Business Information Security Officer-VP
State Street
- Location
- Quincy
- Employment
- Full Time
- Work model
- On-Site
- Level
- Staff
- Posted
- Aug 17, 2026
Skills
About this role
Who We Are
Looking For Global Cybersecurity (GCS) manages cyber risk across State Street's business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm's cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization. The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into Senior BISO / MD. The VP BISO leads a small team focused on providing cyber advisory services, building application and service level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework. This role is intended for a cyber risk leader who can support both traditional technology environments and emerging digital asset services. The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing, smart contract assurance, third-party platforms and broader blockchain based financial services solutions. The candidate should translate these topics into clear control expectations for business, technology, risk, compliance, legal, and regulatory stakeholders. The Non-Technical Dimension: Trusted Advisor The VP BISO is a strategic change agent and thought leader. They must build trust through information and transparency with senior executives and be able to present to the highest levels of leadership and, where relevant, external regulators with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk to their businesses. The VP identifies key stakeholders, establishes new relationships, and coordinates resources and Security Guardians to broker the right conversations across GCS and the business. The Technical Dimension This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness. For digital asset services, this includes understanding digital asset custody models, cryptographic key management, HSM and MPC based signing controls, wallet security, smart contract risks, blockchain infrastructure dependencies, and response readiness for suspicious or unauthorized digital asset activity. What You Will Be Responsible For Lead a small team to support aligned business stakeholders while focusing on increased cyber capabilities; execute a cyber book of work aligned to the business. Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs. Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business