Head of Cyber & Information Security Oversight

State Street

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Boston, MANew York, NY
Salary
$225,000–$337,500 / yr
Posted
11 days ago
Freshness
Confirmed live yesterday
Closes
Nov 30, 2026

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $174k
This role $281k
$106k most similar roles pay here $362k

This role pays more than 94% of similar roles. Most pay $144,375–$203,500 — the shaded band above. At the midpoint, this role pays about $281k versus about $174k for comparable roles.

Based on 240 similar postings.

Employer

About State Street

State Street Corporation is one of the world''s largest custodian banks and asset managers, providing investment servicing, investment management, and investment research to institutional investors. Industry: Financial Services & Asset Custody

State Street currently has 210 open roles on FindRole.

Listed pay typically runs $120,000–$202,500 across 202 roles with salary data.

Most-posted roles

View all roles at State Street

At a glance

TL;DR · Head of Cyber & Information Security Oversight

Head of Cyber & Information Security Oversight (SVP) leads the global Cybersecurity Risk Oversight function within the Enterprise Technology Risk Management team. This role provides second line of defense oversight, review, and challenge for global cybersecurity and technology services. The successful candidate will establish cyber risk appetite, develop analytics using AI to provide insights, and manage governance forums like the Vulnerability Governance Forum. Key responsibilities include managing regulatory interactions with entities such as the FCA, PRA, HKMA, MAS, APRA, and ECB while ensuring compliance with frameworks including NIST-CSF, DORA, FFIEC, and MITRE ATT&CK. The role requires translating complex technical issues into business risk for executive leadership. Candidates must possess a CISSP certification and extensive experience in identity management, threat and vulnerability management, and information protection within the financial services or technology sectors to manage global cyber risks effectively.

What you'll do

  • Establish and operate the global Cybersecurity Risk Oversight function within the Enterprise Technology Risk Management department.
  • Define cyber risk appetite, policies, metrics, and thresholds while challenging risk acceptances from first-line business units.
  • Develop an analytics capability using AI to provide actionable cyber risk insights and customized reporting for various regions.
  • Lead senior governance forums, such as the Cybersecurity Risk Committee, to manage and oversee enterprise-wide security risks.
  • Act as a primary point of contact for global regulators regarding cyber risk management and the resolution of regulatory findings.
  • Provide second-line oversight and challenge to first-line cybersecurity controls, processes, and assurance programs.
  • Manage the annual Book of Work including risk assessments, continuous monitoring, and issue management across global teams.
  • Translate complex technical security issues into business risk terms for communication with executive leadership and the Board of Directors.

What we're looking for

  • Must have at least 15 years of experience in the financial services and/or technology industries.
  • Must have at least 5 years of experience in executive roles such as CISO, Deputy CISO, or equivalent in a G-SIB.
  • Must hold a CISSP or equivalent certification.
  • Must possess an undergraduate or advanced degree in a technology or cyber discipline.
  • Must be able to translate technical cybersecurity issues into business risk terms for senior executives and the Board of Directors.
  • Must have experience with regulatory exams and responses (preferred).
  • Must have experience in first line cybersecurity operations (preferred).
  • Must possess working knowledge of industry and regulatory frameworks such as FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM, and MITRE ATT&CK.

More like this

Similar roles

Business Information Security Officer VP

State Street

Quincy, MA +3 36 days ago $120,000–$202,500
Blockchain Digital Assets HSM MPC Smart Contracts AWS Azure Cloud Security Cryptography Key Management IAM PAM SOC SIEM DevSecOps SDLC NIST Cybersecurity Framework Vulnerability Management Incident Response Machine Learning
6+ yrs exp

Business Information Security Officer AVP

State Street

Quincy, MA 22 days ago $90,000–$157,500
Cyber Risk Management Network Security SaaS Zero Trust Secure SDLC Vulnerability Management Patch Management Configuration Management Data Protection Threat Intelligence NIST ISO SOC FFIEC Risk Assessment Security Architecture

Business Information Security Officer AVP

State Street

Boston, MA +1 36 days ago $90,000–$157,500
AWS Azure Network Security Cryptography Identity and Access Management (IAM) Vulnerability Management Incident Response DevSecOps Secure SDLC SIEM NIST CSF 2.0 NIST SP 800-53 ISO 27001 Machine Learning Generative AI
8+ yrs exp

Cyber Intelligence Vice President

JPMorgan Chase

Washington, DC 47 days ago
Threat Intelligence OSINT Python Bash JavaScript PowerShell SIEM Splunk Elasticsearch MITRE ATT&CK NIST Cybersecurity Framework ISO 27001 Third-Party Risk Management Data Analysis Machine Learning AI Incident Response
5+ yrs exp

Cyber Security Review Program Lead

Pacific Life

Newport Beach, CA +1 81 days ago $137,000–$168,000
Cybersecurity Risk Management NIST Cybersecurity Framework COBIT 2019 NIST Privacy Framework Security Review Automation AI Change Management Architecture Review Governance
6+ yrs exp Hybrid

Senior Risk Specialist, Tech Risk

Capital One Financial

McLean, VA +1 3 days ago $111,200–$126,900
Cybersecurity Risk Management AI Cloud Computing AWS GCP Azure Infrastructure as Code Identity and Access Management Application Security Data Protection Site Reliability Engineering Chaos Engineering Business Continuity Disaster Recovery RCSA KRI
2+ yrs exp