State Street
SVP, Head of Cyber & Information Security Oversight
Why this role is important to us
Enterprise Technology Risk Management (ETRM) is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Cyber and Technology Risks across the enterprise.
ETRM plays an important role in the overall success of the organization, and our mission is to establish a world class Technology Risk Management program that aligns business and technology risk to enable effective decision making. The organization is going through a significant transformation, and you will lead key cyber risk assessments on material projects and ensure the identified risks are being prudently managed. This position will also include providing thought leadership and support to both your peers in ETRM and your stakeholders in the business and corporate areas. You will need to periodically participate in meetings with our key regulators and provide support and advice to your stakeholders during regulatory exams and regulatory finding validations.
We are looking for a proven Cyber and Information Security Risk Leader with more than 15 years of experience in the financial services and/or technology industry. The qualified candidate will have a combination of:
The successful candidate will report into the Global Head of Technology and Cyber Risk, who reports to the Chief Operational and Technology Risk Officer within the Operational Risk Management second line function. They will lead, guide and mentor a team of seasoned ETRM Cyber risk professionals to provide Second Line of Defense (SLoD) oversight, review and challenge on Global Cybersecurity and Global Technology Services First Line Organization. The ETRM function is currently being enhanced, and the role is expected to provide significant expertise and experience to shape the Cybersecurity governance function, aligned to industry peers and leading practices.
+ Be a risk advisor and challenge function to the State Street Global CISO function and program.
+ Establish State Street’s Cyber Risk Appetite, with corresponding policies and Metrics and thresholds, reporting breaches, escalating exceptions and challenging risk acceptances and provide guidance on improving the risk position to support the business
+ Be an acknowledged thought leader in the industry, with a strong understanding of attributes of an effective Cybersecurity program at peer organizations
+ Establish an analytics capability to provide cyber risk insights, leveraging AI for greater effectiveness
+ Develop risk reports customized to the business needs of legal entities and regions to drive risk reduction in a cost-effective way.
+ Lead or co-Chair various senior governance forums like the Cybersecurity Risk Committee and the Vulnerability Governance Forum that manage Cybersecurity risk to State Street
+ Communicate and drive effective implementation of ETRM risk management policies, framework, tools, guidelines and standards across the business ensuring cyber risks are identified and managed effectively.
+ Ensuring cyber risks and non-compliance with internal and external standards are proactively identified, prudently managed, and effectively challenged
+ Identifying/assessing/controlling/monitoring risks and supporting FLOD in planning/executing controls and additional compensating controls
+ Review and challenge the first line cyber controls assurance program and the constituent cyber processes
+ Provide challenge to the EVPs leading the Cyber Enterprise Processes and foster deeper and integrated FLOD/SLOD relationships and embedded, proactive risk management
+ Advise FLOD in prioritization of risks, risk initiatives, risk mitigation alternatives
+ Lead second line regulatory interaction for Cyber Risk with regulators, including the FCA/PRA, HKMA, MAS, APRA and ECB, including resolution of issues and concerns
+ Be a thought leader for managing emerging Cybersecurity risks to provide credible risk management guidance to the regulators
+ Collaborate with and support regional) and Business Unit Risk Management peers in matters related to cyber and information security risks
+ Develop and deliver the ETRM Cybersecurity annual Book of Work (risk assessments, continuous monitoring, issues management and reporting) through the established risk leads within the team while leveraging the ETRM India GCC.
+ Coordinate across multiple risk types in Operational Risk Management, like Data Risk, Fraud and Third-Party Risk programs. Utilize available Enterprise Risk and Operational risk management tools (NBPRA, MRI, RCSA, KRI’s, Incident data, Loss event data) in conjunction with other environmental changes to proactively monitor the control environment and identify and address potential weaknesses and/or gaps in a timely manner
+ Keep abreast of new products, services, technologies and applications as well as their respective impact on the organization’s risk profile
These skills will help you succeed in this role
Are you the right candidate? Yes!
We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don’t necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.
$225,000 - $337,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Job ID: R-780933