VP, Information Security Officer managing cyber risk and advisory services at State Street. Collaborating with teams to protect digital assets and enhance security measures across the organization.
Responsibilities
Cyber risk assessment at the application/platform/system levels to identify vulnerabilities and potential threats.
Through collaboration, design appropriate end to end cyber remediation solutions that align to regulatory or industry standards to remediate risk.
Design security capabilities within the development teams allow them to build scale across all scrum teams.
Strong technical collaboration and cyber influence with application and platform owners.
Provide expert guidance and recommendations to senior management on security matters, including risk mitigation solutions, new attack vectors and prevention, and metrics to identify areas of improvement in processes.
Optimize ways to increase security and speed of deployment, while reducing friction within the development cycle.
Collective design and optimize strong DevSecOps models.
Evaluate third party software and services that strengthen cyber capabilities.
Establish a targeted awareness campaign for developers that fosters a “security-first” culture, promotes collaboration, and encourages proactive ownership.
Work directly with technology developers in an agile security lifecycle environment from requirements through deployment and response.
Requirements
At least 7 years of progressive cybersecurity experience with 3+ years within financial services.
3+ years of operationally focused cybersecurity practitioner working with secure cloud technologies.
2+ years’ experience working with business leadership across enterprise projects.
Strong analytical and problem-solving skills, excellent communication (written and verbal) and advisory skills, attention to detail, ability to work independently and in teams, adaptability, and ethical judgment.
Strong technical expertise in at least two focus areas specifically in Multi-Cloud, AI, Software Supply Chain, and Quantum Computing.
Fundamental understanding of data structures, algorithms, and secure coding practices.
Strong working knowledge of secure architectural design principles such as defense in depth, simplification, and secure by design.
Strong technical knowledge in network security, product security, and data protection.
Strong understanding of encryption, tokenization, and hashing.
Good working knowledge of agile methodology, procedures, and iterative decision making.
Demonstrate strategic and tactical thinking, along with decision-making skills and business acumen.
Benefits
retirement savings plan (401K) with company match
insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
paid-time off including vacation, sick leave, short term disability, and family care responsibilities
access to our Employee Assistance Program
incentive compensation including eligibility for annual performance-based awards
Cloud Security Engineer supporting and securing client environments across AWS and hybrid infrastructures. Collaborating with Cloud Operations to monitor, investigate, and remediate security events.
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.
Cybersecurity Assessment Expert at IT - Strat managing A&A of information systems for U.S. federal clients. Ensuring compliance with DOD cybersecurity policies and standards in complex IT environments.
Senior Security Engineer responsible for deploying and maintaining endpoint security solutions. Collaborating across teams to enhance security posture and supporting incident response activities.