State Street logo
State StreetPosted 1 week ago

Business Information Security Officer-VP

$120,000–$202,500 year

On-siteAustin, Texas, United States or Quincy, Massachusetts, United States

Full TimeSenior LevelEnterprise

Job Summary

Lead a small team to execute a cyber book of work aligned with business units, performing cyber risk assessments at application, platform, and system levels to identify vulnerabilities and determine required protections. Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs. Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership. Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management. Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory. Prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership. Advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services. Challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience. Coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations.

Required Qualifications

  • Bachelor's degree in computer science, Information security and assurance, or a related technical field or equivalent work aligned experience
  • At least 6 years of information security experience
  • Trusted Advisor mindset to build trust through information and transparency with senior executives
  • Strategic change agent and thought leader mindset
  • Ability to present to the highest levels of leadership and external regulators with the appropriate blend of technical and business detail
  • Skilled at influencing change to lead teams to further adopt cyber controls while reducing overall residual risk
  • Strong technical background and ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm
  • Strong cyber controls analyst capability to correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services
  • Practitioner-level depth in understanding threats and risk mitigations
  • Ability to perform cyber risk assessments at the application, platform, and system levels
  • Ability to recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness
  • Understanding of digital asset custody models
  • Understanding of cryptographic key management
  • Understanding of HSM and MPC based signing controls
  • Understanding of wallet security
  • Understanding of smart contract risks
  • Understanding of blockchain infrastructure dependencies
  • Understanding of response readiness for suspicious or unauthorized digital asset activity
  • Ability to lead a small team to support aligned business stakeholders
  • Ability to execute a cyber book of work aligned to the business
  • Ability to partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs
  • Ability to oversee and actively manage risks in line with risk appetite through continuous business unit engagement
  • Ability to escalate open risk items to aligned business leadership
  • Ability to perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats
  • Ability to analyze impacts to the bank and determine protections required
  • Ability to integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management
  • Ability to represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory
  • Ability to prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership
  • Ability to advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services
  • Ability to challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience
  • Demonstration of familiarity with custody and key management models, including HSM-backed solutions, Multi-Party Computation (MPC), transaction-signing controls, and cold storage architectures
  • Ability to coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations
  • Practitioner-level depth across several of the following domains: Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud), Networking and network security, Security architecture fundamentals and control design effectiveness, Blockchain and distributed ledger technology fundamentals, Digital asset custody technologies, Supporting Processes (Cryptography, encryption, and key management; Patching and vulnerability management; Cyber resiliency, incident response...
  • Ability to articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning
  • Demonstration of an understanding of model risk, frontier models, and the risk management around them
  • Strong technical expertise across Cloud Security, Digital Assets, AI, Identity & Access Management, Application Security, and Software Supply Chain Security
  • Ability to explain how digital asset risks differ from traditional application risks, including transaction finality, private key compromise, smart contract logic, custody dependencies, on-chain activity, and third-party platform concentration risk
  • Understanding of how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite
  • Understanding of issue management, triage, remediation tracking, and residual-risk scoring
  • Ability to assess digital asset risks across custody, key management, wallet administration, HSM usage, cold storage, smart contracts, third parties, monitoring, incident response, operational resilience, and privileged access
  • Ability to establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams
  • Ability to identify friction and complexities that hinder efficient security controls and coordinate or escalate solutions
  • Ability to translate technical risk into clear, actionable business terms for both technical and nontechnical audiences
  • Good understanding of agile methodology, tools, procedures, and iterative decision-making processes
  • Experience working with dashboards and data-mining tools to build cyber risk profiles
  • Demonstration of continuous learning; staying current on emerging threats, technologies, and trends, and explaining how they keep up to date
  • Ability to know when to admit knowledge gaps and describe how they would go about obtaining the needed information
  • Ability to apply sound judgment when evaluating emerging technologies and distinguish material risk from theoretical concerns

Desired Qualifications

  • CISSP/CISP certification
  • Blockchain and digital asset security certifications (e.g., Certified Blockchain Security Professional (CBSP))
  • Practical experience with digital asset custody, wallet infrastructure, HSMs, MPC technologies, transaction signing controls, smart contracts, tokenization platforms, and blockchain security assessments
  • Experience with Agentic AI use cases and deployments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce