Talent.com
Technology and Cybersecurity Risk Governance, Managing Director
Technology and Cybersecurity Risk Governance, Managing DirectorState Street • Quincy, MA, US
No longer accepting applications
Technology and Cybersecurity Risk Governance, Managing Director

Technology and Cybersecurity Risk Governance, Managing Director

State Street • Quincy, MA, US
30+ days ago
Job type
  • Full-time
Job description

Technology and Cyber Risk Governance Leader

It is an exciting time to join State Street Corporation (SSC) in the Enterprise Technology Risk Management (ETRM) organization. ETRM is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Technology Risk and Cyber Risks across the enterprise. We are looking for a seasoned Technology and Cyber Risk Governance Leader with more than 15 years' experience in financial services and / or technology industry. The qualified candidate should be well versed in identifying, managing and monitoring technology and cyber risks through the establishment of risk management processes, frameworks, methodologies, policy setting, escalation guidelines, monitoring and reporting. The position interacts with all levels of management and senior level executives in IT viz. Head of First Line Risk and Controls, Head of First Line Controls Design, Head of First Line Controls Assurance, Second Line Enterprise Risk Governance Team and Second Line Operational Risk Management Team. Therefore, exceptional interpersonal and communication skills are required. Candidates must demonstrate strong initiative, be able to perform well under pressure and be capable of managing multiple and diverse assignments. The successful candidate will report in to the Global Head of Technology and Cyber Risk. The role will establish and operationalize foundational governance program, assisted by a team of ETRM Risk professionals in alignment with the broader Enterprise Risk Management and Operational Risk Management Programs and mandates. This role will require periodic communications with internal audit and regulators in the financial services domain and therefore, prior experience with regulators is strongly desired. Experience with Cyber and Information Security, Cloud Risk Management (AWS, Azure), Enterprise Architecture, Technology and Operational Resilience is a plus.

ETRM plays an important role in the overall success of the organization and our mission is to establish a world class Technology and Cyber Risk Management Oversight program that aligns business and technology strategies to enable effective decision making. The organization is going through large transformations and risk reduction initiatives and you will establish and operationalize standardized and structured governance aspects to support prudent decision making and timely escalation of risks. This position will also include providing thought leadership and support to both your peers in ETRM and your stakeholders in the business and corporate areas. You will need to periodically participate in meetings with our key regulators and provide support and advise to your stakeholders during regulatory exams and regulatory finding validations.

Your mission is to act as the ETRM advisor to the IT organization and first line of defense (FLOD) control function on matters relating to the IT risk posture of State Street as benchmarked against applicable laws and regulations, rules, standards and best practices. More specifically, you will be :

  • Ensuring technology and cyber risks and non-compliance with internal and external standards are proactively identified, prudently managed, and effectively challenged
  • Maintain the Technology Risk Policy and lead its integration into the broader enterprise risk and operational risk policies
  • Support the definition of technology and cyber risk appetite statements, measurement through metrics and reporting thereof
  • Enhance the design of ETRM's second line risk opinion, in close conjunction with ERM, ORM and ETRM global and regional leads and support the Analytics lead in the generation and reporting to various risk governance forums on a monthly basis
  • Participating in various risk governance forums and executing real time oversight and challenge
  • Facilitate in the adoption of the Enterprise Technology Risk Framework for technology and cyber processes
  • Monitoring technology risk appetite, reporting breaches, escalating exceptions and challenging risk acceptances
  • Facilitate the execution of the quarterly Material Risk Identification Program across the bank for Technology and Cyber Risks in conjunction with Enterprise Risk Management
  • Coordinate across various First line and ETRM leads on the execution and challenge of Risk Control Self Assessments
  • Communicate and drive effective implementation of ETRM risk management policies, framework, tools, guidelines and standards internally within ETRM and across the business ensuring technology risks are identified and managed effectively.
  • Provide strategic leadership, vision and on-going support to the First line of Defense (FLOD) and IT leaders regarding information technology and cyber risk governance best practices and trends
  • Advise IT and FLOD in prioritization of risks, risk initiatives, risk mitigation alternatives
  • Review and appropriately challenge risk decisions, direction, and initiatives under taken by the FLOD providing an independent voice to the risk management process
  • Provide support and advise to ETRM and your stakeholders for regulatory exams and regulatory findings
  • Collaborate with and support regional (APAC and EMEA ETRM) peers in matters related to technology risks
  • Deliver assigned ETRM services annual book of work (risk assessments, continuous monitoring, issues management, reporting etc) through the established risk leads within the team and engaging the ETRM India Service Center of Excellence
  • Keep abreast of new products, services, technologies and applications as well as their respective impact on the organization's risk profile and associated governance mechanisms
  • Serve as a subject matter expert in technology and cyber risk governance, controls, compliance, best practices

These skills will help you succeed in this role :

  • Collaborative
  • Ability to influence, obtain buy in and drive implementation of decisions
  • Strategic mindset linking multiple aspects and initiatives to drive a holistic view of the risk and control environment
  • Excellent Communication skills
  • Leading and developing teams
  • Being an effective mentor and coach
  • Ability to be a strong voice for review and challenge while continuing to maintain positive relationships with business stakeholders
  • An ability to be a leader within their team, as well as be a leader amongst your peers
  • Minimum 15 years of experience in the financial, and or technology industries

    This position requires interacting with "C" level suite, so superior communication, interpersonal, negotiation, presentation and intergroup skills are critical for success

    Ability to translate technical issues into risk terms that business can understand is absolutely necessary

    Experience with regulatory exams and responses is strongly desired

    Advanced degree or undergraduate in technology discipline or equivalent

    Thought leadership around technology and cyber risk governance, policy, frameworks and appetite is a must

    Experience in risk management, compliance or audit, including but not limited to experience in design & implementation of control frameworks is desired

    CRISC, CISSP, TOGAF, CCSK is appreciated but not mandatory

    Working knowledge of industry and regulatory risk and control standards and frameworks - FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM etc is expected

    We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don't necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.

    State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation, we're making our mark on the financial services industry. For more than two centuries, we've been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment research & trading and investment management to institutional clients.

    We make all efforts to create a great work environment. Our benefits packages are competitive and comprehensive. Details vary by location, but you may expect generous medical care, insurance and savings plans, among other perks. You'll have access to flexible Work Programs to help you match your needs. And our wealth of development programs and educational support will help you reach your full potential.

    State Street is an equal opportunity and affirmative action employer.

    Salary Range : $170,000 - $282,500 Annual

    The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

    It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

    Create a job alert for this search

    Governance Risk And • Quincy, MA, US

    Related jobs
    Cybersecurity Vulnerability Management Lead

    Cybersecurity Vulnerability Management Lead

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Vulnerability Management Team Lead to oversee cybersecurity vulnerability management efforts.Key Responsibilities : Develop and lead the enterprise-wide product security...Show more
    Last updated: 4 days ago • Promoted
    Director of Security Engineering

    Director of Security Engineering

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Director of Security Engineering.Key Responsibilities Manage a high-performing team of security engineers and oversee the security engineering budget Collaborate with ...Show more
    Last updated: 30+ days ago • Promoted
    Director of Vendor Governance

    Director of Vendor Governance

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Director - Vendor Governance to oversee and manage third-party supplier relationships within its Retirement & Income Solutions business. Key Responsibilities Lead strate...Show more
    Last updated: 30+ days ago • Promoted
    Operational Risk Director

    Operational Risk Director

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for an Operational Risk Director.Key Responsibilities Lead the operational risk strategy focusing on technology, product, change management, and business risks Conduct data-...Show more
    Last updated: 3 days ago • Promoted
    Manager, Cybersecurity & Operations

    Manager, Cybersecurity & Operations

    OpenGov • Boston, MA, United States
    Full-time
    OpenGov is the leader in AI and ERP solutions for local and state governments in the U.More than 2,000 cities, counties, state agencies, school districts, and special districts rely on the OpenGov ...Show more
    Last updated: 22 days ago • Promoted
    Cybersecurity IAM Manager

    Cybersecurity IAM Manager

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for an Identity & Access Management (IAM) Manager - Cybersecurity.Key Responsibilities Lead and mentor a global IAM team, fostering a collaborative and inclusive culture Dev...Show more
    Last updated: 3 days ago • Promoted
    IT & Cybersecurity Manager

    IT & Cybersecurity Manager

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for an IT & Cybersecurity Manager.Key Responsibilities Manage identity and access systems and support end users with IT-related issues Implement and monitor security control...Show more
    Last updated: 5 days ago • Promoted
    Director of Analytics

    Director of Analytics

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Director of Analytics.Key Responsibilities Lead analytics for a top mobile RPG, guiding strategic direction and insights Define and execute analytics strategies to enh...Show more
    Last updated: 30+ days ago • Promoted
    Director, Cloud Security Specialist

    Director, Cloud Security Specialist

    Fidelity Investments • Boston, MA, US
    Full-time
    The Cloud Security Center of Excellence within Fidelity Enterprise Cyber Security (ECS) is seeking a cloud or data platforms focused security engineer who has broad security domain knowledge includ...Show more
    Last updated: 12 hours ago • Promoted • New!
    Cybersecurity Risk Manager

    Cybersecurity Risk Manager

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Senior Manager Cybersecurity Risk to lead enterprise risk and compliance initiatives for commercial clients. Key Responsibilities Direct the Risk Services team in implem...Show more
    Last updated: 30+ days ago • Promoted
    Credit Risk Director

    Credit Risk Director

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Credit Risk Director to provide risk management oversight and challenge credit-related activities. Key Responsibilities Evaluate and challenge credit strategies using ad...Show more
    Last updated: 1 day ago • Promoted
    Director of Portfolio Risk Strategy

    Director of Portfolio Risk Strategy

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Director of Portfolio Risk & Strategy.Key Responsibilities Define and maintain risk appetite frameworks and credit policies for lending activities across international ...Show more
    Last updated: 3 days ago • Promoted
    Director of RADV Analytics

    Director of RADV Analytics

    VirtualVocations • Dorchester, Massachusetts, United States
    Full-time
    A company is looking for a Director of RADV Program Analytics & Risk Reporting.Key Responsibilities Manage and oversee the development of RADV risk exposure models and audit forecasting tools En...Show more
    Last updated: 2 days ago • Promoted
    Director of Fraud Analytics

    Director of Fraud Analytics

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Director of Fraud Strategy & Analytics to lead the design and execution of its credit card fraud defense strategy. Key Responsibilities Own the Fraud P&L and develop a c...Show more
    Last updated: 30+ days ago • Promoted
    Director of Secure Devices

    Director of Secure Devices

    Boston Consulting Group • Auburndale, MA, US
    Full-time
    Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy whe...Show more
    Last updated: 3 hours ago • Promoted • New!
    Cybersecurity Manager

    Cybersecurity Manager

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Manager, Cybersecurity.Key Responsibilities Develop and implement a comprehensive information security strategy and policies Lead and manage a team of information secu...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity C-SCRM Lead

    Cybersecurity C-SCRM Lead

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Cybersecurity IV&V and Supply Chain Security (C-SCRM) Lead.Key Responsibilities Serve as the lead technical advisor for Third-Party Cyber Risk Management (TPCRM) and In...Show more
    Last updated: 4 days ago • Promoted
    Cyber Resiliency Director

    Cyber Resiliency Director

    VirtualVocations • Lowell, Massachusetts, United States
    Full-time
    A company is looking for a Director of Cyber Resiliency.Key Responsibilities Lead and mentor the Cyber Resiliency team in areas such as cloud security engineering and incident readiness Design a...Show more
    Last updated: 2 days ago • Promoted