Business Information Security Officer
State Street Corporation · Financial Services · 10,000+ employees
Norfolk Downs, Norfolk County · Onsite · full_time
Listed by the employer as “Business Information Security Officer-VP”. Title normalized for comparability.
CLI Career Level
VP-equivalent
Moderate confidence
Opportunity Score
65/100
Solid
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Aug 17, 2026 · Last verified 2 months ago · Sourced from Adzuna US — VP security
CLI Take
Scope matches the title
CLI reads this as a VP-equivalent mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate. The reporting line sits below the executive team — the role reports to Senior BISO (MD). Total compensation and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
65/100 — solid opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Senior BISO (MD). 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
VP-equivalent — The employer lists this as “Business Information Security Officer-VP”. CLI reads it as VP-equivalent because the role shows 10,000+ employee organization, responsibility across business units.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- The role carries more scope than the employer's title suggests.
- Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.
What to probe before applying
- The reporting line sits below the executive team — the role reports to Senior BISO (MD).
- Scope language covers responsibility across business units.
Scoring components · Solid
Compensation is not disclosed and there is no comparable set to place it against.
The reporting line sits below the executive team — the role reports to Senior BISO (MD).
Scope language covers responsibility across business units.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure: not disclosed.
The role carries more scope than the employer's title suggests.
Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.
Team size: not disclosed.
Budget ownership: not disclosed.
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
No compensation disclosed and insufficient comparable data to estimate.
The mandate
The BISO provides cyber risk management oversight for specific lines of business and legal entities. This leader is responsible for delivering cyber advisory services, threat modeling, and executing a security strategy aligned with business unit objectives.
Reporting to the Senior BISO (Managing Director), this VP leads a small team within the first line of defense. The remit covers cyber risk oversight for State Street business units and legal entities.
Scope
- Reports to Senior BISO (MD)
Domains and regulation
- Cyber Defense
- Application Security
- GRC
- Cloud Security
Requirements
Must have
- Experience in cyber risk management oversight within a first line of defense capacity
- Ability to lead a team in providing cyber advisory services
- Experience building application- and service-level threat models
- Capability to deliver security metrics for business units
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Building application- and service-level threat models
- Executing a cyber book of work aligned to specific business units
- Providing cyber risk management oversight within the first line of defense
Not stated in the posting: Salary range or compensation details not disclosed; Specific team size not defined beyond "small team"; Specific regulatory frameworks (e.g., NYDFS, SOX) not explicitly listed in the snippet; Minimum years of experience not specified.
About State Street Corporation
State Street Corporation is a global financial services and bank holding company that provides investment servicing, management, and research to institutional investors. It is one of the world's largest custody banks and asset managers, operating as a Systemically Important Financial Institution (SIFI) with trillions of dollars in assets under custody and administration. For a security leader, the environment involves complex regulatory compliance across multiple international jurisdictions and the protection of critical global financial infrastructure.
- Industry
- Financial Services
- Headcount
- 10,000+ employees
- Headquarters
- Boston, Massachusetts
- Founded
- 1792
- Ownership
- Public company · NYSE:STT
- Funding
- Publicly traded
- Revenue
- Over $10B
Full company profile for State Street Corporation →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.