Business Information Security Officer AVP

State Street

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Quincy, MA
Salary
$90,000–$157,500 / yr
Posted
9 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $171k
This role $124k
$75k most similar roles pay here $229k

This role pays less than 86% of similar roles. Most pay $137,875–$204,904 — the shaded band above. At the midpoint, this role pays about $124k versus about $171k for comparable roles.

Based on 239 similar postings.

Employer

About State Street

State Street Corporation is one of the world''s largest custodian banks and asset managers, providing investment servicing, investment management, and investment research to institutional investors. Industry: Financial Services & Asset Custody

State Street currently has 176 open roles on FindRole.

Listed pay typically runs $120,000–$202,500 across 172 roles with salary data.

Most-posted roles

View all roles at State Street

At a glance

TL;DR · Business Information Security Officer AVP

Business Information Security Officer-AVP serves as a key member of the Business Information Security team, providing cyber risk advisory services to strengthen the firm's defensive posture through proactive management and security-by-design practices. This role involves assessing risks for infrastructure, applications, cloud services, and third-party supply chains while partnering with engineering and architecture teams to embed resilience into network designs. The individual will manage vulnerability remediation, oversee control gap analysis, and provide guidance on risk acceptance and incident response strategies. Required expertise includes enterprise networking concepts, secure cloud environments, Secure SDLC practices, and SaaS delivery models involving identity and data protection. Candidates must navigate complex regulatory frameworks such as FFIEC, NIST, ISO, or SOC while translating technical risks into actionable business guidance for stakeholders in a regulated financial services environment.

What you'll do

  • Assess cyber risks for infrastructure, applications, cloud services, third-party supply chains, and emerging technologies.
  • Review network designs and architecture artifacts to ensure security-by-design and alignment with enterprise standards.
  • Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture.
  • Partner with engineering teams to implement network segmentation, trust boundaries, and zero trust principles.
  • Prioritize remediation activities based on vulnerability trends and systemic control weaknesses.
  • Lead network security risk assessments and track the remediation of identified control gaps.
  • Provide advisory support during cyber incidents regarding impact analysis and containment strategies.
  • Support internal audits and regulatory reviews by articulating the firm's network security posture.

What we're looking for

  • Strong technical understanding of enterprise networking concepts and security controls.
  • Experience with network security technologies, secure cloud environments, and Secure SDLC practices.
  • Experience securing Software-as-a-Service delivery models including identity, data protection, monitoring, and governance.
  • Ability to assess architecture diagrams and design documents for security risk.
  • Experience in cyber risk assessment, control evaluation, and remediation tracking.
  • Strong written and verbal communication skills with the ability to influence without direct authority.
  • Experience in regulated financial services or similarly complex environments.
  • Exposure to regulatory expectations such as FFIEC, NIST, ISO, SOC, or equivalent frameworks.

More like this

Similar roles

Business Information Security Officer AVP

State Street

Boston, MA +1 23 days ago $90,000$157,500
AWS Azure Network Security Cryptography Identity and Access Management (IAM) Vulnerability Management Incident Response DevSecOps Secure SDLC SIEM NIST CSF 2.0 NIST SP 800-53 ISO 27001 Machine Learning Generative AI
8+ yrs exp

Business Information Security Officer VP

State Street

Quincy, MA +3 23 days ago $120,000$202,500
Blockchain Digital Assets HSM MPC Smart Contracts AWS Azure Cloud Security Cryptography Key Management IAM PAM SOC SIEM DevSecOps SDLC NIST Cybersecurity Framework Vulnerability Management Incident Response Machine Learning
6+ yrs exp

Senior BISO

State Street

Quincy, MA +2 10 days ago $170,000$282,500
Cybersecurity Risk Management Vulnerability Management Patch Management Configuration Management Security Architecture Data Protection Crisis Management Information Security Compliance Governance Audit VM
10+ yrs exp

Security Engineering Vice President

Goldman Sachs

New York, NY 75 days ago $150,000$250,000
Cybersecurity Cloud Security Threat Modeling OWASP Top 10 SANS Top 25 SDLC CI/CD Zero Trust AI Network Infrastructure Data Flow Analysis Information Security Controls Risk Assessment

AVP Engineering Security Operations Manager

LPL Financial

Austin, TX +4 45 days ago $129,986$216,609
SIEM EDR DLP Vulnerability Management Identity and Access Management Network Security Cloud Security Splunk Exabeam Sentinel CrowdStrike SentinelOne Microsoft Defender for Endpoint Qualys Tenable Rapid7 Python PowerShell AWS Azure GCP
10+ yrs exp Hybrid