MD, Senior Business Information Security Officer
Listed on 2026-08-03
-
IT/Tech
Cybersecurity
MD, Senior Business Information Security Officer
State Street
Who We Are Looking For
The Managing Director, Senior Business Information Security Officer (BISO) is a senior cybersecurity leader accountable for the end‑to‑end technology risk posture of assigned businesses, platforms, products, and portfolios. The role partners with business, engineering, and platform leadership to enable secure delivery, reduce material cyber risk, and ensure informed executive decision‑making. This role applies deep technical expertise, and translates complex security risks into clear, business‑relevant outcomes.
Why this role is important to us
While reporting into the Global Cybersecurity Organization, the MD, Senior Business Information Security Officer builds strong relationships with aligned business partners to understand strategic roadmaps that drive further product and service advancements within the business to ensure that cybersecurity capabilities are aligned to best enable business success.
What You Will Be Responsible For
Business‑Aligned Risk Responsibilities
- Represent a complete technical security risk posture for assigned businesses.
- Ensure risks are identified, prioritized, and addressed in alignment with business objectives and risk appetite.
- Advise senior leaders on cybersecurity policies, standards, control expectations, and approved architectures.
Technical Risk Leadership
- Provide cyber advisory services to the technology and business partners across application, platform, and infrastructure designs.
- Partner with architecture, security, and engineering leaders to validate control effectiveness and risk decisions.
- Ensure primary and compensating controls are appropriately designed, reviewed, and sustained.
Domain & Emerging Technology Expertise
- Maintain strong practical expertise across cloud‑native and distributed systems, including AI, blockchain, and CI/CD environments.
- Assess emerging technology risks and guide the adoption of proportionate, scalable security controls.
Executive, Regulatory & Audit Engagement
- Engage credibly with executive leadership, Legal Entity Boards, regulators, and second and third lines of defense.
- Present concise, evidence‑based risk narratives, including material issues, trade‑offs, and mitigation strategies.
- Support regulatory examinations, audits, and management reviews with clear ownership and accountability.
Operating Model & Scale
- Operate effectively and efficiently within the security engagement and risk governance model.
- Identify and drive targeted improvements to reduce friction, clarify decision rights, and eliminate low‑value activities.
- Evolve the cyber operating model to support scalable, product‑centric, high‑velocity delivery, including responsible use of AI within an established cloud first model.
What We Value
- Demonstrate strong executive presence, judgment, and accountability consistent with professional responsibilities.
- Lead and develop a small team of cyber risk professionals, setting clear objectives and delivering measurable outcomes.
- Demonstrate strong influencing and risk‑based prioritization skills.
Education & Preferred Qualifications
- 15+ years of progressive cybersecurity experience, including 5+ years in Financial Services.
- Bachelor's Degree in Cybersecurity or related technical discipline.
- Significant experience as an operationally focused cybersecurity practitioner.
- Previous experience within roles such as Site Reliability Engineering, Data Architecture, Cryptography Engineer, and Security Researcher would be an advantage.
- Proven track record partnering with senior business and technology leadership on enterprise initiatives.
- Strong strategic thinking, business acumen, and decision‑making capability.
- Relevant technical certifications preferred (e.g., Cloud Security, AI, Blockchain, Dev Sec Ops , CISSP, CISM).
Salary Range
$170,000 - $282,500 Annual. The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).