Information Security Officer
$120k - $202.5kState Street Bank
Who We Are Looking ForGlobal Cybersecurity (GCS) manages cyber risk across State Street's business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm's cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization.The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into Senior BISO / MD. The VP BISO leads a small team focused on providing cyber advisory services, building application and service level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework.This role is intended for a cyber risk leader who can support both traditional technology environments and emerging digital asset services. The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing, smart contract assurance, third-party platforms and broader blockchain based financial services solutions. The candidate should translate these topics into clear control expectations for business, technology, risk, compliance, legal, and regulatory stakeholders.The Non-Technical Dimension: Trusted AdvisorThe VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives and be able to present to the highest levels of leadership and, where relevant, external regulators with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifies key stakeholders, establishes new relationships, and coordinates resources and Security Guardians to broker the right conversations across GCS and the business.The Technical DimensionThis role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness. For digital asset services, this includes understanding digital asset custody models, cryptographic key management, HSM and MPC based signing controls, wallet security, smart contract risks, blockchain infrastructure dependencies, and response readiness for suspicious or unauthorized digital asset activity.What You Will Be Responsible ForLead a small team to support aligned business stakeholders while focusing on increased cyber capabilities; execute a cyber book of work aligned to the business.Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required.Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory.Prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership.Advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services.Challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience.The candidate should demonstrate familiarity with custody and key management models, including HSM-backed solutions, Multi-Party Computation (MPC), transaction-signing controls, and cold storage architectures.Coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations.Technical Judgment & KnowledgeAligned to the GCS BISO cyber technical skills model, the VP should demonstrate practitioner-level depth across several of the domains below and be able to answer probing questions and coach others.Core TechnologiesCloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)Networking and network securitySecurity architecture fundamentals and control design effectiveness.Blockchain and distributed ledger technology fundamentals, including public and permissioned networks, transaction lifecycle concepts, digital asset infrastructure, and tokenization models.Digital asset custody technologies, including wallet architecture, HSMs, MPC concepts, cold storage, warm/hot wallet risk, transaction signing, and private key protection.Supporting ProcessesCryptography, encryption, and key managementPatching and vulnerability managementCyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)Data classification and data protectionSecure communication protocolsIdentity and Access Management (IAM) / Privileged Access conceptsSecure SDLC, secure engineering, and DevSecOpsSoftware Supply Chain SecurityThird-party & supply chain security (vendor assessments, shared responsibility models)Security operations & monitoring (SOC / SIEM awareness)Smart contract security review, including threat modeling, secure design, independent audit coverage, vulnerability remediation, change governance, and privileged administration riskDigital asset custody control assessment, including HSM-backed key protection, cold storage procedures, key generation, backup, recovery, rotation, destruction, transaction approval workflows, and non-repudiationOn-chain monitoring and digital asset incident response, including suspicious activity alerting, fraud indicators, wallet compromise scenarios, unauthorized transaction response, and escalation proceduresDigital Asset Custody, HSM & Cold Storage FocusThe candidate should not only understand blockchain concepts, but also the specific cyber and operational risks created by custody, wallet administration, private key protection, and transaction signing.Understands the role of HSMs in cryptographic key generation, key storage, transaction signing, secure execution boundaries, tamper resistance, and separation of administrative duties.Can evaluate cold storage models, including offline controls, key ceremony discipline, physical and logical access controls, recovery procedures, availability constraints, and operational errors that could delay or prevent transaction execution.Can assess hot, warm, and cold wallet risk tradeoffs, including availability, automation, transaction velocity, fraud exposure, insider threat, disaster recovery, and business continuity considerations.Can challenge private key lifecycle controls, including key generation, custody, backup, recovery, rotation, revocation, destruction, dual control, quorum approvals, and evidence of control operation.Can evaluate transaction authorization controls, including maker/checker processes, approval thresholds, segregation of duties, privileged access, non-repudiation, monitoring, and exception handling.Emerging Technology & AIThe BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to:Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.Demonstrate an understanding of model risk, frontier models, and the risk management around them.Show strong technical expertise across Cloud Security, Digital Assets, AI, Identity & Access Management, Application Security, and Software Supply Chain Security.Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.Explain how digital asset risks differ from traditional application risks, including transaction finality, private key compromise, smart contract logic, custody dependencies, on-chain activity, and third-party platform concentration risk.Risk ManagementUnderstands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.Understanding of issue management, triage, remediation tracking, and residual-risk scoring.Ability to assess digital asset risks across custody, key management, wallet administration, HSM usage, cold storage, smart contracts, third parties, monitoring, incident response, operational resilience, and privileged access.What We ValueThese skills will help you succeed in this role:Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.Identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions.Translate technical risk into clear, actionable business terms for both technical and nontechnical audiences.Good understanding of agile methodology, tools, procedures, and iterative decision-making processes.Experience working with dashboards and data-mining tools to build cyber risk profiles.Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.Applies sound judgment when evaluating emerging technologies and can distinguish material risk from theoretical concerns.Education & Preferred QualificationsBachelor’s degree in computer science, Information security and assurance, or a related technical field or equivalent work aligned experience.CISSP/CISP preferred.Blockchain and digital asset security certifications (e.g., Certified Blockchain Security Professional (CBSP)) are desirable. Practical experience with digital asset custody, wallet infrastructure, HSMs, MPC technologies, transaction signing controls, smart contracts, tokenization platforms, and blockchain security assessments is strongly preferred.At least 6 years of information security experience in an operational or analytical capacity, with 4+ years within financial services; qualitative cyber risk analysis experience highly preferred.Experience working with the NIST Cybersecurity Framework; AWS or Azure cloud security preferable but not required.Experience with business concepts including finance, business requirements, compliance, and risk management.Familiarity with applicable regional regulatory guidance across the jurisdictions the role supportsPractical experience with blockchain, digital assets, tokenization, custody, wallet infrastructure, smart contracts, HSM-based key management, cold storage, transaction signing controls, or digital asset platform risk assessments strongly preferred.Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork.Salary Range: $120,000 - $202,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.For a full overview, visit .About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.Discover more information on jobs at StateStreet.com/careersRead our CEO StatementJob Application Disclosure:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.SummaryLocation: Quincy, Massachusetts; Berwyn, Pennsylvania; Clifton, New Jersey; Austin, TexasType: Full time
$237.5k - $390k
...Title: Chief Information Security Officer (CISO)Location: Austin, TX / Morristown, NJ (hybrid)Reports To:Chief Technology OfficerAbout Hippo:Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us. We use technology...SuggestedTemporary workFlexible hours$90.9k - $129.9k
...also have comprehensive leadership and technical development academies to help build your skills and capabilities.SummaryAs Information Security Leader (ISO), you will be accountable for all security-related compliance and delivery for the customers assigned. In a typical...SuggestedFull timeFlexible hours$10,271 per month
...Job Overview Title: Chief Information Security Officer (CISO) – Director VI (Posting #19093) Agency: Texas Health and Human Services Commission (HHSC), Health & Human Services Comm. Department: CHIEF INFO SECURITY OFFICE. Location: 4601 W GUADALUPE ST, Austin, TX. Full...SuggestedPermanent employmentFull timeContract workWork at officeRemote workDay shift$82.7k - $173.9k
Job Title: Information System Security OfficerJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: TS/SCIEmployee... ...Authorization to Operate (ATO) for CACI systems/networks.Office location for this opportunity is in:Austin, TXMore About...SuggestedContract workWork experience placementWork at officeLocal areaFlexible hours$134.63k - $224.38k
...part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Private Cloud Information Security Officer (ISO) to join our team in Austin, Texas (US-TX), United States (US).At NTT DATA Americas, we know that with the right people...SuggestedFull timeTemporary workWork at officeRemote workFlexible hours2 days per week3 days per week- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...
- ...Chief Information Security Officer (CISO) About the Company Technology-driven provider of home insurance Industry Insurance Type Public Company Founded 2015 Employees 501-1000 Categories Insurance Finance About the Role The Company...
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees...
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Description Job Description ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment...Full timeLocal areaFlexible hours
$240k - $305k
...sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. As VP, Chief Information Security Officer, you will be responsible for Commerce’s overall information security, compliance, and cyber risk program across our SaaS...For contractorsWork at officeLocal areaRemote work3 days per week- DescriptionExecutive Director, Public Sector Information Security & Compliance Officer TTEC is a global leader in customer experience, engagement, and growth solutions. Our Public Sector Security & Compliance team supports federal, state, and regulated industry programs...Contract workRemote work
$90k - $95k
...Director of Information Technology POSITION SUMMARY The IT Director will provide strategic leadership and oversight for the university... .... This role involves managing the IT department, ensuring the security and integrity of university data, and facilitating the...Full time- ...Technology Team as a Telecommunications Manager located in various offices.We are seeking a professional who thrives in a fast-paced,... ...guide the firm through technology transitions—with emphasis on security, compliance, and business continuity.Key ResponsibilitiesStrategic...Full timeContract workRemote work
- ...authorized by law. Provide leadership and oversight of Network Services operations, including WAN, LAN, wireless, SD-WAN, and network security platformsOversee daily operational activities, including incident management, problem resolution, and service availabilityServe as...Permanent employment
$128.65k - $214.34k
...pursue their financial goals.Job Overview:As a member of the Cyber Security team, an AVP Penetration Tester of Offensive Security will be... ...area of focus at LPL. This is an exciting time to join the Information Security team as we look for highly skilled people to help...Full timeWork from home- ...Requirements:Physical Demand Level: S - Sedentary WorkWhat We’re Looking for:Education requirements are listed below:Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Business, Risk Management, Emergency Management, Engineering, or related field, or...Full timeWork experience placement
- ...ContractJob Summary:Provide leadership and oversight of Network Services operations, including WAN, LAN, wireless, SD-WAN, and network security platforms.Oversee daily operational activities, including incident management, problem resolution, and service availability.Serve...Permanent employment
- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- ...Hippo is seeking a seasoned Chief Information Security Officer to steer cybersecurity strategy, security operations, and governance, risk, and compliance across the enterprise. This leader will own Hippo’s SOC 2 program, drive regulatory compliance for a multi-state,...
- ...Commerce is seeking a VP, Chief Information Security Officer to lead its information security, compliance, and cyber risk program across its SaaS platform, product offerings, and corporate systems. You will manage a distributed team of security professionals and collaborate...
- ...The DomainData and AI are no longer back-office functions — they're the engine of every... ...pipeline deployments.Cybersecurity: Google Security Operations and Agentic Defense... ...paid holidays, and paid time off. See more information on our benefits here:U.S. Employee Benefits...Full timeWork experience placementLive inWork at officeLocal areaShift work
- ...layouts, and CI/CD automation pipelines.Securing Client Data: Google Security Operations... ...include but are not limited to the specific office location, role, skill set, and level of... ...holidays, and paid time off. See more information on our benefits here:U.S. Employee Benefits...Full timeWork experience placementLive inWork at officeLocal area
- ...Mid Level Cyber Security Analyst austin, tx to work on the CISO Security Operations Center team - supporting the rapid threat detection... ...to ensure the confidentiality, integrity and availability of information assets. This role may include daytime, evening or overnight...Full timeNight shiftWeekend workAfternoon shift3 days per week
- Austin, TexasMission Control - Executive Office /Employee / Full-Time /On-siteWho is Sonar... ...helps prevent code quality and code security issues from reaching production, amplifies... ...with high-profile customers will directly inform and shape our product roadmap and GTM strategy...Full timeWork at officeRemote workWork from homeWorldwideFlexible hours
$201.11k - $269.08k
...make them successful. They can engage credibly with Chief Data Officers, CIOs, Enterprise Architects, Data Governance leaders, and... ...decisions. Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including...Full timeWork at office- ...Cloud enables mid-market clients to build secure, scalable cloud foundations while... ...include but are not limited to the specific office location, role, skill set, and level of... ...paid holidays, and paid time off. See more information on our benefits here:U.S. Employee...Full timeWork experience placementLive inWork at officeLocal areaImmediate start
- Full-Time Associate Chiropractor (DC) — NuSpine ChiropracticWe offer exceptional clinical care with best-in-class operational support —so patients get the affordability, convenience, relationship, service, and education they deserve.We're chiropractic-centric. Our exams...Full timeImmediate start
- ...alleviate pain, improve mobility, and enhance overall function. Utilize a strong understanding of human anatomy and physiology to guide informed treatment decisions and optimize patient outcomes. Collaborate with a multidisciplinary healthcare team to deliver comprehensive,...Immediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- chief information security officer ciso Austin, TX
- ciso Austin, TX
- information security officer Austin, TX
- business information security officer Austin, TX
- chief information security officer Austin, TX
- entry level information security analyst Austin, TX
- data center security officer Austin, TX
- information security compliance analyst Austin, TX
- director information security Austin, TX
- information security analyst Austin, TX



