yoinka

AI Security and Data Protection Governance and Controls VP

State Street

QuincyFull TimeStaff
Sign in to applyVerified 43m ago
Location
Quincy
Employment
Full Time
Work model
On-Site
Level
Staff
Posted
Sep 11, 2026

Skills

Cybersecurity

About this role

Who we are looking for We are looking for a Vice President, AI Security and Data Protection Governance and Controls reporting directly to the Managing Director, Data Protection. You will establish and oversee the enterprise governance framework for secure and resilient AI and data protection capabilities, translating strategy into policies, standards, controls, risk decisions, and measurable remediation programs. You will partner across Security, Technology, Risk, Compliance, Legal, Procurement, and the business to embed security-by-design, resilient controls, and adaptable technology standards and AI security and data protection requirements across enterprise platforms, applications, and third-party services. Why this role is important to us The team you will be joining is part of Global Cybersecurity, a function vital to protecting the confidentiality, integrity, availability, and resilience of the firm’s information and technology environment. This role is critical to preparing the organization for emerging AI, data, and emerging technology risks, reducing long-term security and data protection risk, supporting regulatory and audit readiness, and coordinating a controlled transition to secure and resilient AI and data protection capabilities. What you will be responsible for In this role, you will: • Establish and maintain the enterprise governance framework, policies, standards, decision rights, and accountability model for AI security, data protection, and emerging technology risk. • Govern the discovery, inventory, classification, and risk assessment of AI models, data assets, security controls, platforms, applications, integrations, and technology dependencies. • Define risk-based prioritization criteria using data sensitivity, retention period, business criticality, external exposure, and migration complexity, including long-term data exposure and emerging technology risk. • Design minimum control requirements, testing procedures, evidence standards, exception processes, compensating controls, and remediation expectations across applications, infrastructure, cloud, networks, identity, and data platforms. • Establish and oversee the enterprise roadmap for transitioning vulnerable security and data protection implementations to approved approved secure technologies and control solutions, including delivery milestones, control gates, dependencies, and risk escalation. • Partner with Security Architecture and Engineering to embed AI security and data protection and security-by-design and adaptable control requirements into solution design, architecture reviews, engineering standards, and reusable implementation patterns. • Define AI security and data protection requirements and due-diligence criteria for third-party products, cloud services, strategic vendors, contracts, and technology evaluations. • Serve as the subject-matter authority for AI security and data protection governance in engagements with senior leadership, Risk, Compliance, Internal Audit, external auditors, clients, and regulators. • Establish dashboards, key risk indicators, and performance measures for inventory coverage, AI and data risk exposure, control compliance, exceptions, migration progress, remediation, and residual risk. • Lead and develop a team responsible for governance, control oversight, risk assessment, program coordination, and cross-functional execution.

What we value

These skills will help you succeed in this role: • Deep understanding of AI security, data protection, security architecture, governance, risk, and control principles, AI security and data protection, and security-by-design, resilient controls, and adaptable technology standards. • Ability to translate complex technical and emerging risks into clear policies, standards, controls, investment priorities, and executive decisions. • Strong governance, technology risk, control design, exception management, and assurance capabilities within a large,

Listing verified 43m ago. Applications go through the company's official careers site.

← Back to Yoinka

AI Security and Data Protection Governance and Controls VP at State Street, Quincy | Yoinka