State Street Corporation

Business Information Security Officer- AVP

State Street Corporation$90K — $157K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science or related field, or equivalent experience.
  • CISSP or CISM certification strongly preferred; others like CRISC, CISA valued.
  • 8+ years of progressive cybersecurity and risk leadership experience.
  • Technical background preferred in SOC, operations, networking, or engineering.
  • Proven ability to influence executives and communicate technical risk in business terms.

Responsibilities

  • Partner with senior leaders for informed decision-making and prioritization.
  • Manage risks in line with business's risk appetite through ongoing engagement.
  • Collaborate with stakeholders to identify and assess information protection needs.
  • Conduct cyber risk assessments to identify vulnerabilities and recommend protections.
  • Represent global cybersecurity in business control and risk committees.
  • Prepare and deliver executive-level presentations on cyber risk outcomes.
  • Report significant information security risk changes to management.

Benefits

  • 401K retirement savings plan with company match.
  • Comprehensive insurance coverage including health and life.
  • Paid time off for vacation, sick leave, and family responsibilities.
  • Access to Employee Assistance Program for support.
  • Incentive compensation eligibility based on performance.
Full Job Description

Who We Are Looking For

TheAssistant Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense. The AVP - BISO integrates into small team focused on providing cyber advisory services, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework. 

BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting.

The Non-Technical Dimension: Trusted Advisor & Change Agent

The AVP - BISO is a change agent and thought leader. They must build trust through information and transparency with senior executives, be able to present to the highest levels of leadership, with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled atinfluencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses.

The Technical Dimension

This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. The AVP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on theresidual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness. 

Why this role is important to us

Global Cybersecurity (GCS) manages cyber risk across State Street’s business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm’s cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units — providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization. 

What You Will Be Responsible For

·Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs. 

·Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership. 

·Collaborate with key stakeholders to identify information assets and assess the protection needs requirements for the entire line of business and legal entity. 

·Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required via GCS standards.

·Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums. 

·Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership. 

·Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis. 

Technical Judgment & Knowledge

Aligned to the GCS BISO cyber technical skills model, the AVP should demonstrate practitioner-level depth across at least two of the domains below and be able to answer probing questions and coach others. Assess each area against the proficiency scale at the end of this document. 

Core Technologies

·Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud) 

·Networking and network security 

·Security architecture fundamentals and control design effectiveness 

·Operating systems 

Supporting Processes

·Cryptography, encryption, and key management 

·Patching and vulnerability management 

·Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews) 

·Data classification and data protection 

·Secure communication protocols 

·Identity and Access Management (IAM) / Privileged Access concepts 

·Secure SDLC, secure engineering, and DevSecOps 

·Third-party & supply chain security (vendor assessments, shared responsibility models) 

·Security operations & monitoring (SOC / SIEM awareness, KPIs, posture reporting) 

Emerging Technology & AI

The BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to: 

·Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning. 

·Demonstrate an understanding of model risk, frontier models, and the risk management around them. 

Risk Management

·Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite. 

·Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001). 

·Understanding of issue management, triage, remediation tracking, and residual-risk scoring. 

What We Value

These skills will help you succeed in this role: 

·Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams. 

·Translate technical risk into clear, actionable business terms for both technical and non-technical audiences. 

·Experience working with dashboards and data-mining tools to build cyber risk profiles. 

·Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date. 

·Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information. 

Education & Preferred Qualifications

·Bachelor’s degree in computer science, or a related technical field — or equivalent work-aligned experience. 

·CISSP or CISM strongly preferred.CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued. 

·Eight or more years of progressive cybersecurity and risk leadership, including governance, risk, and compliance preferably within regulated financial services. Technical cybersecurity background i.e. SOC, operations, networking, engineering, etc. preferred.

·Demonstrated ability to influence executives, translate technical risk into business language, and operate across audit, regulatory, and third-party risk domains. Strong analytical and strong interpersonal skills including active listening, dependability, and teamwork. 

Salary Range:

$90,000 - $157,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit .

About State Street Corporation

State Street Corporation Careers

Join the dynamic team at State Street Corporation, a leading financial services provider known for its commitment to innovation, leadership, and professional growth. As a global powerhouse in investment management and servicing, we offer unparalleled job opportunities that propel your career to new heights.

Work You’ll Do

At State Street Corporation, you’ll be part of a culture that values diversity, leadership, and continuous professional development. Engage in work that transforms the financial landscape and helps our clients achieve their investment goals. Our team at State Street is at the forefront of combining industry expertise with cutting-edge technology to deliver exceptional service and results.

Explore Our Job Opportunities

Whether you’re looking for an entry-level position or a senior role, State Street Corporation offers a range of career paths in areas such as asset management, data analytics, finance, and technology. Our hiring process is designed to identify and nurture talent, focusing on your skills and potential. Prepare your resume, ace the interview, and join a team that’s committed to your career growth.

Internship Programs

Kickstart your career with a State Street internship. Our programs provide hands-on experience, networking opportunities, and professional mentoring in a real-world setting. Interns at State Street gain valuable insights and skills that make them competitive candidates for full-time positions within our company.

Benefits and Growth

State Street Corporation is dedicated to the growth and well-being of our employees. We offer a comprehensive benefits package that supports both your professional and personal life. From advanced career training and leadership development programs to health and wellness benefits, we ensure that our team members have the resources they need to succeed.

Inclusive Culture and Diversity

We pride ourselves on fostering an inclusive environment where every employee can thrive. Diversity is not just embraced; it’s celebrated. At State Street, you’ll work alongside a diverse group of professionals who bring a wide range of perspectives and ideas to the table. Our diversity training programs are designed to enhance collaboration and innovation across our global team.

Stay Connected

Join Our Team Discover the career you’ve always wanted by exploring the job opportunities at State Street Corporation. We look for driven, curious, and innovative team players who are ready to make an impact. Search State Street jobs now and find the position that best matches your skills and interests. Keep Up to Date Stay informed with career tips, insider perspectives, and industry-leading insights you can use today—all from the people who work here. Our careers blog provides you with the latest trends, tools, and advice to keep you ahead in your professional journey.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at State Street Corporation, where your career development is our priority. Join State Street Corporation and be part of a team that values innovation, leadership, and a commitment to excellence. Your future in the financial services industry starts here.
Learn more about State Street Corporation
Size
39,335 employees
Market Cap
$28.4 billion
Industry
Net Income
$2.4 billion
Founded
1792
5 Year Trend
-4.9%
NASDAQ

Similar Jobs

More Jobs at State Street Corporation

More Finance & Insurance Jobs

Find similar Business Information Security Officer- AVP jobs: