Business Information Security Officer-VP
$120k - $202.5kState Street Bank
Who We Are Looking For The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into the Senior BISO (MD). The VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework. BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting.The Non-Technical Dimension: Trusted Advisor & Change Agent The VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives, and be able to present to the highest levels of leadership, with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifies key stakeholders, establishes new relationships, and coordinates resources and Security Guardians to broker the right conversations across GCS and the business. The Technical Dimension This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. The VP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness. Why this role is important to usGlobal Cybersecurity (GCS) manages cyber risk across State Street’s business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm’s cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units — providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization. What You Will Be Responsible For Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs. Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership. Collaborate with key stakeholders to identify information assets and assess the protection needs requirements for the entire line of business and legal entity. Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required; own application- and service-level threat models. Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management. Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums. Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership. Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis. Technical Judgment & Knowledge Aligned to the GCS BISO cyber technical skills model, the VP should demonstrate practitioner-level depth across several of the domains below and be able to answer probing questions and coach others. Assess each area against the proficiency scale at the end of this document. Core Technologies Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud) Networking and network security Security architecture fundamentals and control design effectiveness Operating systems Supporting Processes Cryptography, encryption, and key management Patching and vulnerability management Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews) Data classification and data protection Secure communication protocols Identity and Access Management (IAM) / Privileged Access concepts Secure SDLC, secure engineering, and DevSecOps Third-party & supply chain security (vendor assessments, shared responsibility models) Security operations & monitoring (SOC / SIEM awareness, KPIs, posture reporting) Emerging Technology & AI The BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to: Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning. Demonstrate an understanding of model risk, frontier models, and the risk management around them. Show strong technical expertise in at least two focus areas across Multi-Cloud, AI, Machine Learning, Blockchain, Software Supply Chain, and Quantum Computing. Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus. Risk Management Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite. Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001). Understanding of issue management, triage, remediation tracking, and residual-risk scoring. What We Value These skills will help you succeed in this role: Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams. Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions. Translate technical risk into clear, actionable business terms for both technical and non-technical audiences. Good understanding of agile methodology, tools, procedures, and iterative decision-making processes. Experience working with dashboards and data-mining tools to build cyber risk profiles. Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date. Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information. Education & Preferred Qualifications Bachelor’s degree in Computer Science, or a related technical field — or equivalent work-aligned experience. CISSP or CISM required. CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued. Emerging-tech / AI security certification a strong plus — e.g., ISACA Advanced in AI Security Management (AAISM), the first AI-centric security management credential (for CISM/CISSP holders), covering AI Governance & Program Management, AI Risk Management, and AI Technologies & Controls. 5+ years working with business leadership across enterprise projects; Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork. Salary Range: $120,000 - $202,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.For a full overview, visit .About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.Discover more information on jobs at StateStreet.com/careersRead our CEO StatementJob Application Disclosure:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.SummaryLocation: Quincy, Massachusetts; Toronto, OntarioType: Full time
- ...Vice President, Business Information Security Officer About the Company Expanding provider of investment management, research & trading services... ...to the highest levels of leadership. Candidates for the VP BISO role at the company should have a Bachelor's degree...Suggested
$120k - $202.5k
...collaborate closely with architecture, AI and security teams to deliver production-grade... ...Communicate strategy, recommendations, and business impact clearly to senior stakeholders... ...ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender...SuggestedFull timeTemporary workFlexible hours$120k - $202.5k
...State Street Investment Management’s (IM) Business & Technology Risk and Resilience (BTRR)... ..., public accountant, risk or compliance officer Experience in risk management,... ...and resolve conflicts; ability to make informed, risk optimized decisions under time pressure...SuggestedTemporary workRemote workFlexible hours$110k - $188.75k
...responsible forAs a Vice President in this role, you willLead the business, process, and data analysis of complex data and visualization... ...owners and product to ensure all stakeholders are well informed and that the project roadmap is on track.Identify and define any...SuggestedFull timeTemporary workFlexible hoursShift work- State Street is seeking a Vice President level independent contributor to join the Alternative Investments Transformation team. You will lead analytics projects, collaborate with technology and stakeholders, and design solutions for internal operations and clients. The ...Suggested
- ...Practice ManagementWe help wealth management firms solve today’s business challenges so they can grow tomorrow.Practice Management is... ...national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression,...Full timeTemporary workFlexible hours
$120k - $202.5k
...Cyber Policy Enforcement Lead, VP is responsible for leading the... ...are embedded within business processes, ownership is clearly... ...clear reporting that enables informed management decision-making.Key... ...Certified Information Systems Security Professional)CISM (Certified Information...Full timeTemporary workFlexible hours$160k - $195k
...Boston, MA or Quincy, MA (4 days a week in office) Full Time $160-195K/Yr plus Bonus... ...for: Use your understanding of Security Data Science and Graph Theory to analyze... ...across the enterprise. Work closely with business units to understand people, process, and...Full timeWork at office$321.4k - $370k
The Vice President & Chief Compliance Officer provides strategic and independent leadership... ...privacy, operational, financial, and business-conduct risks. Oversees risk-based... ..., Human Resources, Internal Audit, Information Security, and other functions, as appropriate....Full timeFor contractorsFixed term contractFlexible hours- ...Industries, Inc. seeks a strategic Director of Information Technology to lead IT strategy, cybersecurity, and business applications. You will nurture executive partnerships... ..., and cloud technologies, with a focus on security, reliability, and cost efficiency. #J-18808-...
$110k - $188.75k
...Responsible For As a Vice President in this role, you will Lead the business, process, and data analysis of complex data and visualization... ...owners and product to ensure all stakeholders are well informed and that the project roadmap is on track. Identify and define...Temporary workFlexible hoursShift work$90k - $157.5k
...oversight, vulnerability reduction, and security-by-design practices. The role serves as... ...technology, infrastructure, application, and business teams, ensuring cybersecurity risks are... ...appetite.As a member of the Business Information Security organization, the AVP Cyber Security...Temporary work$120k - $217.5k
...a team of developers building automated business workflows. You'll write code, review PRs... ...Solutions need to meet enterprise standards for security, resilience, controls, and... ...with AI and agentic automation to have an informed opinion on where they're ready and where...Full timeTemporary workFlexible hours$220k - $370k
...experienced Senior Director or VP of Regulatory Affairs. The... ...is onsite 4 days/week in our office in Brighton, MA. Responsibilities... ..., risk mitigation, and key business decisions such as label expansion... ..., and recommended actions to inform development, regulatory, and...Summer workWork at officeFlexible hours$200k - $225k
...the way, come join the Broadridge team.The VP, Head of Policy & Data Operations leads... ...Custom Policy, Technology, Product, and Business stakeholders to ensure seamless policy execution... ..., Economics, Data Analytics, Business, Information Systems, or a related field, or...Full timeLocal areaRemote work$170k - $267.5k
...Managing Director to lead Private Equity Business Solutions and Platform Strategy within... ...OfficeEstablish and maintain a Private Equity Model Office function focused on process optimization... ...'s degree in Finance, Accounting, Information Systems, Business Administration, or...Full timeTemporary workWork at officeFlexible hours$113k - $188k
...climate science, policy, data, and business implications into practical... ...exposure and vulnerability information, scenario analysis,... ...Ability to work in a Guidehouse Office or Client Office.What Would Be... ...sets, experience and training, security clearances, licensure and certifications...Permanent employmentFull timeFor contractorsInternshipWork at officeRemote workFlexible hoursShift work$120k - $202.5k
Who we are looking for The AI Security Architect is a hands-on technical role responsible for designing, implementing, and reviewing security... ...AI services, and developer productivity use cases.Stay informed on AI security trends, tooling, and common risk patterns through...Full timeTemporary workFlexible hours$214k - $342k
...Summary The Vice President, Business Operations - Customer Success... ...across Customer Success. The VP will partner closely with Customer... ...make recommendations when information is incomplete. Deep... ...collaborativeworkspaces — some offices even welcome dogs.We also encourage...Full timeTemporary workWork at office$120k - $202.5k
...delivery execution across critical business and technology domains while... ...scalable, resilient, and secure solutions.Key... ...Computer Science, Engineering, Information Systems, or related discipline... ...RequirementOnsite 4 days a week in office and one day remoteStandard business...Full timeTemporary workWork at officeFlexible hours- Vice President, Business ApplicationsTriumvirate Environmental, one of the largest environmental... ...based out of our Somerville, MA office. This individual will lead enterprise business... .... This position reports to our Chief Information Officer. This position will be fully...Work at officeRelocation
$170k - $252.5k
...transformations that advance long-term business objectives, client outcomes and... ...migration, service-model redesign, middle-office transaction lifecycle modernization; define... ...compliance with regulatory, audit, information security and operational resilience requirements...Full timeTemporary workWork at officeFlexible hoursShift work- Resourcesoft, Inc. in Marlborough, MA, is seeking a cybersecurity business analyst to capture and optimize enterprise security processes. The role involves transforming security practices into auditable workflows, and shaping governance, SOPs, and runbooks to support audit...
$168.75k - $200k
...is the AI control tower for business reinvention. Our ServiceNow AI... .... Combined with ServiceNow’s Security and Risk capabilities, as well... ..., remote, or required in office) are categories that are assigned... ...level: Not ApplicableIndustry: Information Technology And ServicesWork at officeImmediate startRemote workFlexible hours$110k - $181.25k
Who we are looking forThe VP of Software Sourcing is an important... ...from LegalNegotiate IT security schedules with support from IT... ...stakeholders are based in the Quincy office.Identify risks and... ...in class procurement, risk, Information Security and payable processesProven...Full timeTemporary workWork at officeLocal areaFlexible hours- Competitive Power Ventures (CPV) is seeking an experienced Head of Procurement & Contracting to build and lead CPV Renewable Power's procurement function. You will develop strategies, oversee major equipment supply and EPC contracts, manage key supplier relationships, ...Remote work
$110k - $188.75k
...Street’s move to Cloud based SAS tools where business ownership, process knowledge and ability... ...depth understanding of Oracle security modelUnderstanding or familiarity with RMC... ...ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender...Full timeTemporary workFlexible hours- ...analytics products for investment portfolio analysis, performance measurement, and risk analytics.Key ResponsibilitiesPartner with business and technology teams to gather requirements and translate business needs into functional requirements, process flows, user stories...WorldwideFlexible hours
- ...to high standards.About the roleThe BSA Officer administers and maintains all aspects of... ...Identification and Verification across all business lines and productsCustomer Due Diligence... ...to organize and present ideas and information in a simple, concise, and unambiguous mannerAbility...Work at office
$120k - $217.5k
..., collaborating with diverse business and technology teams to drive... ...organization?As a Business Architect, VP at State Street Investment... ..., data integration, and security best practices.Experience... ...ethnicity, age, disability, genetic information, sex, sexual orientation,...Full timeTemporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Business Information Security Officer-VP. Be the first to apply!
- vp customer success Quincy, MA
- vice president development Quincy, MA
- vice president real estate development Quincy, MA
- vice president communications Quincy, MA
- vice president manufacturing Quincy, MA
- vp safety Quincy, MA
- vice president research Quincy, MA
- vice president tax Quincy, MA
- vice president of retail Quincy, MA
- vice president healthcare Quincy, MA


