MD Senior BISO

State Street

Boston (MA)

On-site

USD 170,000 - 283,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401K match
Health insurance
Paid time off
Employee assistance program
Incentive compensation

Job summary

State Street seeks a MD-level Business Information Security Officer (BISO) to lead cyber risk across the enterprise. As a senior cybersecurity executive, you will translate risk into business terms, advise executives, and drive resilient strategy, governance, and regulatory alignment.

You will manage a team of cyber risk advisors, partner with global technology and control functions, oversee risk governance, incident guidance, and strategic technology initiatives including cloud adoption and

Qualifications

  • 15+ years of progressive cybersecurity, technology risk, or information security experience.
  • 8+ years leading cyber risk, cyber advisory, security architecture, security operations, or information security functions.
  • Demonstrated experience engaging with executive management, boards, regulators, and external stakeholders.
  • Proven record leading large-scale cybersecurity transformation or risk reduction initiatives.
  • Bachelor’s degree in computer science, cybersecurity, information systems, risk management, or related field.

Responsibilities

  • Serve as the senior cybersecurity advisor to business executives, legal entity leadership, and global technology services.
  • Provide strategic guidance regarding cyber threats, vulnerabilities, resiliency risks, and cyber control deficiencies.
  • Influence enterprise-wide cyber risk reduction initiatives and investment decisions at the business unit level aligning cyber policy and technical standards.
  • Drive the integration of cybersecurity considerations into business strategy, transformation programs, and critical business services.
  • Lead executive discussions regarding cyber risk posture, emerging risks, and risk mitigation priorities.
  • Establish and oversee cyber risk governance frameworks across the assigned business portfolios within the assigned business unit.
  • Ensure cyber risks are actively managed within approved risk appetite thresholds.
  • Review and challenge risk acceptance decisions involving material cyber exposures.
  • Provide oversight of cyber control effectiveness, remediation activities, and residual risk management.
  • Lead escalation of significant cyber risks to execute risk committees and senior governance forums.
  • Build strong partnerships with Business Executives, Technology Leaders, and control function partners.
  • Translate complex technical risks into clear business impacts and actionable recommendations.
  • Enable informed decision-making through transparent risk reporting and executive-level communication.
  • Provide consultative leadership on major technology initiatives, cloud adoption, AI programs, digital transformation, acquisitions, and strategic business initiatives.
  • Serve as a strategic change agent driving enterprise adoption of cybersecurity controls and risk management practices.
  • Partner with vulnerability management teams to prioritize remediation activities based on risk.
  • Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures.
  • Provide advisory support on patch management, configuration management, and security hardening efforts.
  • Assist business and technology teams in developing sustainable remediation strategies.
  • Drive enterprise efforts to improve cyber resilience, operational resilience, and recovery preparedness.
  • Oversee execution of strategic cyber remediation programs.
  • Ensure alignment of cyber investments toward the highest-risk business services and assets.
  • Guide business and technology leaders through major cyber incidents, crisis management activities, and lessons-learned programs.
  • Champion threat-informed defense strategies to reduce business unit cyber exposure.
  • Represent cybersecurity during regulatory examinations, client reviews, and external assessments.
  • Engage with regulators, auditors, and industry groups regarding cybersecurity risk management practices.
  • Ensure alignment with applicable regulatory requirements and industry best practices.
  • Partner with compliance, legal, and enterprise risk management functions to address emerging regulatory expectations.
  • Lead and develop a team of Cyber Security Advisors
  • Establish workforce strategies that strengthen cybersecurity capabilities and succession planning.
  • Foster a culture of accountability, collaboration, innovation, and continuous improvement.
  • Mentor future cybersecurity leaders and strengthen cyber risk management capabilities across the organization.
  • Drive consistent execution of cybersecurity objectives, metrics, and performance outcomes.
  • Strong and proven background in cybersecurity leadership
  • Cyber Engineering and Advisory, Cyber Strategy, Risk Management, and Executive Reporting
  • Technical and Security Domains
  • Secure Cloud, Data Protection, Frontier Model Security, Secure Architecture, and VM
  • Leadership Qualities
  • Organizational Influence, Cross Functional Collaboration, Strategic Thinking, and Engagement

Skills

Cybersecurity leadership
Executive reporting
Regulatory knowledge
Strategic risk management
Cloud security
Threat intelligence
Stakeholder management

Education

Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Risk Management, or related field

Tools

VM
Cloud platforms

Job description

Who we are looking for

The MD , Business Information Security Officer (BISO) serves as a senior cybersecurity executive within the first line of defense, responsible for providing both strategic cyber risk leadership and tactical cyber advisory services across the enterprise. This role acts as the primary cybersecurity advisor to executive management, business leadership, and the technology organization, ensuring cyber risks are effectively identified, assessed, governed, and managed in alignment with the business units risk appetite, strategic objectives, and regulatory obligations.

Why this role is important to us

The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a culture of accountability and cyber resilience. This individual leads a team of cyber risk advisors while serving as a key liaison between Global Cybersecurity, the business, technology organizations, and control functions.

The successful candidate combines executive leadership, deep cybersecurity expertise, regulatory acumen, and strong business judgment to strengthen the firm’s security posture while enabling strategic growth and innovation.

What you will be responsible for

Business Unit Cyber Risk Leadership

  • Serve as the senior cybersecurity advisor to business executives, legal entity leadership, and global technology services.
  • Provide strategic guidance regarding cyber threats, vulnerabilities, resiliency risks, and cyber control deficiencies.
  • Influence enterprise-wide cyber risk reduction initiatives and investment decisions at the business unit level aligning cyber policy and technical standards.
  • Drive the integration of cybersecurity considerations into business strategy, transformation programs, and critical business services.
  • Lead executive discussions regarding cyber risk posture, emerging risks, and risk mitigation priorities.

Cyber Risk Advisory & Oversight

  • Establish and oversee cyber risk governance frameworks across the assigned business portfolios within the assigned business unit.
  • Ensure cyber risks are actively managed within approved risk appetite thresholds.
  • Review and challenge risk acceptance decisions involving material cyber exposures.
  • Provide oversight of cyber control effectiveness, remediation activities, and residual risk management.
  • Lead escalation of significant cyber risks to execute risk committees and senior governance forums.

Trusted Advisor to Senior Leadership

  • Build strong partnerships with Business Executives, Technology Leaders, and control function partners.
  • Translate complex technical risks into clear business impacts and actionable recommendations.
  • Enable informed decision-making through transparent risk reporting and executive-level communication.
  • Provide consultative leadership on major technology initiatives, cloud adoption, AI programs, digital transformation, acquisitions, and strategic business initiatives.
  • Serve as a strategic change agent driving enterprise adoption of cybersecurity controls and risk management practices.

Vulnerability and Exposure Management

  • Partner with vulnerability management teams to prioritize remediation activities based on risk.
  • Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures.
  • Provide advisory support on patch management, configuration management, and security hardening efforts.
  • Assist business and technology teams in developing sustainable remediation strategies.

Cyber Resilience and Risk Reduction

  • Drive enterprise efforts to improve cyber resilience, operational resilience, and recovery preparedness.
  • Oversee execution of strategic cyber remediation programs.
  • Ensure alignment of cyber investments toward the highest-risk business services and assets.
  • Guide business and technology leaders through major cyber incidents, crisis management activities, and lessons-learned programs.
  • Champion threat-informed defense strategies to reduce business unit cyber exposure.

Regulatory and External Engagement

  • Represent cybersecurity during regulatory examinations, client reviews, and external assessments.
  • Engage with regulators, auditors, and industry groups regarding cybersecurity risk management practices.
  • Ensure alignment with applicable regulatory requirements and industry best practices.
  • Partner with compliance, legal, and enterprise risk management functions to address emerging regulatory expectations.

Talent and Organizational Leadership

  • Lead and develop a team of Cyber Security Advisors
  • Establish workforce strategies that strengthen cybersecurity capabilities and succession planning.
  • Foster a culture of accountability, collaboration, innovation, and continuous improvement.
  • Mentor future cybersecurity leaders and strengthen cyber risk management capabilities across the organization.
  • Drive consistent execution of cybersecurity objectives, metrics, and performance outcomes.

Technical and Leadership Competencies

  • Strong and proven background in cybersecurity leadership
  • Cyber Engineering and Advisory, Cyber Strategy, Risk Management, and Executive Reporting
  • Technical and Security Domains
  • Secure Cloud, Data Protection, Frontier Model Security, Secure Architecture, and VM
  • Leadership Qualities
  • Organizational Influence, Cross Functional Collaboration, Strategic Thinking, and Engagement

What we value

These skills will help you succeed in this role

  • Material reduction in enterprise cyber risk exposure.
  • Effective management of cyber risks within approved risk appetite.
  • Positive regulatory and audit outcomes.
  • Increased cyber resiliency across critical business services.
  • Executive confidence in cyber risk reporting and decision support.
  • Successful execution of cyber transformation and risk remediation initiatives.
  • Measurable improvement in cybersecurity governance maturity and control effectiveness.

Education & Preferred Qualifications

  • 15+ years of progressive cybersecurity, technology risk, or information security experience.
  • 8+ years leading cyber risk, cyber advisory, security architecture, security operations, or information security functions.
  • Demonstrated experience engaging with executive management, boards, regulators, and external stakeholders.
  • Proven record leading large-scale cybersecurity transformation or risk reduction initiatives.
  • Strong understanding of financial services, regulatory environments, and cybersecurity frameworks.
  • Exceptional communication, executive presentation, and stakeholder management skills.
  • Bachelor’s degree in computer science, Cybersecurity, Information Systems, Risk Management, or related field.

Salary Range:

$170,000 - $282,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

MD Senior BISO
MD Senior BISO

State Street • Quincy (CA)

On-site
USD 170,000 - 283,000
Business Information Security Officer-VP
Business Information Security Officer-VP

govconcareershub.com • Quincy (MA)

On-site
USD 120,000 - 203,000
401K match
Comprehensive benefits
Paid time off
MD Cyber Governance & Regulatory Relations
MD Cyber Governance & Regulatory Relations

State Street • Quincy (MA)

On-site
USD 170,000 - 283,000
401K with company match
Medical, dental, vision insurance
Paid time off
+2
MD Cyber Governance & Regulatory Relations
MD Cyber Governance & Regulatory Relations

State Street • Boston (MA)

On-site
USD 170,000 - 283,000
401K with company match
Comprehensive benefits (medical/dental
Paid time off and volunteer days
+1
MD, Senior Business Information Security Officer
MD, Senior Business Information Security Officer

SupportFinity™ • Princeton (TX)

On-site
USD 170,000 - 283,000
401K with company match
Comprehensive insurance coverage
Paid time off including vacation and sick leave
+2
Business Information Security Officer-VP
Business Information Security Officer-VP

State Street • Austin (TX)

On-site
USD 120,000 - 203,000
Cyber Policy Enforcement Lead, VP
Cyber Policy Enforcement Lead, VP

State Street • Quincy (MA)

On-site
USD 120,000 - 203,000
401K with company match
Insurance coverage (medical, life, etc
Paid time off
+3
Business Information Security Officer- AVP
Business Information Security Officer- AVP

State Street • Boston (MA)

On-site
USD 90,000 - 158,000
Business Information Security Officer-VP
Business Information Security Officer-VP

State Street • Berwyn (PA)

On-site
USD 120,000 - 203,000
Business Information Security Officer-VP
Business Information Security Officer-VP

State Street Corporation • Quincy (MA)

On-site
USD 120,000 - 203,000