State Street
Who We Are Looking For We are looking for a Vice President of Cyber Security reporting to the Regional CISO, UK & Ireland. You will act as a senior cyber advisor embedded in the region, partnering closely with business, technology, risk, and compliance teams to ensure cyber security priorities are shaped around regional business needs, regulatory obligations, and client commitments, while still drawing on strong technical expertise to identify practical security improvements and drive change that strengthens cyber resilience. The successful candidate will bring strong business acumen and stakeholder judgement, underpinned by solid technical credibility across offensive security, cyber risk, and security solution architecture. You will be comfortable engaging regional business and legal entity leaders on their priorities, reviewing complex technology and control issues, challenging proposed approaches constructively, and translating technical risk into clear, actionable decisions for senior stakeholders. Why This Role is Important To Us The team you will be joining is part of the Regional CISO organization within Global Cybersecurity (GCS), a key function to the bank because it connects global cyber capabilities with regional business, regulatory, legal entity, and client priorities. This is a vital role in ensuring the region's businesses and legal entities are supported with cyber requirements and implementation guidance that reflect local regulatory expectations, client needs, and operational priorities, helping the bank remain secure in a rapidly evolving threat landscape. What You Will Be Responsible For In this role, you will: Act as the regional point of orchestration for cross-functional cyber activities, ensuring business, technology, risk, and legal entity priorities are understood, owned, prioritised, and progressed through to measurable outcomes. Provide senior cyber advisory and constructive challenge and support to business and technology teams, ensuring cyber security decisions support regional business objectives and legal entity requirements. Lead or materially contribute to regulatory alignment activities, including impact assessments, evidence reviews, responses to supervisory queries, readiness reviews, and remediation tracking for the region. Prepare clear briefings, papers, risk narratives, and executive updates for senior stakeholders, governance forums, legal entity committees, and Regional CISO leadership. Support client, business, and external engagement where specialist cyber input is required, presenting the bank's cyber posture and improvement activity in a clear and credible manner. Review complex cyber issues and support solution design, including findings from, vulnerability management, security architecture, and secure processes. Translate security insights into practical, risk-based remediation plans that reduce risk exposure for the organization. Drive change across the bank by identifying recurring control weaknesses, root causes, and opportunities to simplify or improve cyber processes, governance, metrics, and accountability. What We Value These skills will help you succeed in this role Strong business acumen with the ability to understand regional business, regulatory, and client priorities, and to shape cyber security advice accordingly. Strong influencing and change leadership skills, with the confidence to challenge constructively and bring business and technical teams together around executable solutions. Ability to convert regulatory expectations and audit findings into pragmatic implementation plans that work in a complex banking environment. Excellent written and verbal communication skills, including the ability to explain technical risk in concise, business-relevant language. We are looking for a strong technical candidate with hands on experience who is able to translate complex technical solutions to both senior technology and business stakeholders. Technical cyber knowledge with the credibility to engage senior engineers, architects, offensive security specialists, risk teams, and senior business stakeholders. Practical offensive security awareness, including attack paths, common enterprise weaknesses, penetration testing outputs, red/purple team findings, exploitability, and risk based remediation. Security solution architecture knowledge across cloud, identity and access management, network security, application security, endpoint, data protection, third party connectivity, and resilience controls. Sound judgement, ownership mindset, and the ability to balance risk reduction, regulatory expectations, business delivery, and operational practicality. Education & Preferred Qualifications Degree: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Risk Management, or a related discipline preferred; equivalent industry experience will always be considered. Years of experience: Typically 10-15 years of experience in cyber security, technology risk, security architecture, offensive security, cyber consulting, operational resilience, or a related financial services role. Certifications: Relevant certification to support relevant experience such as CISSP, CSSLP, GIAC GSSP, OSWE, SABSA, SABSA and vendor specific certification. Knowledge of tools or technologies: Practical and demonstrable knowledge of coding, application security, security architecture . Role Experience: Experience in senior BISO roles at Financial Services or Critical National Infrastructure organizations is preferred but not required. Ability to demonstrate work in complex and advanced cyber security environments is a benefit. Additional language requirements: N/A. Additional Requirements Additional requirements for this role include: Some travel may be required for regional stakeholder, client, industry, or regulatory engagement. The role may occasionally support urgent cyber, regulatory, or incident related activity outside standard working hours. The candidate must be able to handle confidential and sensitive information appropriately. Work Requirement Hybrid Work Requirement: London based hybrid working arrangement, with regular presence in the London office in line with business and team requirements. Shift Timings: UK business hours, with flexibility required to support global stakeholders and time sensitive cyber or regulatory matters. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement Job ID: R-795098
Who We Are Looking For We are looking for a Vice President of Cyber Security reporting to the Regional CISO, UK & Ireland. You will act as a senior cyber advisor embedded in the region, partnering closely with business, technology, risk, and compliance teams to ensure cyber security priorities are shaped around regional business needs, regulatory obligations, and client commitments, while still drawing on strong technical expertise to identify practical security improvements and drive change that strengthens cyber resilience. The successful candidate will bring strong business acumen and stakeholder judgement, underpinned by solid technical credibility across offensive security, cyber risk, and security solution architecture. You will be comfortable engaging regional business and legal entity leaders on their priorities, reviewing complex technology and control issues, challenging proposed approaches constructively, and translating technical risk into clear, actionable decisions for senior stakeholders. Why This Role is Important To Us The team you will be joining is part of the Regional CISO organization within Global Cybersecurity (GCS), a key function to the bank because it connects global cyber capabilities with regional business, regulatory, legal entity, and client priorities. This is a vital role in ensuring the region's businesses and legal entities are supported with cyber requirements and implementation guidance that reflect local regulatory expectations, client needs, and operational priorities, helping the bank remain secure in a rapidly evolving threat landscape. What You Will Be Responsible For In this role, you will: Act as the regional point of orchestration for cross-functional cyber activities, ensuring business, technology, risk, and legal entity priorities are understood, owned, prioritised, and progressed through to measurable outcomes. Provide senior cyber advisory and constructive challenge and support to business and technology teams, ensuring cyber security decisions support regional business objectives and legal entity requirements. Lead or materially contribute to regulatory alignment activities, including impact assessments, evidence reviews, responses to supervisory queries, readiness reviews, and remediation tracking for the region. Prepare clear briefings, papers, risk narratives, and executive updates for senior stakeholders, governance forums, legal entity committees, and Regional CISO leadership. Support client, business, and external engagement where specialist cyber input is required, presenting the bank's cyber posture and improvement activity in a clear and credible manner. Review complex cyber issues and support solution design, including findings from, vulnerability management, security architecture, and secure processes. Translate security insights into practical, risk-based remediation plans that reduce risk exposure for the organization. Drive change across the bank by identifying recurring control weaknesses, root causes, and opportunities to simplify or improve cyber processes, governance, metrics, and accountability. What We Value These skills will help you succeed in this role Strong business acumen with the ability to understand regional business, regulatory, and client priorities, and to shape cyber security advice accordingly. Strong influencing and change leadership skills, with the confidence to challenge constructively and bring business and technical teams together around executable solutions. Ability to convert regulatory expectations and audit findings into pragmatic implementation plans that work in a complex banking environment. Excellent written and verbal communication skills, including the ability to explain technical risk in concise, business-relevant language. We are looking for a strong technical candidate with hands on experience who is able to translate complex technical solutions to both senior technology and business stakeholders. Technical cyber knowledge with the credibility to engage senior engineers, architects, offensive security specialists, risk teams, and senior business stakeholders. Practical offensive security awareness, including attack paths, common enterprise weaknesses, penetration testing outputs, red/purple team findings, exploitability, and risk based remediation. Security solution architecture knowledge across cloud, identity and access management, network security, application security, endpoint, data protection, third party connectivity, and resilience controls. Sound judgement, ownership mindset, and the ability to balance risk reduction, regulatory expectations, business delivery, and operational practicality. Education & Preferred Qualifications Degree: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Risk Management, or a related discipline preferred; equivalent industry experience will always be considered. Years of experience: Typically 10-15 years of experience in cyber security, technology risk, security architecture, offensive security, cyber consulting, operational resilience, or a related financial services role. Certifications: Relevant certification to support relevant experience such as CISSP, CSSLP, GIAC GSSP, OSWE, SABSA, SABSA and vendor specific certification. Knowledge of tools or technologies: Practical and demonstrable knowledge of coding, application security, security architecture . Role Experience: Experience in senior BISO roles at Financial Services or Critical National Infrastructure organizations is preferred but not required. Ability to demonstrate work in complex and advanced cyber security environments is a benefit. Additional language requirements: N/A. Additional Requirements Additional requirements for this role include: Some travel may be required for regional stakeholder, client, industry, or regulatory engagement. The role may occasionally support urgent cyber, regulatory, or incident related activity outside standard working hours. The candidate must be able to handle confidential and sensitive information appropriately. Work Requirement Hybrid Work Requirement: London based hybrid working arrangement, with regular presence in the London office in line with business and team requirements. Shift Timings: UK business hours, with flexibility required to support global stakeholders and time sensitive cyber or regulatory matters. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement Job ID: R-795098
State Street
Job Description The Security Guardian - Blockchain & Smart Contract Security, Vice President , provides cyber risk management advisory services to the digital product line of business within State Street. This role is responsible for working closely with the development teams and aligned cybersecurity peers in protecting digital assets and blockchain systems by identifying vulnerabilities and issues, designing security controls, evaluating 3rd party cyber controls, designing threat models, and implementing Crypto Currency Security Standards (CCSS). The Information Security Officer will be a strategic change agent that, in addition to providing cyber advisory services to the digital product team, will also be a thought leader to protect the bank. Focusing on transformation, the Information Security Officer will assess ways to further strengthen the banks' cyber security resiliency aligned to the digital products. Key Responsibilities Include Cyber risk assessment at the application/platform/system levels to identify vulnerabilities and potential threats. Through collaboration, design appropriate end to end cyber remediation solutions to remediate risk. Oversee the timely remediation of cyber issues aligned to digital product. Strong technical collaboration with application and platform owners. Provide expert guidance and recommendations to senior management on security matters, including risk mitigation solutions, new attack vectors and prevention, and securing blockchain architecture and decentralized applications. Strong technical expertise in at least three focus areas specifically in Multi-Cloud, AI, Blockchain, Smart Contracts and cryptography. Fundamental understanding of data structures and algorithms. Strong technical knowledge in network security, product security, and data protection. Strong conceptual understanding of public, private, consortium, and hybrid blockchain technologies. Good understanding of agile methodology, procedures, and iterative decision making. Qualifications At least 7 years of progressive cybersecurity experience with 3+ years within financial services. 2+ years of operationally focused cybersecurity practitioner working with blockchain technologies 2+ years' experience working with business leadership across enterprise projects. Strong analytical and problem-solving skills, excellent communication (written and verbal) and advisory skills, attention to detail, ability to work independently and in teams, adaptability, and ethical judgment. Demonstrate strategic and tactical thinking, along with decision-making skills and business acumen. Strong knowledge of applied cryptography and secure architecture/design principles related to blockchain and smart contracts. Proven experience auditing and securing blockchain platforms and smart contracts based applications Strong knowledge of common vulnerabilities and their mitigations in blockchain and smart contracts platforms Beneficial to have secure programming experience in Python and Solidity but not required. At least one - Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Blockchain Security Professional (CBSP), or Certified AI Security Professional (CAISP). AWS or Azure Cloud Security is preferable but not required. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement Job ID: R-778913
Job Description The Security Guardian - Blockchain & Smart Contract Security, Vice President , provides cyber risk management advisory services to the digital product line of business within State Street. This role is responsible for working closely with the development teams and aligned cybersecurity peers in protecting digital assets and blockchain systems by identifying vulnerabilities and issues, designing security controls, evaluating 3rd party cyber controls, designing threat models, and implementing Crypto Currency Security Standards (CCSS). The Information Security Officer will be a strategic change agent that, in addition to providing cyber advisory services to the digital product team, will also be a thought leader to protect the bank. Focusing on transformation, the Information Security Officer will assess ways to further strengthen the banks' cyber security resiliency aligned to the digital products. Key Responsibilities Include Cyber risk assessment at the application/platform/system levels to identify vulnerabilities and potential threats. Through collaboration, design appropriate end to end cyber remediation solutions to remediate risk. Oversee the timely remediation of cyber issues aligned to digital product. Strong technical collaboration with application and platform owners. Provide expert guidance and recommendations to senior management on security matters, including risk mitigation solutions, new attack vectors and prevention, and securing blockchain architecture and decentralized applications. Strong technical expertise in at least three focus areas specifically in Multi-Cloud, AI, Blockchain, Smart Contracts and cryptography. Fundamental understanding of data structures and algorithms. Strong technical knowledge in network security, product security, and data protection. Strong conceptual understanding of public, private, consortium, and hybrid blockchain technologies. Good understanding of agile methodology, procedures, and iterative decision making. Qualifications At least 7 years of progressive cybersecurity experience with 3+ years within financial services. 2+ years of operationally focused cybersecurity practitioner working with blockchain technologies 2+ years' experience working with business leadership across enterprise projects. Strong analytical and problem-solving skills, excellent communication (written and verbal) and advisory skills, attention to detail, ability to work independently and in teams, adaptability, and ethical judgment. Demonstrate strategic and tactical thinking, along with decision-making skills and business acumen. Strong knowledge of applied cryptography and secure architecture/design principles related to blockchain and smart contracts. Proven experience auditing and securing blockchain platforms and smart contracts based applications Strong knowledge of common vulnerabilities and their mitigations in blockchain and smart contracts platforms Beneficial to have secure programming experience in Python and Solidity but not required. At least one - Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Blockchain Security Professional (CBSP), or Certified AI Security Professional (CAISP). AWS or Azure Cloud Security is preferable but not required. About State Street Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success. We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. Discover more information on jobs at Read our CEO Statement Job ID: R-778913