Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Business Information Security Officer-VP

$120k - $202.5k
Full-time

State Street

Who We Are Looking For

Global Cybersecurity (GCS) manages cyber risk across State Street's business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm's cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization.

The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into Senior BISO / MD. The VP BISO leads a small team focused on providing cyber advisory services, building application and service level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework.

This role is intended for a cyber risk leader who can support both traditional technology environments and emerging digital asset services. The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing, smart contract assurance, third-party platforms and broader blockchain based financial services solutions. The candidate should translate these topics into clear control expectations for business, technology, risk, compliance, legal, and regulatory stakeholders.

The Non-Technical Dimension: Trusted Advisor

The VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives and be able to present to the highest levels of leadership and, where relevant, external regulators with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifies key stakeholders, establishes new relationships, and coordinates resources and Security Guardians to broker the right conversations across GCS and the business.

The Technical Dimension

This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness. For digital asset services, this includes understanding digital asset custody models, cryptographic key management, HSM and MPC based signing controls, wallet security, smart contract risks, blockchain infrastructure dependencies, and response readiness for suspicious or unauthorized digital asset activity.

What You Will Be Responsible For

  • Lead a small team to support aligned business stakeholders while focusing on increased cyber capabilities; execute a cyber book of work aligned to the business.
  • Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.
  • Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.
  • Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required.
  • Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.
  • Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory.
  • Prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership.
  • Advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services.
  • Challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience.
  • The candidate should demonstrate familiarity with custody and key management models, including HSM-backed solutions, Multi-Party Computation (MPC), transaction-signing controls, and cold storage architectures.
  • Coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations.

Technical Judgment & Knowledge

Aligned to the GCS BISO cyber technical skills model, the VP should demonstrate practitioner-level depth across several of the domains below and be able to answer probing questions and coach others.

Core Technologies

  • Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)
  • Networking and network security
  • Security architecture fundamentals and control design effectiveness.
  • Blockchain and distributed ledger technology fundamentals, including public and permissioned networks, transaction lifecycle concepts, digital asset infrastructure, and tokenization models.
  • Digital asset custody technologies, including wallet architecture, HSMs, MPC concepts, cold storage, warm/hot wallet risk, transaction signing, and private key protection.

Supporting Processes

  • Cryptography, encryption, and key management
  • Patching and vulnerability management
  • Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)
  • Data classification and data protection
  • Secure communication protocols
  • Identity and Access Management (IAM) / Privileged Access concepts
  • Secure SDLC, secure engineering, and DevSecOps
  • Software Supply Chain Security
  • Third-party & supply chain security (vendor assessments, shared responsibility models)
  • Security operations & monitoring (SOC / SIEM awareness)
  • Smart contract security review, including threat modeling, secure design, independent audit coverage, vulnerability remediation, change governance, and privileged administration risk
  • Digital asset custody control assessment, including HSM-backed key protection, cold storage procedures, key generation, backup, recovery, rotation, destruction, transaction approval workflows, and non-repudiation
  • On-chain monitoring and digital asset incident response, including suspicious activity alerting, fraud indicators, wallet compromise scenarios, unauthorized transaction response, and escalation procedures

Digital Asset Custody, HSM & Cold Storage Focus

The candidate should not only understand blockchain concepts, but also the specific cyber and operational risks created by custody, wallet administration, private key protection, and transaction signing.

  • Understands the role of HSMs in cryptographic key generation, key storage, transaction signing, secure execution boundaries, tamper resistance, and separation of administrative duties.
  • Can evaluate cold storage models, including offline controls, key ceremony discipline, physical and logical access controls, recovery procedures, availability constraints, and operational errors that could delay or prevent transaction execution.
  • Can assess hot, warm, and cold wallet risk tradeoffs, including availability, automation, transaction velocity, fraud exposure, insider threat, disaster recovery, and business continuity considerations.
  • Can challenge private key lifecycle controls, including key generation, custody, backup, recovery, rotation, revocation, destruction, dual control, quorum approvals, and evidence of control operation.
  • Can evaluate transaction authorization controls, including maker/checker processes, approval thresholds, segregation of duties, privileged access, non-repudiation, monitoring, and exception handling.

Emerging Technology & AI

The BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to:

  • Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.
  • Demonstrate an understanding of model risk, frontier models, and the risk management around them.
  • Show strong technical expertise across Cloud Security, Digital Assets, AI, Identity & Access Management, Application Security, and Software Supply Chain Security.
  • Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.
  • Explain how digital asset risks differ from traditional application risks, including transaction finality, private key compromise, smart contract logic, custody dependencies, on-chain activity, and third-party platform concentration risk.

Risk Management

  • Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.
  • Understanding of issue management, triage, remediation tracking, and residual-risk scoring.
  • Ability to assess digital asset risks across custody, key management, wallet administration, HSM usage, cold storage, smart contracts, third parties, monitoring, incident response, operational resilience, and privileged access.

What We Value

These skills will help you succeed in this role:

  • Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.
  • Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.
  • Translate technical risk into clear, actionable business terms for both technical and nontechnical audiences.
  • Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.
  • Experience working with dashboards and data-mining tools to build cyber risk profiles.
  • Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.
  • Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.
  • Applies sound judgment when evaluating emerging technologies and can distinguish material risk from theoretical concerns.

Education & Preferred Qualifications

  • Bachelor’s degree in computer science, Information security and assurance, or a related technical field or equivalent work aligned experience.
  • CISSP/CISP preferred.
  • Blockchain and digital asset security certifications (e.g., Certified Blockchain Security Professional (CBSP)) are desirable. Practical experience with digital asset custody, wallet infrastructure, HSMs, MPC technologies, transaction signing controls, smart contracts, tokenization platforms, and blockchain security assessments is strongly preferred.
  • At least 6 years of information security experience in an operational or analytical capacity, with 4+ years within financial services; qualitative cyber risk analysis experience highly preferred.
  • Experience working with the NIST Cybersecurity Framework; AWS or Azure cloud security preferable but not required.
  • Experience with business concepts including finance, business requirements, compliance, and risk management.
  • Familiarity with applicable regional regulatory guidance across the jurisdictions the role supports
  • Practical experience with blockchain, digital assets, tokenization, custody, wallet infrastructure, smart contracts, HSM-based key management, cold storage, transaction signing controls, or digital asset platform risk assessments strongly preferred.
  • Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork.

Salary Range:

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit .

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Business Information Security Officer-VP in Clifton, NJ vacancy
  • $160k - $275k

     ...opportunity?Join RBC's newly established US Cyber Security & Resilience function as a strategic leader responsible...  ...security standards and initiatives across our US business units. As the Business Information Security Officer (BISO) (Global Security), you'll translate global... 
    Suggested
    Full time
    Flexible hours

    Royal Bank of Canada

    Jersey City, NJ
    10 hours ago
  • $110k - $188.75k

    Role SummaryThe Markets Business Unit Controller is responsible for partnering with the...  ...Unit Controller, involve FX Trading and Securities Lending.Who we are looking forWe are...  ...ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender... 
    Suggested
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Clifton, NJ
    1 day ago
  • $203.6k - $339.3k

    The Vice President, CSD Business Operations, is responsible for leading the strategic and operational functions that enable business performance...  ...insights, performance metrics, and reporting to support informed decision-making.Monitor organizational performance and identify... 
    Suggested
    Full time
    Contract work
    Local area
    Work from home

    CIGNA

    Bloomfield, NJ
    1 day ago
  • $10 per hour

     ...advice to your clients, then a role as a Business Relationship Manager is for you.As a...  ...>$10+MM revenueProficient in Microsoft Office tools including Outlook, Excel, Word, and...  ...disability needs. Visit our FAQs for more information about requesting an accommodation.Equal... 
    Suggested
    Work at office

    JP Morgan Chase

    Saddle Brook, NJ
    2 days ago
  • $200k - $225k

     ...the way, come join the Broadridge team.The VP, Head of Policy & Data Operations leads...  ...Custom Policy, Technology, Product, and Business stakeholders to ensure seamless policy execution...  ..., Economics, Data Analytics, Business, Information Systems, or a related field, or... 
    Suggested
    Full time
    Local area
    Remote work

    Broadridge

    Newark, NJ
    3 days ago
  •  ...management, sales, and sales delivery methods Participate in business calls and community activities to develop new business...  ...without loss of efficiency or composure Ability to exchange information with others clearly and concisely, to present ideas, facts, and... 

    ION Financial MHC INC

    Englewood, NJ
    a month ago
  • $120k - $202.5k

     ...analytics based services and solutions to business units across State Street. Our mission...  ...our business partners to make timely and informed decisions.What you will be responsible...  ...including Agency Lending, Prime Services, Secured Financing, derivatives in interest rates... 
    Full time
    Temporary work
    Work experience placement
    Flexible hours

    State Street Bank

    Clifton, NJ
    2 days ago
  • $120k - $202.5k

     ...responsible forAs a Systems Analyst, VP you will:What we value User...  ...or a BA in Finance or Business with an IT concentration.A minimum...  ....Charles River IMS or securities trading software experience is...  ...ethnicity, age, disability, genetic information, sex, sexual orientation,... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Clifton, NJ
    10 hours ago
  • Citi's Investor Services Technology group is seeking a Tax Reclaim Transformation Technology Lead in Jersey City, New Jersey. This role focuses on driving the digitization and automation of global withholding tax reclaim operations. The ideal candidate will have over...

    Jobleads-US

    Jersey City, NJ
    1 day ago
  •  ...Business Relationship Manager Senior Government Not-for-Profit If you are customer focused, enjoy building relationships, and providing...  ...health or physical disability needs. Visit our FAQs for more information about requesting an accommodation. Equal Opportunity... 
    Work experience placement

    Chase

    Saddle Brook, NJ
    5 days ago
  •  ...of highly skilled, trusted, and dynamic security architects and engineers tasked with securing...  ...on threats to State Street’s critical business environments from Nation States, Cyber...  ...management team, senior leaders, and information security professionals on cyber threat trends... 
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    State Street Bank

    Clifton, NJ
    3 days ago
  • $160k - $260k

     ...opportunity?RBC is seeking a Director, Regulatory Affairs (Global Cyber Security) to serve as the embedded advisor to the CISO on cybersecurity...  ...into actual security decisions. You'll work across all business entities and technology domains, balancing proactive compliance... 
    Full time
    Flexible hours

    Royal Bank of Canada

    Jersey City, NJ
    10 hours ago
  • $160k - $275k

     ...opportunity? Royal Bank of Canada is seeking a Technical Information Security Officer to provide US regional cybersecurity leadership and ensure...  ...intelligence and threat hunting capabilities across our US Lines of Business.In this role you will oversee enterprise cybersecurity... 
    Full time
    Flexible hours

    Royal Bank of Canada

    Jersey City, NJ
    4 days ago
  • $142.32k - $213.48k

     ...in a production environment by partnering with technology and business partners. You will have to address complex problems involving...  ...unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.... 
    Full time

    Citigroup

    Rutherford, NJ
    2 days ago
  •  ...infrastructure leadership role supporting business-critical environments across research, manufacturing, labs, corporate offices, commercial operations, and cloud platforms...  ...direction, improving reliability, strengthening security, managing vendor performance, and making... 
    Remote work
    3 days per week

    Spinnaker Search

    Clifton, NJ
    more than 2 months ago
  • $225k - $255k

     ..., providing strategic leadership across business functions, running the current application...  ..., implementation, and management of all information and operational technology initiatives....  ...operational efficiency, ensure data security, and deliver measurable business value at... 
    Contract work
    Local area
    Flexible hours

    Veolia Environnement

    Paramus, NJ
    2 days ago
  • $166.9k - $219k

     ...Global Cloud & Data Center Lead to deliver secure, compliant, and cost-effective cloud and...  ...approve infrastructure designs to meet business and regulatory requirements. Support...  ...Bachelor’s degree in Computer Science, Information Technology, Business Administration, or... 
    Full time
    For contractors
    3 days per week

    Eisai

    Nutley, NJ
    4 days ago
  • $206.5k - $344.1k

     ...—from problem definition and business case development through design...  ...with Legal, Privacy, Risk, Security, and enterprise AI governance...  ...enablement forums, to drive data-informed prioritization, investment...  ...teams, transformation offices, or design-led delivery models... 
    Full time
    Local area
    Work from home

    CIGNA

    Bloomfield, NJ
    4 days ago
  •  ...Vice President of Business Operations & Transformation About the Company A growing public relations agency focused on operational excellence and business transformation. Industry Public Relations and Communications Type Privately Held About the Role... 

    Confidential

    Manhattan, NY
    2 days ago
  •  ...Vice President, Business Operations & Transformation About the Company A growing public relations agency focused on organizational effectiveness and business transformation. Industry Public Relations and Communications Type Privately Held About the... 

    Confidential

    Manhattan, NY
    5 days ago
  •  ...Trade and Working Capital (T&WC) Business! As the AI Use Case Business Lead (VP), within T&WC, you will serve as...  ...disability needs. Visit our FAQs for more information about requesting an accommodation...  ...leader across banking, markets, securities services and payments.... 

    JP Morgan Chase

    Jersey City, NJ
    1 day ago
  • $110k - $188.75k

     ...Architecture, Release Management, Operations, and Business stakeholders to ensure AI capabilities...  ..., UX, Data Science, Compliance, Security, and Go-to-Market teams to deliver enterprise...  ..., ethnicity, age, disability, genetic information, sex, sexual orientation, gender... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Clifton, NJ
    1 day ago
  •  ...results to steer the company financially to meet its targets. The business environment has many variations and changes, and the candidate...  ..., systematic, precise and innovative.   Additional Information Perks & Benefits ~401k with Generous Company Match... 
    Full time
    Local area
    Worldwide

    Sika

    Rutherford, NJ
    14 days ago
  •  ...NJ is seeking a Senior Principal, BRM - IT to serve as the strategic IT interface for the CSD segment, shaping sector roadmaps and business-enabled technology solutions. You will partner with Sector Presidents and IT leaders to drive digital transformation, deliver... 

    L3HHCM20

    Clifton, NJ
    2 days ago
  •  ...Mound, TX or Pittston, PA 30% of traveling required General Business Manager, PPO Profits What we're looking for in an industry-leading...  ...: PPO Fee Negotiations Revenue Cycle Management (RCM) In-Office Membership Plans Medical Billing The role leads strategic planning... 
    Work at office

    PPO Profits

    Newark, NJ
    4 days ago
  • State Street's Centralized Modeling & Analytics and Operations (CMAO) team seeks an experienced quantitative analyst to join the ERM organization. You will work on counterparty credit risk modeling for SSGM, shaping methodology and analytics across a broad set of asset ...

    State Street

    Clifton, NJ
    4 days ago
  • $105.4k - $207.8k

     ...with confidence, and proactively manage to secure success. Identity security market is...  ...teams to gather requirements, translate business needs into technical solutions, and manage...  ...in Computer Science, Cyber Security, Information Security, Engineering, Information Technology... 
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    1 day ago
  • $134.5k - $265.1k

     ...Privacy team, you will be responsible for:Translating client business needs and Digital Trust & Privacy requirements into AI-enabled...  ...QualificationsRequired:Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field; alternatively,... 
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    2 days ago
  •  ...enabled ways of working. You’ll partner across lines of defense and business teams to improve effectiveness, consistency, transparency, and...  ...is to empower the three lines of defense with risk-based information to manage their control environment. This is achieved by... 

    JP Morgan Chase

    Jersey City, NJ
    2 days ago
  • $120k - $202.5k

     ...within the State Street Markets (SSM) business unit.SSM, a division of State Street Bank...  ...markets business activities, including securities finance, brokerage services, and sales...  ...ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Clifton, NJ
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Business Information Security Officer-VP. Be the first to apply!