
Leading company in the financial services industry
MD GRC Risk Management and Governance at State Street
About the role
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ensures cyber risk is consistently identified, assessed, governed, and reported in alignment with the Enterprise Risk Framework, regulatory expectations, and the firm’s risk appetite. The role serves as a central coordination point, with a strong focus on framework governance, risk management, findings oversight and management, and executive‑level reporting.
Key Responsibilities
- Own and evolve the Cyber Risk Management Framework, ensuring alignment with the Enterprise Risk Framework and regulatory expectations.
- Govern cyber risk taxonomies, risk appetite statements, risk metrics, and assessment methodologies.
- Support embedding cyber risk practices across the L3 Cyber risk methodology and support functional and business risk owners in their efforts to improve and sustain cyber risk posture.
- Provide oversight of control assurance and remediation execution and quality, including challenge, escalation, and consistency.
- Ensure consistent linkage between assessment outcomes, risk appetite, and remediation priorities.
- Enable and guide Enterprise Process Owner (EPO) / Metric Owners with challenges related to processes area / Key Risk Indicator improvement, ensuring clear accountability and effective operation.
- Support the second line of defense in defining, maintaining, and overseeing Cyber Key Risk Indicators (KRIs) and thresholds, ensuring they provide meaningful insight into risk posture and trends.
- Coordinate cyber risk matters for management‑level and executive Risk Committees, including agenda development, materials, and escalation.
- Produce and oversee executive‑level cyber risk reporting, including risk posture, trends, material issues, and emerging risks.
- Ensure reporting is concise, decision‑oriented, and aligned with enterprise and Board risk governance expectations.
- Serve as the primary cyber risk interface with Technology Risk Advisors (TRAs), coordinating inputs, challenge, outcomes, and follow‑through.
- Oversee LOD and legal entity cyber risk reporting, ensuring a consistent Global Cybersecurity view.
- Coordinate with Cyber Compliance teams to provide accurate data sharing for regulatory engagement and legal entities.
- Provide governance oversight for issues that impact cyber risk, including intake, severity assessment, challenge, escalation, and closure monitoring.
- Oversee cyber risk acceptance governance, ensuring decisions are risk‑informed, appropriately documented, time‑bound, and approved at the correct level.
- Ensure alignment between issues, risk acceptances, and risk appetite.
- Lead the intake and governance of cyber findings from audits, regulatory reviews, assessments, and testing activities.
- Ensure findings are consistently risk‑rated, challenged where appropriate, and tracked through remediation to closure.
- Monitor remediation progress, aging, and systemic themes, escalating concerns as needed to governance/management committees.
Required Qualifications
- 10+ years of experience in cybersecurity risk management, technology risk, or enterprise risk governance, with significant experience at a senior leadership level.
- Bachelor’s degree in information systems, computer science, data analytics, cybersecurity or related field (or equivalent experience).
- Deep understanding of cyber risk frameworks, enterprise risk management, and regulatory expectations within a large, complex financial services or regulated environment.
- Proven experience with risk governance, control assurance and assessments, KRIs, issue management, and executive reporting.
- Strong ability to build relationships across the three lines of defense and influence at executive and Board levels.
- Exceptional communication skills, with the ability to translate technical and risk concepts into executive‑level insights.
- Experience leading highly successful teams in achieving objectives and key results.
Preferred Skills
- Cybersecurity Certifications such as: CISSP, CISM or equivalent.
- Experience implementing automated and/or continuous controls monitoring in cloud and hybrid environments.
- Strong analytical mindset with the ability to translate ambiguous risk or control questions into measurable metrics and repeatable tests.
- Clear written and verbal communication skills, including the ability to explain complex technical findings and trends to leadership.
Salary Range:
$170,000 - $282,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Required skills
Cyber risk management
Governance
Risk metrics
Executive reporting
Control oversight
Regulatory compliance
Total Views
0
Total Apply Clicks
0
Total Mock Apply
0
Total Bookmarks
0
More open roles at State Street

Alternatives Financial Reporting, Associate 2
State Street · Hyderabad, India

Java Developer - Senior Associate
State Street · Bangalore, India

Investment Solutions Group – Intermediate Research Analyst - Assistant Manager
State Street · Bangalore, India

Java Developer - Team Lead
State Street · Bangalore, India

Authentication Systems Engineering & Operations Manager, Vice President
State Street · Quincy, Massachusetts
Similar jobs

Staff Tech, Security, T4
Collins Aerospace (RTX) · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site)

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Senior Principal Systems Security Engineer (Cyber) - P5 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-AL-HUNTSVILLE-401 ~ 401 Jan Davis Dr NW ~ JAN DAVIS 401

Network/Security Analyst- Onsite
Collins Aerospace (RTX) · US-MT-GREAT FALLS-6932-CUST ~ 6932 Goddard Dr ~ GODDARD (External Site)
About State Street

State Street
PublicState Street Corporation is an American multinational financial services and bank holding company headquartered at One Congress Street in Boston. It is the second-oldest continuously operating U.S. bank, tracing its roots to Union Bank, chartered in 1792.
10,001+
Employees
Boston
Headquarters
$55B
Valuation
Reviews
10 reviews
3.7
10 reviews
Work-life balance
3.2
Compensation
4.0
Culture
3.8
Career
3.4
Management
2.8
68%
Recommend to a friend
Pros
Supportive colleagues and team culture
Good benefits and retirement plans
Learning and advancement opportunities
Cons
Heavy workload and overtime expectations
Poor management direction and support
High stress and fast-paced environment
Salary Ranges
101 data points
Mid/L4
Mid/L4 · Application Security Engineer
1 reports
$160,557
total per year
Base
$123,506
Stock
-
Bonus
-
$160,557
$160,557
Interview experience
5 interviews
Difficulty
2.6
/ 5
Duration
21-35 weeks
Offer rate
20%
Experience
Positive 20%
Neutral 60%
Negative 20%
Interview process
1
Application Review
2
Recruiter Screen
3
Phone Interview
4
Technical/Hiring Manager Interview
5
Final Interview/Offer Stage
Common questions
Technical Knowledge
Behavioral/STAR
Past Experience
Culture Fit
Latest updates
Santa Barbara State Street saga continues, but plan for return of cars stalls - Santa Barbara News-Press
Santa Barbara News-Press
News
·
1w ago
Santa Barbara City Council votes to receive Draft State Street Master Plan - News Channel 3-12
News Channel 3-12
News
·
1w ago
State Street in Pullman closed Wednesday for sewer service repair - KXLY.com
KXLY.com
News
·
1w ago
Where State Street Investment Management Sees Opportunity - Barron's
Barron's
News
·
1w ago