Jobs and Careers
ST

Head of AI Security & Data Protection

State Street
United Statesfull_timeVerifiedPosted 12 Feb 2026
💰 $337,500/yr($225,000/yr$337,500/yr)

About the role

Position Overview:

The Senior Vice President, Head of AI Security & Data Protection, is a critical leadership role responsible for defining, implementing, and overseeing State Street’s comprehensive strategy for securing AI and data protection. This role leads teams across both domains, ensuring the confidentiality, integrity, and availability of sensitive data assets, and the design and stewardship of defensible, scalable, and secure AI archichitectures and implementations. The SVP will drive innovation in threat modeling and AI security, while maintaining regulatory compliance and operational excellence. A key component of this role will be to proactively address the risks of quantum computing by developing and executing a robust Post-Quantum Cryptography (PQC) readiness strategy. The successful candidate will be a seasoned security executive with deep expertise in AI, data security technologies, regulatory compliance (e.g., GDPR, CCPA, NYDFS, PCI DSS, etc.), and a proven track record of managing complex data security and cryptographic programs within a large, highly regulated financial institution.

Key Responsibilities:

Strategic Leadership

· Develop and execute State Street’s global strategy for secure AI and data protection, aligned with business objectives and regulatory requirements.

· Define and steward secure AI architectures and threat modeling frameworks across the enterprise.

· Lead the identification, assessment, and mitigation of risks across enterprise data security, including emerging threats from quantum computing and AI.

· Champion security-by-design principles in all technology initiatives, integrating security into application development, infrastructure, and cloud environments.

Data Protection & Governance

· Develop and execute a comprehensive data protection strategy for customer, supplier, and product data, with actionable controls and measurable outcomes.

· Define, implement, and maintain data protection policies, standards, and procedures, ensuring ongoing compliance and executive sponsorship.

· Maintain deep knowledge of global data protection laws and frameworks (GDPR, CCPA, LGPD, NYDFS, PCI DSS, etc.) and industry standards (NIST, COBIT, ISO 27001).

· Lead architecture, tooling selection, risk assessment, control design, and implementation for data protection and governance solutions.

Threat Modeling & Defensible Architecture

· Establish and mature threat modeling practices for AI, integrating them into architecture and engineering processes.

· Oversee the development and implementation of pilot programs and testing for emerging technology security (e.g., Post-Quantum Cryptography migration, AI model governance).

AI Security & Emerging Technology

· Manage data protection for AI/Generative AI initiatives, including data governance for models, data provenance, and model risk considerations.

· Stay abreast of emerging threats and technologies, proactively enhancing State Street’s security posture in areas such as quantum computing, AI, and cloud security.

· Collaborate with architecture and engineering teams to evaluate and integrate suitable security solutions for emerging technologies.

Operational Excellence & Program Management

· Oversee the design, implementation, and management of data security controls: DLP, data classification, encryption, tokenization, masking, database activity monitoring, and cloud data security posture management.

· Drive controls automation and governance technology initiatives (e.g., Archer, ServiceNow GRC) to streamline risk management, policy enforcement, and audit readiness.

· Integrate GRC with project/portfolio management tools (e.g., Jira, Clarity) for alignment of control requirements and remediation efforts.

· Develop and implement incident response plans and procedures, including considerations for “Harvest Now, Decrypt Later” scenarios.

Stakeholder Engagement & Advisory

· Serve as a trusted advisor to the CISO, executive leadership, and business units on all matters related to enterprise architecture, data protection, and emerging technology security.

· Build strong partnerships with the Chief Data Officer (CDO), Chief Technology Risk Officer (CTRO), Chief Architect, Head of Emerging Technologies and business units to embed security requirements in business processes.

· Represent State Street in industry forums, conferences, and regulatory discussions related to data security and emerging technologies.

Analytics, Insights & Decision Support

· Deliver measurable dashboards and KPIs/KRIs that drive action and provide insights into the effectiveness of security controls and architecture for AI and data programs.

· Synthesize input from diverse stakeholders to develop practical, scalable solutions and recommendations.

Team Leade

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

State Street

View company profile →