Hiring.Camp

Business Information Security Officer-AVP

Statestreet

·

Yesterday

Salary
$90k – $158k
Location
Quincy, Massachusetts, United States of America · BOSTON · CR1 - 700 District
Workplace
Hybrid
Type
Full-time
Department
Administration
Seniority
VP
Closing date
Today
Source
Workday

Description

AVP, Cyber Risk Advisor 

The AVP, Cyber Risk Advisor provides cyber risk advisory services focused on strengthening the firm's defensive cybersecurity posture through proactive risk management, cyber control oversight, vulnerability reduction, and security-by-design practices. The role serves as a trusted advisor to technology, infrastructure, application, and business teams, ensuring cybersecurity risks are identified, assessed, and managed in alignment with enterprise standards, regulatory expectations, and risk appetite. 

As a member of the Business Information Security organization, the AVP Cyber Security Advisor partners closely with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions and measurable reductions in cyber exposure. The successful candidate combines strong technical cybersecurity knowledge with the ability to influence stakeholders and translate complex cyber risks into actionable business guidance. 

Cyber Risk Advisory & Oversight 

  • Assess cyber risks associated with infrastructure, applications, cloud services, third party supply chain, and emerging technologies. 

  • Assess network designs, material changes, and new initiatives for security risk; review architecture artifacts and control implementations. 

  • Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture related to network controls. 

  • Support execution of enterprise cyber risk management objectives and control improvement initiatives across Saas platforms in support of client deliverables. 

Security Architecture & Design Influence 

  • Partner with network and cloud engineering teams to embed securitybydesign and resilience principles across onprem, cloud, and hybrid networks. 

  • Review and influence network segmentation, trust boundaries, ingress/egress controls, and monitoring strategies. 

  • Influence the alignment with security patterns with enterprise standards, zero trust principles, and regulatory obligations while working with cyber threat intel to build models. 

  • Partner with GCS Security Guardians to ensure current network security principals and guidance are updated and documented. 

Vulnerability and Exposure Management 

  • Partner with vulnerability management teams to prioritize remediation activities based on risk. 

  • Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures. 

  • Provide advisory support on patch management, configuration management, and security hardening efforts. 

  • Assist business and technology teams in developing sustainable remediation strategies. 

Risk Assessment & Control Governance 

  • Lead or support network security risk assessments, control gap analysis, and prioritization aligned to enterprise risk frameworks. 

  • Track remediation of identified control gaps and provide transparent risk reporting and escalation as needed. 

  • Support internal audits, regulatory reviews, and risk committees by articulating network security posture and key risks. 

Threat and Incident Advisory 

  • Provide advisory support during cyber incidents and events, including impact analysis, containment strategy guidance, and participate in playbook refinement. 

  • Partner with threat intelligence teams, cyber defense center, and vulnerability management teams to interpret emerging threats, model exposure, and appropriate remediation. 

Qualifications and Experience 

  • Strong technical understanding of enterprise networking concepts and security controls. 

  • Strong experience with network security technologies, secure cloud, Secure SDLC practices  

  • Experience in securing Software-as-a-Service delivery models (Identity, Data Protection, Monitoring, and Governance) 

  • Ability to assess architecture diagrams and design documents for security risk. 

  • Experience in cyber risk assessment, control evaluation, and remediation tracking. 

  • Strong written and verbal communication skills; able to influence without direct authority. 

  • Experience in regulated financial services or similarly complex environments. 

  • Exposure to regulatory expectations (e.g., FFIEC, NIST, ISO, SOC, or equivalent frameworks). 

  • Experience supporting audits, regulators, or executive risk forums. 

 

Salary Range:

$90,000 - $157,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Skills

CybersecuritySOCRisk Management

Similar Jobs

30

Business Information Security Officer

Att · SVK:BL:Bratislava / Einsteinova 24 - Adm:24 Einsteinova, Slovakia +1 · Remote

Yesterday

Business Information Security Officer (BISO) - CFO and GRM

Ghr · Washington, United States of America +2 · Onsite

6 days ago

Business Information Security Officer (BISO) - CFO and GRM

Ghr · Washington, United States of America +2 · Onsite

6 days ago

Business Information Security Officer - Americas

Unilever · Hoboken US HQ, United States of America

6 days ago

Business Information Security Officer

Allegis Global Solutions · Hanover, MD, United States · Hybrid

1 week ago

Business Information Security Officer

Barclays · Wilmington, 125 South West Street, United States of America

1 week ago

Senior Business Information Security Officer- Managing Director

Statestreet · Hyderabad, India

1 week ago

Business Information Security Officer

TMHCC enables you to take · Connecticut - Glastonbury, United States of America · Hybrid

1 week ago

Business Information Security Officer- AVP

Statestreet · BOSTON, United States of America +1

2 weeks ago

Business Information Security Officer-VP

Statestreet · Quincy, Massachusetts, United States of America +3

2 weeks ago

Business Information Security Officer - Operational Technology

Downer · Melbourne, VIC, Australia

3 weeks ago

Business Information Security Officer- Digital and Industrial Solutions

WSP · Montreal, QC, Canada

3 weeks ago

Senior Business Information Security Officer

mtb · Buffalo, NY, United States of America · Hybrid

1 month ago

Principal Business Information Security Officer

Quickenloans · Seattle - Hill7, United States of America

1 month ago

Sr Business Information Security Officer 

Lennar · St Petersburg FL (Fountain), United States of America

1 month ago

Business Information Security Principal

Capgroup · Irvine, United States of America

1 month ago

Director, Security Consulting — Business Information Security Officer (BISO) Commercial IT

AstraZeneca is · US - Gaithersburg - MD, United States of America

2 months ago

Enterprise Business Information Security Officer

Jabil · USA - St. Petersburg - RSV, United States of America · Remote, Onsite

2 months ago

Business Information Security Officer

Avnet · Poing, Germany +1 · Remote

2 months ago

Business Information Security Officer, Dental & Care Services

Bupa Careers · Staines, United Kingdom +1 · Hybrid

2 months ago

MTS- Information Security & Business Continuity Manager

Hrhub · Milan - Palazzo Mezzanotte, Italy · Hybrid, Onsite

2 months ago

Principal Business Information Security Officer (BISO)

Lplfinancial · Fort Mill/Charlotte, United States of America +1

3 months ago

Business Information Security Officer

Dolby · San Francisco, CA,US, US

3 months ago

Business Information Security Officer - GSC - US

Sysco · Sysco Corporate, United States of America · Hybrid, Onsite

3 months ago

Business Information Security officer MEI (BISO)

Fugro · Fugro House, D-222/30 Navi Mumbai IN, India +1 · Hybrid

3 months ago

Business Information Security Officer

Warnerbros · Shanghai Office - Jingan District, China · Onsite

3 months ago

Cyber Security Business Information Officer (BISO)

RELX Jobs · UK-Oxford (Nielsen House), United Kingdom +1

3 months ago

Cyber Security Business Information Officer (BISO)

Relx · UK-Oxford (Nielsen House), United Kingdom +1

3 months ago

Business Information Security Officer

Sysco · Sysco Corporate, United States of America · Hybrid, Onsite

7 months ago

Lead, Business Intelligence, Information Security Governance

Pru · Wash, 213 Washington St., Newark, NJ, United States of America · Remote, Hybrid, Onsite

2 weeks ago