Third-party & supply chain security (vendor assessments, shared responsibility models)
- Security operations & monitoring (SOC / SIEM awareness)
- Smart contract security review, including threat modeling, secure design, independent audit coverage, vulnerability remediation, change governance, and privileged administration risk
- Digital asset custody control assessment, including HSM-backed key protection, cold storage procedures, key generation, backup, recovery, rotation, destruction, transaction approval workflows, and non-repudiation
- On-chain monitoring and digital asset incident response, including suspicious activity alerting, fraud indicators, wallet compromise scenarios, unauthorized transaction response, and escalation procedures.
- Generative AI risk articulation
- Frontier model AI risk management
- Cloud Security
- Digital Assets
- AI
- Identity & Access Management
- Application Security
- Software Supply Chain Security
- Agentic AI use cases and deployments
- Analytical skills
- Communication (written and verbal)
- Research skills
- Organizational skills
- Interpersonal skills
- Active listening
- Dependability
- Teamwork
Location
- Primary location specified
Work Type
- Full-time
Experience Level
- Vice President
- At least 6 years of information security experience in an operational or analytical capacity
- 4+ years within financial services
- Qualitative cyber risk analysis experience highly preferred
Education Level
- Bachelor’s degree in computer science, Information security and assurance, or a related technical field or equivalent work aligned experience.
- CISSP/CISP preferred.
- Blockchain and digital asset security certifications (e.g., Certified Blockchain Security Professional (CBSP)) are desirable.
Salary/Compensations
- $120,000 - $202,500 Annual
Benefits
- Retirement savings plan (401K) with company match
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
- Paid-time off including vacation, sick leave, short term disability, and family care responsibilities
- Access to our Employee Assistance Program
- Incentive compensation including eligibility for annual performance-based awards
- Eligibility for certain tax advantaged savings plans
About the Company
- Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability.
- We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
- We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential.
- As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.
- Join us in shaping the future.
Equal Opportunity
- As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
