State Street Corporation

Data Protection, Managing Director

State Street Corporation$170K — $282K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or related discipline; advanced degree preferred.
  • 15+ years of leadership experience in cybersecurity and data protection within large, regulated organizations.
  • Strong understanding of data governance, classification, DLP, encryption, and access controls.
  • Proven ability in securing cloud-native data ecosystems and understanding AI security risks.
  • Relevant certifications such as CISSP, CISM, CCSP, or similar are strongly preferred.

Responsibilities

  • Define and execute the firm's long-term Enterprise Data Protection Strategy.
  • Establish frameworks for sensitive data protection across its lifecycle.
  • Drive modern security models to protect data, regardless of location or technology.
  • Develop metrics and reporting to quantify data risk and control effectiveness.
  • Lead initiatives to understand and mitigate data risk at scale.

Benefits

  • Opportunity to lead the enterprise data protection strategy in a global financial institution.
  • Executive-level visibility across Security, Technology, and Data organizations.
  • Direct influence on the firm’s AI and cloud transformation efforts.
  • Inclusive culture fostering innovation and engineering excellence.
Full Job Description
Who we are looking for

We are looking for a Data Protection Managing Director reporting directly to the SVP of Data and AI Security. The Managing Director, Data Protection is a senior leadership role responsible for defining, governing, and scaling the firm's enterprise-wide data protection strategy. This leader will establish a modern, risk-based data security program that enables the organization's digital, cloud, AI, and data transformation objectives while protecting the firm's most critical information assets. The role requires a visionary security leader who can balance business enablement with strong security outcomes. The successful candidate will drive the evolution from traditional data protection approaches toward a modern, intelligence-driven program focused on data discovery, classification, retention, access governance, AI security, and automated protection controls.

The Managing Director will serve as the firm's foremost authority on data security and protection, partnering across Security, Engineering, Data, Privacy, Legal, Risk, Compliance, Infrastructure, and Business teams to ensure security is embedded into platforms, pipelines, governance frameworks, and delivery processes.

What you will be responsible for

  • Define and execute the firm's multi-year Enterprise Data Protection Strategy, ensuring alignment with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.


  • Establish a comprehensive framework for protecting sensitive information throughout its lifecycle, including:


  • Data discovery


  • Classification


  • Access governance


  • Retention and disposal


  • Encryption and key management


  • Monitoring and protection controls


  • Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.


  • Develop executive-level metrics and reporting that quantify data risk, control effectiveness, and remediation progress.


  • Lead enterprise initiatives to know, understand, and reduce data risk at scale.


  • Establish programs to identify and continuously inventory:


  • Sensitive customer and firm data


  • Regulated and restricted information


  • Secrets and credentials


  • Legacy data stores


  • High-risk repositories


  • Shadow data environments


  • Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.


  • Develop actionable intelligence that enables business leaders and technology teams to understand where sensitive data resides and how it is exposed.


  • AI Data security & Protection - Lead the firm's strategy for protecting data from emerging AI-related threats and misuse.


  • Establish controls and protections against:


  • Prompt injection attacks


  • Model misuse


  • Data leakage through AI systems


  • Retrieval-augmented generation (RAG) data exposure


  • Adversarial AI attacks


  • Model manipulation


  • AI-enabled social engineering


  • Partner closely with AI, Engineering, and Security Architecture teams to ensure AI capabilities are deployed using:


  • Secure-by-default configurations


  • Approved usage patterns


  • Security guardrails


  • Automated controls


  • Enterprise-approved AI platforms


  • Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.


  • Establish rigorous enterprise-wide data lifecycle management and retention programs designed to minimize unnecessary data exposure.


  • Drive initiatives to:


  • Eliminate obsolete and redundant data


  • Reduce data longevity where business value no longer exists


  • Improve defensibility and regulatory compliance


  • Reduce attack surface through data minimization


  • Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.


  • Ensure retention policies are enforced through technology controls rather than manual processes whenever possible.


  • Data Access Governance - Lead enterprise efforts to analyze, govern, and continuously monitor access to sensitive information.


  • Develop and implement:


  • Data-centric access control models


  • Risk-based authorization frameworks


  • Privileged access controls


  • Continuous entitlement reviews


  • Excessive permissions identification


  • Access anomaly detection


  • Partner with Identity and Access Management teams to strengthen least-privilege principles across business and technology environments.


  • Ensure access decisions are informed by data sensitivity, business context, user risk, and regulatory requirements.


  • Establish a comprehensive view of the firm's data protection control environment.


  • Conduct enterprise-wide assessments to:


  • Map existing controls


  • Identify security gaps


  • Measure control effectiveness


  • Assess residual risk


  • Prioritize remediation activities


  • Develop risk-based roadmaps that focus resources on the most significant data protection exposures.


  • Drive accountability across technology and business stakeholders to ensure timely remediation of material risks.


  • Partner closely with the Data organization to ensure security is embedded throughout the data ecosystem.


  • Influence the design of:


  • Data platforms


  • Data pipelines


  • Analytics environments


  • Governance frameworks


  • AI and ML platforms


  • Data products


  • Promote security-by-design principles that enable innovation while reducing operational friction.


  • Establish scalable security patterns that integrate directly into engineering workflows, automation pipelines, and platform services.


  • Lead strategic modernization initiatives supporting the future state of data security.


  • Drive improvements across:


  • Enterprise encryption programs


  • Key management services


  • Automated key rotation


  • Secrets management


  • Ephemeral infrastructure


  • Machine identity controls


  • Partner with Infrastructure, Cloud Engineering, and Enterprise Architecture teams to strengthen cryptographic hygiene and reduce operational risk.


  • Develop forward-looking strategies that support emerging technology requirements and evolving regulatory expectations.


  • Ensure data protection capabilities align with applicable regulatory and industry expectations, including:


  • FFIEC


  • NYDFS


  • GDPR


  • SEC requirements


  • NIST frameworks


  • ISO standards


  • Serve as the executive leader for data protection reviews involving regulators, auditors, clients, and control assurance functions.


  • Provide defensible and transparent reporting on the firm's data protection posture and remediation activities.


What we value

These skills will help you succeed in this role:

  • Executive Leadership & Stakeholder Engagement - Serve as a trusted advisor to executive leadership, including the CISO, CIO, CDO, Risk leadership, and business executives.


  • Translate complex technical and data risks into clear business decisions and investment priorities.


  • Build strong partnerships across Security, Technology, Data, Legal, Privacy, Compliance, and Risk organizations.


  • Champion a culture where protecting sensitive data is viewed as a business imperative rather than a compliance exercise.


  • Team Leadership & Development - Build and lead a high-performing global Data Protection organization.


  • Develop teams responsible for:


  • Data Security Engineering


  • Data Discovery & Classification


  • Data Governance Security


  • Data Loss Prevention


  • Data Access Governance


  • Encryption & Key Management


  • Mentor future leaders and establish a culture focused on innovation, accountability, automation, and measurable outcomes.


  • Recognized leader in Data Security and Data Protection.


  • Strategic thinker with the ability to execute and deliver measurable outcomes.


  • Strong business acumen and executive presence.


  • Deep understanding of modern cloud, AI, and data architectures.


  • Passion for automation, scale, and simplification.


  • Ability to influence organizational boundaries and drive enterprise-wide change.


  • Data-driven decision maker with strong risk management instincts.


  • Customer-first mindset focused on trust, resilience, and protection of critical information assets.


Education and Preferred Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or related discipline.


  • Advanced degree preferred.


  • Relevant certifications such as CISSP, CISM, CCSP, CDPSE, or cloud security certifications strongly preferred.


  • 15+ years of progressive leadership experience in cybersecurity, data protection, data security, or related disciplines.


  • Demonstrated success leading enterprise-scale data protection programs within large, highly regulated organizations.


  • Deep expertise in data discovery, classification, DLP, encryption, key management, data governance, and access controls.


  • Proven experience securing cloud-native data ecosystems and modern data platforms.


  • Strong understanding of AI security risks and data protection requirements associated with GenAI and AI-enabled business processes.


  • Experience partnering with Data, Engineering, Privacy, Legal, Compliance, and Risk organizations.


  • Track record of driving large-scale transformation and modernization initiatives.


  • Experience presenting to executive leadership, boards, regulators, and auditors.


What we offer

  • Opportunity to define and lead the enterprise data protection strategy for a global systemically important financial institution.


  • Executive-level visibility and influence across Security, Technology, and Data organizations.


  • Direct impact on the firm's AI, cloud, and data transformation journey.


  • Competitive compensation and comprehensive benefits.


  • Collaborative culture focused on innovation, engineering excellence, and client trust.


Salary Range:
$170,000 - $282,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street Corporation

State Street Corporation Careers

Join the dynamic team at State Street Corporation, a leading financial services provider known for its commitment to innovation, leadership, and professional growth. As a global powerhouse in investment management and servicing, we offer unparalleled job opportunities that propel your career to new heights.

Work You’ll Do

At State Street Corporation, you’ll be part of a culture that values diversity, leadership, and continuous professional development. Engage in work that transforms the financial landscape and helps our clients achieve their investment goals. Our team at State Street is at the forefront of combining industry expertise with cutting-edge technology to deliver exceptional service and results.

Explore Our Job Opportunities

Whether you’re looking for an entry-level position or a senior role, State Street Corporation offers a range of career paths in areas such as asset management, data analytics, finance, and technology. Our hiring process is designed to identify and nurture talent, focusing on your skills and potential. Prepare your resume, ace the interview, and join a team that’s committed to your career growth.

Internship Programs

Kickstart your career with a State Street internship. Our programs provide hands-on experience, networking opportunities, and professional mentoring in a real-world setting. Interns at State Street gain valuable insights and skills that make them competitive candidates for full-time positions within our company.

Benefits and Growth

State Street Corporation is dedicated to the growth and well-being of our employees. We offer a comprehensive benefits package that supports both your professional and personal life. From advanced career training and leadership development programs to health and wellness benefits, we ensure that our team members have the resources they need to succeed.

Inclusive Culture and Diversity

We pride ourselves on fostering an inclusive environment where every employee can thrive. Diversity is not just embraced; it’s celebrated. At State Street, you’ll work alongside a diverse group of professionals who bring a wide range of perspectives and ideas to the table. Our diversity training programs are designed to enhance collaboration and innovation across our global team.

Stay Connected

Join Our Team Discover the career you’ve always wanted by exploring the job opportunities at State Street Corporation. We look for driven, curious, and innovative team players who are ready to make an impact. Search State Street jobs now and find the position that best matches your skills and interests. Keep Up to Date Stay informed with career tips, insider perspectives, and industry-leading insights you can use today—all from the people who work here. Our careers blog provides you with the latest trends, tools, and advice to keep you ahead in your professional journey.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at State Street Corporation, where your career development is our priority. Join State Street Corporation and be part of a team that values innovation, leadership, and a commitment to excellence. Your future in the financial services industry starts here.
Learn more about State Street Corporation
Size
39,335 employees
Market Cap
$28.4 billion
Industry
Net Income
$2.4 billion
Founded
1792
5 Year Trend
-4.9%
NASDAQ

Similar Jobs

More Jobs at State Street Corporation

More Information Technology Jobs

Find similar Data Protection, Managing Director jobs: