Business Information Security Officer-AVP

State Street

Boston (MA)

On-site

USD 90,000 - 158,000

Full time

8 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401K with company match
Insurance coverage (medical, dental,视,
Paid time off (vacation, sick leave, F
Employee Assistance Program
Performance-based awards
Tax-advantaged savings plans

Job summary

State Street is seeking an AVP, Cyber Risk Advisor in Boston to strengthen our defensive cybersecurity posture. You will partner with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions.

The role combines strong technical cybersecurity knowledge with the ability to influence stakeholders and translate cyber risks into actionable business guidance.

Qualifications

  • Strong technical understanding of enterprise networking concepts and security controls.
  • Strong experience with network security technologies, secure cloud, Secure SDLC practices
  • Experience in securing Software-as-a-Service delivery models (Identity, Data Protection, Monitoring, and Governance)
  • Ability to assess architecture diagrams and design documents for security risk.
  • Experience in cyber risk assessment, control evaluation, and remediation tracking.
  • Strong written and verbal communication skills; able to influence without direct authority.
  • Experience in regulated financial services or similarly complex environments.
  • Exposure to regulatory expectations (e.g., FFIEC, NIST, ISO, SOC, or equivalent frameworks).
  • Experience supporting audits, regulators, or executive risk forums.

Responsibilities

  • Assess cyber risks associated with infrastructure, applications, cloud services, third party supply chain, and emerging technologies.
  • Assess network designs, material changes, and new initiatives for security risk; review architecture artifacts and control implementations.
  • Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture related to network controls.
  • Support execution of enterprise cyber risk management objectives and control improvement initiatives across Saas platforms in support of client deliverables.
  • Partner with network and cloud engineering teams to embed security-by-design and resilience principles across on-prem, cloud, and hybrid networks.
  • Review and influence network segmentation, trust boundaries, ingress/egress controls, and monitoring strategies.
  • Influence the alignment with security patterns with enterprise standards, zero trust principles, and regulatory obligations while working with cyber threat intel to build models.
  • Partner with GCS Security Guardians to ensure current network security principals and guidance are updated and documented.
  • Lead or support network security risk assessments, control gap analysis, and prioritization aligned to enterprise risk frameworks.
  • Track remediation of identified control gaps and provide transparent risk reporting and escalation as needed.
  • Support internal audits, regulatory reviews, and risk committees by articulating network security posture and key risks.
  • Provide advisory support during cyber incidents and events, including impact analysis, containment strategy guidance, and participate in playbook refinement.

Skills

Enterprise networking security
Network security technologies
Secure SDLC
SaaS security
Architecture risk assessment
Cyber risk assessment
Written and verbal communication
Regulated financial services
Regulatory frameworks
Audits and regulators

Job description

AVP, Cyber Risk Advisor

The AVP, Cyber Risk Advisor provides cyber risk advisory services focused on strengthening the firm's defensive cybersecurity posture through proactive risk management, cyber control oversight, vulnerability reduction, and security-by-design practices. The role serves as a trusted advisor to technology, infrastructure, application, and business teams, ensuring cybersecurity risks are identified, assessed, and managed in alignment with enterprise standards, regulatory expectations, and risk appetite.

As a member of the Business Information Security organization, the AVP Cyber Security Advisor partners closely with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions and measurable reductions in cyber exposure. The successful candidate combines strong technical cybersecurity knowledge with the ability to influence stakeholders and translate complex cyber risks into actionable business guidance.

Cyber Risk Advisory & Oversight
  • Assess cyber risks associated with infrastructure, applications, cloud services, third party supply chain, and emerging technologies.
  • Assess network designs, material changes, and new initiatives for security risk; review architecture artifacts and control implementations.
  • Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture related to network controls.
  • Support execution of enterprise cyber risk management objectives and control improvement initiatives across Saas platforms in support of client deliverables.
Security Architecture & Design Influence
  • Partner with network and cloud engineering teams to embed security-by-design and resilience principles across on-prem, cloud, and hybrid networks.
  • Review and influence network segmentation, trust boundaries, ingress/egress controls, and monitoring strategies.
  • Influence the alignment with security patterns with enterprise standards, zero trust principles, and regulatory obligations while working with cyber threat intel to build models.
  • Partner with GCS Security Guardians to ensure current network security principals and guidance are updated and documented.
Vulnerability and Exposure Management
  • Partner with vulnerability management teams to prioritize remediation activities based on risk.
  • Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures.
  • Provide advisory support on patch management, configuration management, and security hardening efforts.
  • Assist business and technology teams in developing sustainable remediation strategies.
Risk Assessment & Control Governance
  • Lead or support network security risk assessments, control gap analysis, and prioritization aligned to enterprise risk frameworks.
  • Track remediation of identified control gaps and provide transparent risk reporting and escalation as needed.
  • Support internal audits, regulatory reviews, and risk committees by articulating network security posture and key risks.
Threat and Incident Advisory
  • Provide advisory support during cyber incidents and events, including impact analysis, containment strategy guidance, and participate in playbook refinement.
  • Partner with threat intelligence teams, cyber defense center, and vulnerability management teams to interpret emerging threats, model exposure, and appropriate remediation.
Qualifications And Experience
  • Strong technical understanding of enterprise networking concepts and security controls.
  • Strong experience with network security technologies, secure cloud, Secure SDLC practices
  • Experience in securing Software-as-a-Service delivery models (Identity, Data Protection, Monitoring, and Governance)
  • Ability to assess architecture diagrams and design documents for security risk.
  • Experience in cyber risk assessment, control evaluation, and remediation tracking.
  • Strong written and verbal communication skills; able to influence without direct authority.
  • Experience in regulated financial services or similarly complex environments.
  • Exposure to regulatory expectations (e.g., FFIEC, NIST, ISO, SOC, or equivalent frameworks).
  • Experience supporting audits, regulators, or executive risk forums.
Salary Range

$90,000 - $157,500 Annual

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Job Application Disclosure

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Job ID: R-795096

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Information Security Officer- AVP
Business Information Security Officer- AVP

State Street • Boston (MA)

On-site
USD 90,000 - 158,000
MD Senior BISO
MD Senior BISO

State Street • Clifton (NJ)

On-site
USD 170,000 - 283,000
401(k) with company match
Comprehensive health benefits
Paid time off and employee programs
MD Senior BISO
MD Senior BISO

State Street • Quincy (MA)

On-site
USD 170,000 - 283,000
401K with company match
Comprehensive benefits package
Paid time off
Business Information Security Officer- AVP
Business Information Security Officer- AVP

govconcareershub.com • Boston (MA)

On-site
USD 90,000 - 158,000
MD Senior BISO
MD Senior BISO

State Street • Boston (MA)

On-site
USD 170,000 - 283,000
401K match
Health insurance
Paid time off
+2
MD Senior BISO
MD Senior BISO

State Street • Quincy (CA)

On-site
USD 170,000 - 283,000
Cybersecurity, AVP - Technical Delivery Manager
Cybersecurity, AVP - Technical Delivery Manager

State Street • Quincy (MA)

Hybrid
USD 90,000 - 158,000
401K with company match
Medical insurance
Dental insurance
+2
Assistant Vice President – IT Security Governance & Risk Management
Assistant Vice President – IT Security Governance & Risk Management

State Street • Princeton (NJ)

Hybrid
USD 100,000 - 168,000
Business Information Security Officer-VP
Business Information Security Officer-VP

State Street • Austin (TX)

On-site
USD 120,000 - 203,000
Business Information Security Officer-VP
Business Information Security Officer-VP

State Street • Clifton (NJ)

On-site
USD 120,000 - 203,000
401K with company match
Paid time off