368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$120k – $203k per year
Location
In office (United States, Toronto)
Seniority
Architect · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
State Street is a major American financial services and bank holding company headquartered in Boston, Massachusetts. As one of the world's largest custodian banks and asset managers, it provides comprehensive asset servicing, fund administration, foreign exchange, and investment management through its State Street Global Advisors division.

Who We Are Looking For

The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting intothe Senior BISO (MD). The VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework.

BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting.

The Non-Technical Dimension: Trusted Advisor & Change Agent

The VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives, andbe able to present to the highest levels of leadership,with the appropriate blendof technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing changeto lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifieskey stakeholders, establishesnew relationships, and coordinates resources and Security Guardians to brokerthe right conversations across GCS and the business.

The Technical Dimension

This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. The VP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on the residual cyber risksaligned to business functions and critical business services, with practitioner-level depth in at least two focus areas. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness.

Why this role is important to us

Global Cybersecurity (GCS) manages cyber risk across State Street’s business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm’s cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units - providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization.

What You Will Be Responsible For

  • Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.

  • Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.

  • Collaborate with key stakeholders to identify information assets and assess the protection needs requirements for the entire line of business and legal entity.

  • Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required; own application- and service-level threat models.

  • Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.

  • Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums.

  • Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership.

  • Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis.

Technical Judgment & Knowledge

Aligned to the GCS BISO cyber technical skills model, the VP should demonstrate practitioner-level depth across several of the domains below and be able to answer probing questions and coach others. Assess each area against the proficiency scale at the end of this document.

Core Technologies

  • Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)

  • Networking and network security

  • Security architecture fundamentals and control design effectiveness

  • Operating systems

Supporting Processes

  • Cryptography, encryption, and key management

  • Patching and vulnerability management

  • Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)

  • Data classification and data protection

  • Secure communication protocols

  • Identity and Access Management (IAM) / Privileged Access concepts

  • Secure SDLC, secure engineering, and DevSecOps

  • Third-party & supply chain security (vendor assessments, shared responsibility models)

  • Security operations & monitoring (SOC / SIEM awareness, KPIs, posture reporting)

Emerging Technology & AI

The BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to:

  • Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.

  • Demonstrate an understanding of model risk, frontier models, and the risk management around them.

  • Show strong technical expertise in at least two focus areas across Multi-Cloud, AI, Machine Learning, Blockchain, Software Supply Chain, and Quantum Computing.

  • Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.

Risk Management

  • Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.

  • Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001).

  • Understanding of issue management, triage, remediation tracking, and residual-risk scoring.

What We Value

These skills will help you succeed in this role:

  • Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.

  • Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.

  • Translate technical risk into clear, actionable business terms for both technical and non-technical audiences.

  • Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.

  • Experience working with dashboards and data-mining tools to build cyber risk profiles.

  • Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.

  • Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.

Education & Preferred Qualifications

  • Bachelor’s degree in Computer Science, or a related technical field - or equivalent work-aligned experience.

  • CISSP or CISM required. CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued.

  • Emerging-tech / AI security certification a strong plus - e.g., ISACA Advanced in AI Security Management (AAISM), the first AI-centric security management credential (for CISM/CISSP holders), covering AI Governance & Program Management, AI Risk Management, and AI Technologies & Controls.

  • 5+ years working with business leadership across enterprise projects;

  • Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork.

Salary Range:

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Toronto
$24k – $64k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chennai
Python
Scala
SQL
TypeScript
JavaScript
Java
Python
pySpark
Java
Spring Boot
Databases
Apache Kafka
Databricks
AI/ML
AI Agents
Copilot
Google ADK
LLM
NLP
Prompt Engineering
Spark
Devin
Model Context Protocol
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
OpenShift
GitHub
Analytics
ETL/ELT
Apply
$42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
$12k – $35k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
Databases
MySQL
Oracle
PostgreSQL
AI/ML
AI Agents
DevOps
AIOps
Amazon EC2
AWS
CI/CD
CloudFormation
GitHub Actions
Kubernetes
Terraform
Amazon CloudWatch
Amazon S3
GitHub
IAM
Apply
$54k – $159k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Singapore
Bash
PowerShell
Python
DevOps
Ansible
AWS
Azure
Chef
Docker
Hyper-V
Incident Management
Kubernetes
Puppet
Red Hat
Terraform
VMWare
Windows Server
Apply
Backend Engineer 1 day ago
$45k – $57k per year • In office • Full-Time • 3+ years exp • Tokyo
Python
TypeScript
JavaScript
Python
FastAPI
Databases
PostgreSQL
Frontend
Next.js
React.js
DevOps
Amazon EC2
AWS
AWS CDK
CI/CD
Docker
GitHub Actions
Vercel
Amazon CloudWatch
Amazon S3
GitHub
IAM
Management
Linear
Apply
$17k – $41k per year (Estimated) • In office • Full-Time • 6+ years exp • Bengaluru • Hyderabad
Python
SQL
Analytics
Power BI
Management
Power Automate
Apply
$34k – $72k per year (Estimated) • In office • Full-Time • 16+ years exp • Bachelor's Degree • Bengaluru
Databases
Databricks
AI/ML
Feature Store
OpenAI
Cybersecurity
GDPR
Apply
$49k per year • Remote/Hybrid • Full-Time • 6+ years exp • Kraków • Gdańsk
Bash
C#
JavaScript
PowerShell
Python
SQL
DevOps
Azure
CI/CD
Rest API
QA
Gatling
JMeter
k6
Playwright
Selenium
Apply
$21k – $41k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad • Bengaluru
Python
SQL
Databases
Oracle
AI/ML
Copilot
LangChain
Prompt Engineering
RAG
Semantic Search
OpenAI
Semantic Search
DevOps
Azure
CI/CD
Git
GitHub
Analytics
ETL/ELT
Apply
In office • Full-Time • 3+ years exp • Bachelor's Degree • Hangzhou
Java
Python
AI/ML
AI Agents
LangChain
LangGraph
LLM
Prompt Engineering
RAG
DevOps
Azure
CI/CD
Docker
Git
Kubernetes
Rest API
Apply
In office • Internship • Toronto
SQL
Visual Basic
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • Toronto
Go
JavaScript
Ruby
Scala
Apply
$71k – $165k per year (Estimated) • In office • Internship • Bachelor's Degree • Toronto
Go
JavaScript
Ruby
Scala
Apply
$73k – $92k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Toronto
DevOps
SLI/SLO/SLA
Analytics
Power BI
Tableau
Apply
$99k – $211k per year (Estimated) • In office • 15+ years exp • Toronto
Databases
Amazon Redshift
Apache Kafka
Databricks
Google BigQuery
Snowflake
AI/ML
AI Agents
Amazon SageMaker
dbt
LLM
Model Context Protocol
RAG
DevOps
Amazon Kinesis
AWS
Analytics
Tableau
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.