← All roles
VP

Business Information Security Officer

State Street Corporation · Financial Services · 10,000+ employees

Norfolk Downs, Norfolk County · Onsite · full_time

Listed by the employer as “Business Information Security Officer-VP”. Title normalized for comparability.

CLI Career Level

VP-equivalent

Moderate confidence

Opportunity Score

65/100

Solid

Moderate confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 17, 2026 · Last verified 2 months ago · Sourced from Adzuna US — VP security

CLI Take

Scope matches the title

CLI reads this as a VP-equivalent mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate. The reporting line sits below the executive team — the role reports to Senior BISO (MD). Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

65/100 — solid opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Senior BISO (MD). 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

VP-equivalent — The employer lists this as “Business Information Security Officer-VP”. CLI reads it as VP-equivalent because the role shows 10,000+ employee organization, responsibility across business units.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.

What to probe before applying

  • The reporting line sits below the executive team — the role reports to Senior BISO (MD).
  • Scope language covers responsibility across business units.

Scoring components · Solid

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level0 · weight 12%

The reporting line sits below the executive team — the role reports to Senior BISO (MD).

Functional and geographic scope21 · weight 12%

Scope language covers responsibility across business units.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposureNot disclosed · excluded from the score

Executive and board exposure: not disclosed.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory100 · weight 10%

Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

The BISO provides cyber risk management oversight for specific lines of business and legal entities. This leader is responsible for delivering cyber advisory services, threat modeling, and executing a security strategy aligned with business unit objectives.

Reporting to the Senior BISO (Managing Director), this VP leads a small team within the first line of defense. The remit covers cyber risk oversight for State Street business units and legal entities.

Scope

  • Reports to Senior BISO (MD)

Domains and regulation

  • Cyber Defense
  • Application Security
  • GRC
  • Cloud Security

Requirements

Must have

  • Experience in cyber risk management oversight within a first line of defense capacity
  • Ability to lead a team in providing cyber advisory services
  • Experience building application- and service-level threat models
  • Capability to deliver security metrics for business units

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Salary range or compensation details not disclosed; Specific team size not defined beyond "small team"; Specific regulatory frameworks (e.g., NYDFS, SOX) not explicitly listed in the snippet; Minimum years of experience not specified.

About State Street Corporation

State Street Corporation is a global financial services and bank holding company that provides investment servicing, management, and research to institutional investors. It is one of the world's largest custody banks and asset managers, operating as a Systemically Important Financial Institution (SIFI) with trillions of dollars in assets under custody and administration. For a security leader, the environment involves complex regulatory compliance across multiple international jurisdictions and the protection of critical global financial infrastructure.

Industry
Financial Services
Headcount
10,000+ employees
Headquarters
Boston, Massachusetts
Founded
1792
Ownership
Public company · NYSE:STT
Funding
Publicly traded
Revenue
Over $10B

Full company profile for State Street Corporation →

View original job description
Who We Are Looking For The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into the Senior BISO (MD). The VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics a…

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.