Jobs and Careers
ST

Cybersecurity GRC Strategy, Governance and Reporting Lead

State Street
United Statesfull_timeVerifiedPosted 27 Feb 2025
💰 $282,500/yr($170,000/yr$282,500/yr)

About the role

Who we are looking for

We are seeking a senior leader to serve as the Head of Cybersecurity GRC Strategy, Governance and Reporting, a critical role in ensuring the organizations cybersecurity program operates with transparency, accountability and alignment with regulatory and business priorities.

The role is responsible for overseeing the development and implementation of robust governance frameworks, ensuring compliance with cybersecurity regulations and standards, and managing the lifecycle of issues and risks that impact the organizations risk and security posture.

The ideal candidate will have a proven track record in cybersecurity governance, regulatory adherence and risk management, coupled with exceptional leadership and communication skills.

About the Cybersecurity GRC Team

The Governance Risk & Compliance team is an exciting and growing area of cybersecurity with unique insight into the whole spectrum of our cybersecurity activity at State Street.

The function ensures that State Street aligns with business objectives, regulatory requirements and risk tolerance. It operates through three core pillars; Governance, Risk and Compliance supported by ongoing monitoring , reporting and improvement.

As a member of the Cybersecurity GRC Team, you will have a significant opportunity in making a difference on the team, within the cybersecurity organization, as well as State Street overall.

What you will be responsible for

  • Leading the Cyber Strategy, Governance and Reporting EPO Workstream to ensure that the process area meets its forecast to hit its controls effectiveness satisfactory score by the end of 2025.
  • Defining and maintaining the cybersecurity governance framework, ensuring alignment with business objectives and risk tolerance.
  • Leading the development of cybersecurity policies, standards and procedures ensuring consistency across all subs and affiliates.
  • Overseeing and owning the Cybersecurity Written Information Security Plan (WISP), ensuring that it is reviewed and approved by the State Street Board on an annual basis.
  • Leading the bi-annual cybersecurity maturity assessment
  • Leading the Cyber Strategy, Governance and Reporting Enterprise Process Owner (EPO) Workstream
  • Overseeing the cybersecurity stakeholder management and interaction plan, driving decision making ,tracking accountability,  and fostering stakeholder relationships
  • Establishing and overseeing a centralized cybersecurity issues management program and governance framework across the 17 Enterprise Process Areas, defining procedures for tracking and resolving issues related to risks, audits and compliance.
  • Working across other functions to identify, assess prioritize and close cybersecurity issues.
  • Develop processes to escalate critical issues ensure timely resolution in accordance with the Issues Management Standard.
  • Provide regular reporting and actionable insights to the GRC and GCS Leadership team on issue and remediation progress.

What we value

These skills will help you succeed in this role

  • A strategic thinker who can drive alignment across diverse stakeholders while maintaining clear focus on organizational objectives
  • A subject matter expert who understands the complexities of cybersecurity regulations and standards and can translate them into actionable strategies.
  • A leader who anticipates challenges, navigates complex issues and drives effective resolutions.
  • An advocate for clear communications and robust reporting that builds trust with the team and stakeholders.

Education and Preferred Qualifications

  • 10+ Years of experience in cybersecurity, with significant exposure to governance, compliance and risk management
  • Deep knowledge of cybersecurity regulations, standards and frameworks (e.g., NIST, CSF etc.)
  • Demonstrated expertise in managing governance structures, regulatory compliance efforts and issue tracking systems such as Archer and Service Now
  • Proven leadership experience with the ability to build and manage high performing teams.
  • Relevant certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.

Are you the right candidate? Yes!

We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don’t necessarily need you to fulfil all of them when applying. If you like change and inno

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

State Street

View company profile →