Business Information Security Officer-VP

State StreetQuincy, MA

About The Position

The Vice President, Business Information Security Officer (BISO) provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense and reporting into Senior BISO / MD. The VP BISO leads a small team focused on providing cyber advisory services, building application and service level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework. This role is intended for a cyber risk leader who can support both traditional technology environments and emerging digital asset services. The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing, smart contract assurance, third-party platforms and broader blockchain based financial services solutions. The candidate should translate these topics into clear control expectations for business, technology, risk, compliance, legal, and regulatory stakeholders.

Requirements

  • Bachelor’s degree in computer science, Information security and assurance, or a related technical field or equivalent work aligned experience.
  • At least 6 years of information security experience in an operational or analytical capacity, with 4+ years within financial services; qualitative cyber risk analysis experience highly preferred.
  • Experience working with the NIST Cybersecurity Framework; AWS or Azure cloud security preferable but not required.
  • Experience with business concepts including finance, business requirements, compliance, and risk management.
  • Familiarity with applicable regional regulatory guidance across the jurisdictions the role supports
  • Strong analytical, communication (written and verbal), research, and organizational skills; strong interpersonal skills including active listening, dependability, and teamwork.

Nice To Haves

  • CISSP/CISP preferred.
  • Blockchain and digital asset security certifications (e.g., Certified Blockchain Security Professional (CBSP)) are desirable.
  • Practical experience with digital asset custody, wallet infrastructure, HSMs, MPC technologies, transaction signing controls, smart contracts, tokenization platforms, and blockchain security assessments is strongly preferred.
  • Practical experience with blockchain, digital assets, tokenization, custody, wallet infrastructure, smart contracts, HSM-based key management, cold storage, transaction signing controls, or digital asset platform risk assessments strongly preferred.
  • Experience with Agentic AI use cases and deployments is a plus.

Responsibilities

  • Lead a small team to support aligned business stakeholders while focusing on increased cyber capabilities; execute a cyber book of work aligned to the business.
  • Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.
  • Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.
  • Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required.
  • Integrate information security risk review into lifecycle processes such as Incident Management, Vulnerability Management, Third-Party Risk Review, Cyber Resiliency, eSDLC, and Change and Project Management.
  • Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums alongside Executive Management, Internal Audit, Enterprise Technology Risk Management, Compliance, Legal, and Regulatory.
  • Prepare and deliver executive-ready presentations and briefings on protection needs outcomes, threat models, and control results to mid and senior level leadership.
  • Advise on blockchain and digital asset risk across tokenization, custody, wallet operations, transaction authorization, transaction signing, smart contract use, blockchain infrastructure, and any third-party digital asset services.
  • Challenge custody and key management designs, including HSM usage, cold storage controls, private key lifecycle management, backup and recovery, quorum approvals, segregation of duties, break-glass access, and operational resilience.
  • Coordinate with security architecture, application security, cloud security, IAM/PAM, SOC/SIEM, vendor risk, risk management, legal, compliance, and technology teams to define practical digital asset control expectations.
  • Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.
  • Demonstrate an understanding of model risk, frontier models, and the risk management around them.
  • Show strong technical expertise across Cloud Security, Digital Assets, AI, Identity & Access Management, Application Security, and Software Supply Chain Security.
  • Use AI effectively to solve problems; experience with Agentic AI use cases and deployments is a plus.
  • Explain how digital asset risks differ from traditional application risks, including transaction finality, private key compromise, smart contract logic, custody dependencies, on-chain activity, and third-party platform concentration risk.
  • Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.
  • Understanding of issue management, triage, remediation tracking, and residual-risk scoring.
  • Ability to assess digital asset risks across custody, key management, wallet administration, HSM usage, cold storage, smart contracts, third parties, monitoring, incident response, operational resilience, and privileged access.

Benefits

  • our retirement savings plan (401K) with company match
  • insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages
  • paid-time off including vacation, sick leave, short term disability, and family care responsibilities
  • access to our Employee Assistance Program
  • incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans)
  • eligibility for certain tax advantaged savings plans
  • inclusive development opportunities
  • flexible work-life support
  • paid volunteer days
  • vibrant employee networks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service