Talent.com
No longer accepting applications
Head of Cyber Security Risk Oversight, Managing Director

Head of Cyber Security Risk Oversight, Managing Director

The Security Executive CouncilBoston, MA, United States
30+ days ago
Job type
  • Full-time
Job description

Head of Cyber Security Risk Oversight, Managing Director

Organization

State Street

Description

Overview

About the job

Who We Are Looking For

It is an exciting time to join State Street Corporation (SSC) in the Enterprise Technology Risk Management (ETRM) organization. ETRM is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Cyber and Technology Risks across the enterprise. We are looking for a seasoned Cyber and Information Security Risk Leader with more than 15 years of experience in the financial services and / or technology industry. The qualified candidate should be well versed in identifying, assessing, managing and monitoring cyber risks across several domains such as Identity and Access, Information Protection, Threat and Vulnerability Management, Cyber Incident and Response, Application security, Secure configuration, Security architecture and cyber risks related to Third parties. The position interacts with all levels of management and senior level executives in IT, including CISO, Sr. BISO, Head of Cyber GRC, CTO, CIO, etc. Therefore, exceptional interpersonal and communication skills are required. Candidates must demonstrate strong initiative, be able to perform well under pressure and be capable of managing multiple and diverse assignments. The successful candidate will report into the Global Head of Technology and Cyber Risk, who reports to the Chief Operational and Technology Risk Officer within the Operational Risk Management second line function. They will lead, guide and mentor a team of seasoned ETRM Cyber risk professionals to provide Second Line of Defense (SLoD) oversight, review and challenge on Global Cybersecurity and Global Technology Services First Line Organization. This role will require periodic communication with internal audit and regulators in the financial services domain and therefore, prior experience with regulators is strongly desired. Experience with Technology risk, Resiliency, Cloud Risk Management (AWS, Azure), Enterprise Architecture is a plus.

Why this role is important to us

ETRM plays an important role in the overall success of the organization and our mission is to establish a world class Technology Risk Management program that aligns business and technology risk to enable effective decision making. The organization is going through a significant transformation, and you will lead key cyber risk assessments on material projects and ensure the identified risks are being prudently managed. This position will also include providing thought leadership and support to both your peers in ETRM and your stakeholders in the business and corporate areas. You will need to periodically participate in meetings with our key regulators and provide support and advice to your stakeholders during regulatory exams and regulatory finding validations.

What You Will Be Responsible For

  • Your mission is to act as the ETRM advisor to the first line of defense (FLOD) on matters relating to the Cyber risk posture of State Street as benchmarked against applicable laws and regulations, rules, standards and best practices. More specifically, you will be :
  • Ensuring cyber risks and non-compliance with internal and external standards are proactively identified, prudently managed, and effectively challenged
  • Identifying / assessing / controlling / monitoring risks and supporting FLOD in planning / executing controls and additional compensating controls
  • Participating in various risk governance forums and executing real time oversight and challenge
  • Monitoring cyber risk appetite, reporting breaches, escalating exceptions and challenging risk acceptances
  • Providing an independent opinion on FLOD Cyber risk management, recommending appropriate improvements
  • Review and challenge the first line cyber controls assurance program and the constituent cyber processes
  • Interacting with the Enterprise Process Owners for the Cyber processes and foster deeper and integrated FLOD / SLOD relationships and embedded risk management
  • Communicate and drive effective implementation of ETRM risk management policies, framework, tools, guidelines and standards across the business ensuring cyber risks are identified and managed effectively.
  • Provide strategic leadership, vision and on-going support to the First line of Defense (FLOD) regarding cybersecurity related best practices and trends
  • Advise FLOD in prioritization of risks, risk initiatives, risk mitigation alternatives
  • Review and appropriately challenge cyber risk response decisions, directions, and initiatives undertaken by the FLOD providing an independent voice to the risk management process
  • Provide support and advice to ETRM and your stakeholders for regulatory exams and regulatory findings
  • Collaborate with and support regional (APAC and EMEA ETRM) peers in matters related to cyber and information security risks
  • Deliver assigned ETRM annual book of work (risk assessments, continuous monitoring, issues management, reporting etc) through the established risk leads within the team and engaging the ETRM India Service Center of Excellence
  • Utilize available Enterprise Risk and Operational risk management tools (NBPRA, MRI, RCSA, KRI’s, Incident data, Loss event data) in conjunction with other environmental changes to proactively monitor the control environment and identify and address potential weaknesses and / or gaps in a timely manner
  • Keep abreast of new products, services, technologies and applications as well as their respective impact on the organization’s risk profile
  • Serve as a subject matter expert in cyber risk, controls, compliance, best practices

What We Value

These skills will help you succeed in this role

  • Collaborative
  • Ability to influence, obtain buy in and drive implementation of decisions
  • Strategic mindset linking multiple aspects and initiatives to drive a wholistic view of the risk and control environment
  • Excellent Communication skills
  • Leading and developing a team
  • Being an effective mentor and coach
  • Ability to be a strong voice for review and challenge while continuing to maintain positive relationships with business stakeholders
  • An ability to be a leader within their team, as well as being a leader amongst your peers
  • Qualifications

    Education & Preferred Qualifications

    Education & Preferred Qualifications

  • Minimum 15 years of experience in the financial, and or technology industries
  • This position requires interacting with “C” level suite, so superior communication, interpersonal, negotiation, presentation and intergroup skills are critical for success
  • The ability to translate technical issues into risk terms that business can understand is necessary
  • Experience with regulatory exams and responses is strongly desired
  • Advanced degree or undergraduate degree in technology / cyber disciple or equivalent
  • Thought leadership around cyber risks is a must
  • Experience in first line, risk management, compliance or audit, including but not limited to experience in design & implementation of control frameworks, penetration testing, cyber incident detection and response, encryption and data protection, EDR, SIEM, SOC
  • CISSP or equivalent is appreciated but not mandatory
  • Working knowledge of industry and regulatory risk and control standards and frameworks such as FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM, and MITRE ATTACK is expected
  • Compensation

    Salary Range

    $170,000 - $282,500 Annual

    The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

    We know how to fine-tune corporate security because we've led effective and efficient Fortune 500-level security programs. The SEC helps businesses find the best balance of risk mitigation, cost and innovation.

    Want insight delivered to your inbox? Subscribe to Security Insight newsletter.

    #J-18808-Ljbffr

    Create a job alert for this search

    Head Of Security • Boston, MA, United States

    Related jobs
    • Promoted
    Director, Revenue Acceleration - Next Generation Security

    Director, Revenue Acceleration - Next Generation Security

    Palo Alto NetworksBoston, MA, US
    Full-time
    Director, Revenue Acceleration - Next Generation Security.At Palo Alto Networks everything starts and ends with our mission : Being the cybersecurity partner of choice, protecting our digital way of...Show moreLast updated: 10 days ago
    • Promoted
    Director, Infrastructure & Security Operations

    Director, Infrastructure & Security Operations

    Brooks AutomationChelmsford, MA, US
    Full-time
    Director, Infrastructure & Security Operations.Brooks is seeking a dynamic and hands-on Director of Infrastructure & Security Operations to lead and mature our global IT infrastructure and SecOps c...Show moreLast updated: 30+ days ago
    • Promoted
    Technology and Cybersecurity Risk Governance, Managing Director

    Technology and Cybersecurity Risk Governance, Managing Director

    State StreetQuincy, MA, US
    Full-time
    Technology and Cyber Risk Governance Leader.It is an exciting time to join State Street Corporation (SSC) in the Enterprise Technology Risk Management (ETRM) organization.ETRM is responsible for th...Show moreLast updated: 12 days ago
    • Promoted
    Senior Director Head of Site Management and Monitoring Oversight

    Senior Director Head of Site Management and Monitoring Oversight

    CSL Plasma Inc.Waltham, MA, United States
    Full-time
    CSL's R&D organization is accelerating innovation to deliver greater impact for patients.With a project-led structure and a focus on collaboration, we’re building a future-ready team that thrives i...Show moreLast updated: 7 days ago
    • Promoted
    Director, Threat Management

    Director, Threat Management

    ModernaCambridge, MA, US
    Permanent
    Insider Risk And Threat Management Director.This role leads Moderna's Insider Risk and Threat Management program, with responsibility for designing, implementing, and sustaining strategies that pre...Show moreLast updated: 27 days ago
    Cybersecurity Lead

    Cybersecurity Lead

    CenturiaHanscom Afb, Massachusetts, United States, 01731
    Full-time
    Job Title : Wing Cyberspace Lead.Location : Hanscom Air Force Base.Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions to...Show moreLast updated: 6 days ago
    • Promoted
    VP, Enterprise Risk Management

    VP, Enterprise Risk Management

    ISACABrookline, MA, United States
    Full-time
    Reporting to the SVP, Chief Compliance Officer, the VP of Enterprise Risk Management (ERM) will serve as the key leader responsible for providing oversight, innovation, and strategic direction to d...Show moreLast updated: 30+ days ago
    • Promoted
    Head of Security Operations

    Head of Security Operations

    CanonicalBoston, MA, United States
    Full-time
    This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, to...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Architect (Director level, individual contributor)

    Lead Security Architect (Director level, individual contributor)

    ManulifeBoston, MA, United States
    Full-time
    At Manulife, we are changing the way we unlock value and secure the enterprise through technology and we want you to be part of it! We are growing our cybersecurity program with the vision to deliv...Show moreLast updated: 2 days ago
    • Promoted
    Sr. Managing Director, Technical Risk Engineering

    Sr. Managing Director, Technical Risk Engineering

    The HartfordBoston, MA, United States
    Full-time
    Why consider this job opportunity.Opportunity for career advancement and growth within the organization.Potential for short-term or annual bonuses and long-term incentives.Collaborative and inclusi...Show moreLast updated: 2 days ago
    • Promoted
    Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

    Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)

    Insulet Corporation, MA, United States
    Full-time
    Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA) page is loaded## Senior Director, Cyber Security (Hybrid - San Diego, CA or Acton, MA)locations : San Diego, California : Act...Show moreLast updated: 13 days ago
    • Promoted
    • New!
    Cyber Infrastructure Security Compliance Lead

    Cyber Infrastructure Security Compliance Lead

    Banco Santander SABoston, MA, United States
    Full-time
    Cyber Infrastructure Security Compliance LeadCountry : United States of America • •Your Journey Starts Here : • •Santander is a global leader and innovator in the financial services industry.We believe t...Show moreLast updated: 6 hours ago
    • Promoted
    Cybersecurity SME

    Cybersecurity SME

    AvintNorth Lexington, MA, US
    Full-time
    Applicants must have an Active Top Secret Clearance • •.The Cybersecurity SME serves as a cybersecurity and RMF expert within the technical domain and acts as a senior advisor to government cybersecu...Show moreLast updated: 30+ days ago
    • Promoted
    Executive Director, Security & Information Protection

    Executive Director, Security & Information Protection

    Odyssey SystemsWakefield, MA, US
    Full-time
    Executive Director Of Security & Information Protection.Odyssey is seeking an Executive Director of Security & Information Protection to lead the recently formed Security & Information Protection g...Show moreLast updated: 30+ days ago
    • Promoted
    Vice President, Corporate Information Technology & Security Risk Management

    Vice President, Corporate Information Technology & Security Risk Management

    ZOLL Medical CorporationChelmsford, MA, US
    Full-time
    Vice President, Corporate Information Technology & Security Risk Management.At ZOLL, we're passionate about improving patient outcomes and helping save lives. We provide innovative technologies that...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Director of Cyber Third-Party Assurance

    Director of Cyber Third-Party Assurance

    MassMutualBoston, MA, United States
    Full-time
    Full-Time, Boston, Springfield.As the Director of the Cyber Third-Party Assurance team you will work in a fast-paced, collaborative environment overseeing the onboarding and continuous monitoring o...Show moreLast updated: 6 hours ago
    • Promoted
    VP, Head of Information Security & Infrastructure

    VP, Head of Information Security & Infrastructure

    Berkshire Residential InvestmentsBoston, MA, United States
    Full-time
    Berkshire Residential Investments is a people-first real estate investment company who values not only the impact we make as a company, but the time we spend together in our high-performing teams.W...Show moreLast updated: 30+ days ago
    • Promoted
    VP, Head of Information Security & Infrastructure

    VP, Head of Information Security & Infrastructure

    BerkshireBoston, MA, United States
    Full-time
    VP, Head of Information Security & Infrastructure.VP, Head of Information Security & Infrastructure.Berkshire Residential Investments is a people-first real estate investment company who values not...Show moreLast updated: 30+ days ago
    • Promoted
    Head of Operational Risk Assessments and Governance

    Head of Operational Risk Assessments and Governance

    MassMutualBoston, MA, United States
    Full-time
    Head of Operational Risk Assessments and Governance.MassMutual is seeking a strategic and experienced risk leader to serve asHead of Operational Risk Assessments and Governance.This second line of ...Show moreLast updated: 6 days ago
    • Promoted
    Lead Security Architect (Director level, individual contributor)

    Lead Security Architect (Director level, individual contributor)

    Manulife Insurance MalaysiaBoston, MA, United States
    Full-time
    Nous utilisons des • •pour fournir des statistiques qui nous aident à vous offrir la meilleure expérience sur note site.Vous y trouverez des renseignements sur les témoins, ou vous pouvez les désac...Show moreLast updated: 6 days ago