Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Business Information Security Officer

$120k - $202.5k

State Street Bank

Who We Are Looking ForThe Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into the Senior BISO (MD). The VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework.BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting.Why this role is important to usGlobal Cybersecurity (GCS) manages cyber risk across State Street’s business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm’s cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units — providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization.The Non-Technical Dimension: Trusted Advisor & Change AgentThe VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives, and be able to present to the highest levels of leadership, with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifies key stakeholders, establishes new relationships, and coordinates resources and Security Guardians to broker the right conversations across GCS and the business.The Technical DimensionThis role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. The VP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness.What You Will Be Responsible ForPartner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.Collaborate with key stakeholders to identify information assets and assess the protection needs requirements for the entire line of business and legal entity.Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required; own application- and service-level threat models.Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums.Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership.Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis.Technical Judgment & KnowledgeAligned to the GCS BISO cyber technical skills model, the VP should demonstrate practitioner-level depth across several of the domains below and be able to answer probing questions and coach others. Assess each area against the proficiency scale at the end of this document.Core TechnologiesCloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)Networking and network securitySecurity architecture fundamentals and control design effectivenessOperating systemsSupporting ProcessesCryptography, encryption, and key managementPatching and vulnerability managementCyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)Data classification and data protectionSecure communication protocolsIdentity and Access Management (IAM) / Privileged Access conceptsSecure SDLC, secure engineering, and DevSecOpsThird-party & supply chain security (vendor assessments, shared responsibility models)Security operations & monitoring (SOC / SIEM awareness, KPIs, posture reporting)Emerging Technology & AIThe BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to:Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.Demonstrate an understanding of model risk, frontier models, and the risk management around them.Show strong technical expertise in at least two focus areas across Multi-Cloud, AI, Machine Learning, Blockchain, Software Supply Chain, and Quantum Computing.Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.Risk ManagementUnderstands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001).Understanding of issue management, triage, remediation tracking, and residual-risk scoring.What We ValueThese skills will help you succeed in this role:Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.Translate technical risk into clear, actionable business terms for both technical and non-technical audiences.Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.Experience working with dashboards and data-mining tools to build cyber risk profiles.Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.Education & Preferred QualificationsBachelor’s degree in Computer Science, or a related technical field — or equivalent work-aligned experience.CISSP or CISM required. CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued.Emerging-tech / AI security certification a strong plus — e.g., ISACA Advanced in AI Security Management (AAISM), the first AI-centric security management credential (for CISM/CISSP holders), covering AI Governance & Program Management, AI Risk Management, and AI Technologies & Controls.5+ years working with business leadership across enterprise projects;Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork.Salary Range: $120,000 - $202,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.For a full overview, visit .About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.Discover more information on jobs at StateStreet.com/careersRead our CEO StatementJob Application Disclosure:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.SummaryLocation: Boston, MassachusettsType: Full time

Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the Business Information Security Officer in Boston, MA vacancy
  •  ...Vice President, Business Information Security Officer About the Company Expanding provider of investment management, research & trading services Industry Financial Services Type Public Company Founded 1792 Employees 10,001+ Categories Financial... 
    Suggested

    Confidential

    Quincy, MA
    5 days ago
  • $149.18k - $240k

     ...is the AI control tower for business reinvention. Our ServiceNow AI...  .... Combined with ServiceNow’s Security and Risk capabilities, as well...  ..., remote, or required in office) are categories that are assigned...  ...level: Not ApplicableIndustry: Information Technology And Services
    Suggested
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Boston, MA
    4 days ago
  • $82.3k - $220k

     ...that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit .Job Description Summary:The Information System Security Officer 2 (ISSO) supports the continuous monitoring and authorization efforts of multiple... 
    Suggested
    Full time
    Local area

    Draper Laboratory

    Cambridge, MA
    4 days ago
  •  ...Director of Cybersecurity to serve as the company’s Chief Information Security Officer, shaping the overall cybersecurity strategy and roadmap for...  ...of people, data, and IP. You will partner with CIO and business leaders to mature capabilities across architecture,... 
    Suggested

    Jobleads-US

    Cambridge, MA
    5 days ago
  •  ...the client seeks an accomplished, strategic, and forward-looking leader to serve as its inaugural Chief Information Security Officer (CISO). In this role, you will define and advance a comprehensive, institute-wide information security strategy to safeguard the organization... 
    Suggested

    Confidential

    Cambridge, MA
    1 day ago
  • $90k - $157.5k

     ...Cybersecurity Fusion Operations Analyst to join a world-class information security team in our Quincy office. We are looking for a detail oriented, team player...  ...with incident response, threat intelligence and business stakeholders Support the facilitation and delivery... 
    Temporary work
    Work at office
    Flexible hours

    State Street

    Quincy, MA
    4 days ago
  • $160k - $195k

     ...Boston, MA or Quincy, MA (4 days a week in office) Full Time Web Cam Interview $160-195K/...  ...for: Use your understanding of Security Data Science and Graph Theory to analyze...  ...across the enterprise. Work closely with business units to understand people, process, and... 
    Full time
    Work at office

    Syntricate Technologies

    Quincy, MA
    2 days ago
  • $243k - $365k

     ...experienced leader for the company’s centralized Security organization. The scope of Security...  ...security and privacy engineering, information security, and governance, risk, and...  ...level security programs. The SEC helps businesses find the best balance of risk mitigation... 
    Full time
    Work experience placement

    Jobleads-US

    Boston, MA
    2 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Clinical-stage biotechnology (BioTech) firm Industry Biotechnology Type...  ...people, data, technology assets, intellectual property, and business operations. The successful candidate will be responsible... 

    Confidential

    Cambridge, MA
    4 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup... 

    Confidential

    Boston, MA
    4 days ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing...  ...cognitive engines aiware and digital media hub Business Classifications SAAS B2B Enterprise About the... 

    Confidential

    Boston, MA
    4 days ago
  •  ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security...  ...as a protective measure but as a strategic enabler for business evolution. This role is pivotal in driving the security... 

    Confidential

    Boston, MA
    4 days ago
  • $105.4k - $207.8k

    Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber...  ...unique challenges and opportunities businesses face in cybersecurity. Join our team to...  ...servicesAssessing client cyber and information technology environments, including infrastructure... 
    Local area
    Visa sponsorship

    Deloitte

    Boston, MA
    4 days ago
  •  ...Let’s see what we can achieve. Together. Summary The Chief Information Security Officer (CISO), working in collaboration with and in support of...  ...DLA Piper’s clients, people, data, reputation, and global business operations by leading a mature, business-aligned information... 
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Boston, MA
    3 days ago
  • $145.9k - $234.2k

     ...Legal, Privacy, Procurement, business owners, and technical stakeholders...  ...monitoring, subcontractor security, secure development, business...  ...preferred, ideally in information systems, cybersecurity, or risk...  ...the significant benefits of in-office collaboration by embracing a... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Work at office
    Work from home

    Moderna

    Cambridge, MA
    2 days ago
  • $134.5k - $265.1k

     ...Position Summary Cyber Security & Risk Strategy Manager Our Deloitte Cyber team understands...  ...unique challenges and opportunities businesses face in cybersecurity. Join our team to...  ..., public policy, cybersecurity, information systems, finance, economics, or a related... 
    Local area
    Visa sponsorship

    Deloitte

    Boston, MA
    4 days ago
  •  ...Verily Health seeks a passionate Security leader to helm its centralized Security organization. You will build and mentor a 20-person team, set strategy, and drive governance, risk, and compliance across products and corporate systems. You will collaborate with Engineering... 

    Jobleads-US

    Boston, MA
    2 days ago
  •  ...strategic guidanceDevelop high-quality client deliverables, including business processes, requirements, executive reports, governance...  ...federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local... 
    Work experience placement
    H1b
    Local area

    KPMG

    Boston, MA
    1 day ago
  • $107.5k - $204.5k

     ...transferable U.S. government issued security clearance is required prior...  ...our three market leading businesses, world-class operations and...  ...clearance process. More information about Security Clearances can...  ...process in-person at one of our office locations, regardless of... 
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation
    Flexible hours

    Raytheon

    Boston, MA
    2 days ago
  • $178k - $307.05k

     ...Function Technology Enterprise Strategy & Security Job Sub Function Product Strategy Job...  ...capabilities connect end to end. In a business-partnering capacity, this leader will work...  ...Systems, Enterprise Architecture, Information Security & Risk, Clinical Technology, Data... 
    Temporary work
    Local area
    Immediate start

    Johnson & Johnson Innovative Medicine

    Cambridge, MA
    3 days ago
  • $212k - $333.19k

     ...with Takeda will commence and that the information I provide in my application will be processed...  ...of how technology and AI enable business performance, accelerate innovation, support...  ...supporting the Chief Digital & Technology Officer (CDTO), Data, Digital & Technology (DD&T... 
    Minimum wage
    Full time
    Local area

    Jobleads-US

    Cambridge, MA
    1 day ago
  •  ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories... 
    Remote work

    Confidential

    Boston, MA
    2 days ago
  •  ...Deputy Chief Information Security Officer (CISO) About the Company Innovative digital life insurance company Industry Insurance Type Privately Held, VC-backed Founded 2016 Employees 501-1000 Funding $6-$10 million Specialties life insurance... 

    Confidential

    Boston, MA
    3 days ago
  • $137k - $236k

     ...regulatory plans and submissions. Execute pre-market and post-market regulatory activities as per applicable procedures in I&S, IP&S and business units as assigned. This position will support software enabled medical devices with focus on major markets including the US and EU... 
    Work visa

    Philips

    Cambridge, MA
    1 day ago
  • Business Development Manager - Cyber Security Full-time New position as a Business Development Manager working with an award winning security platform...  ...with marketing to ensure efficient prospect/customer information exchange and hand-off Remove roadblocks to BDR success... 
    Full time

    Intelletec

    Cambridge, MA
    4 days ago
  • $112.9k - $338.3k

     ...data, analytics, and AI-enabled insights to inform decisions and guide action, while...  ...can continuously adapt as technologies, business models and ways of working evolve. Contribute...  ...but are not limited to the specific office location, role, skill set, and level of experience... 
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Boston, MA
    3 days ago
  •  ...government contractor and provider of enterprise information technology (IT) services and solutions....  ...with government and industry to tackle business challenges and pressures for Federal...  ...Engineering and Integration, Cyber Security / Information Assurance, Application Development... 
    For contractors

    Abacus Technology Corporation

    Lexington, MA
    a month ago
  • $245k - $325k

     ...Senior Director, Cybersecurity to serve as the company’s Chief Information Security Officer, responsible for building and scaling enterprise...  ...people, data, technology assets, intellectual property, and business operations. Reporting to the CIO, this role defines and... 
    Contract work
    For contractors

    Jobleads-US

    Cambridge, MA
    5 days ago
  •  ...Chief Information Officer (CIO) and Chief Technology Officer (CTO) About the Company Expanding...  ...vision and roadmap in alignment with business objectives, leading the development of...  ...overseeing the development and maintenance of secure, scalable, and efficient payment... 
    Remote work

    Confidential

    Boston, MA
    3 days ago
  • $81.15k - $83.57k

     ...Description Job Description Description The Information Technology Manager & Information Security Officer is a hybrid leadership and hands-on technical...  ...effective system backup, disaster recovery, and business continuity capabilities  Manage telephony and communication... 
    Local area
    Remote work

    Action for Boston Community Development

    Cambridge, MA
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Business Information Security Officer. Be the first to apply!