Jobs and Careers
ST

Assistant Vice President – IT Security Governance & Risk Management

State Street
United Statesfull_timeVerifiedPosted 17 Apr 2026
💰 $167,500/yr($100,000/yr$167,500/yr)

About the role

Role Summary

We are seeking an experienced IT Security Governance & Risk Management leader to support enterprise‑wide remediation and compliance initiatives across Alternatives Investment Services (AIS) and Insurance technology platforms.

At the AVP level, this role acts as a hands‑on execution lead and escalation point, partnering with application owners, production support, infrastructure teams, and senior leadership to ensure timely remediation of identity, access, vulnerability, and application lifecycle risks in a highly regulated environment.

The role requires strong execution discipline, governance maturity, and the ability to drive outcomes across a large, complex application portfolio.

Key Responsibilities

Identity & Access Risk Management

  • Lead remediation of aged passwords and non‑human/service accounts across a large portfolio of AIS and Insurance applications.
  • Partner with application and production support teams to drive corrective actions including password rotation, account disablement, or decommissioning.
  • Track remediation activity through enterprise change management tools and ensure committed actions are executed on schedule.
  • Validate remediation outcomes using identity and access platforms and ensure evidence is audit‑ready.
  • Maintain centralized tracking, metrics, and reporting for non‑compliant accounts.
  • Escalate repeated non‑compliance and missed timelines to senior management, clearly articulating risk and impact.

Vulnerability & Patch Governance

  • Review weekly vulnerability reports and validate trends, new findings, and remediation progress.
  • Identify carried‑over and at‑risk vulnerabilities and engage application teams to ensure timely resolution.
  • Maintain high‑quality data sets and develop management views to support leadership decision‑making.
  • Produce weekly executive‑level reporting for AIS and Insurance portfolios, including risks, trends, and remediation timelines.
  • Coordinate with infrastructure and security teams to resolve issues and remove blockers.

Multi‑Factor Authentication (MFA) Compliance

  • Track and govern MFA implementation across AIS and Insurance applications.
  • Coordinate with application teams to manage timelines, dependencies, and attestations.
  • Provide clear, concise weekly status reporting to senior leadership.
  • Highlight risks and escalate applications not meeting agreed‑upon milestones.

Policy Violations & Control Exceptions

  • Review periodic policy violation reports related to application security controls.
  • Engage application owners to obtain remediation plans and progress updates.
  • Provide guidance on remediation of common violations and control gaps.
  • Escalate non‑responsive or non‑compliant applications to senior leadership.

Application Risk Remediation

  • Drive remediation of interactive and legacy account risks in collaboration with application owners and support teams.
  • Support teams with remediation approaches to align accounts with non‑interactive access standards.
  • Maintain status tracking and escalate stalled remediation activity where required.

Application Lifecycle Risk & Resilience

  • Ensure applications using end‑of‑life or unsupported components are properly documented in enterprise lifecycle risk repositories.
  • Validate remediation timelines and support application teams with required updates.
  • Escalate applications that fail to maintain accurate lifecycle risk data.

Financial & Delivery Transparency

  • Produce and maintain governance and status reporting for key technology initiatives within AIS and Insurance.
  • Partner with delivery teams to ensure accomplishments, upcoming activities, and risks are accurately captured and communicated.
  • Support audit and regulatory inquiries through consistent, high‑quality reporting.

Required Qualifications

  • 7–10+ years of experience in IT risk management, security governance, identity and access management, or regulatory compliance.
  • Proven ability to lead remediation activities across large, complex application portfolios.
  • Strong experience producing executive‑level reporting and communicating technical risk to senior stakeholders.
  • Demonstrated ability to drive accountability, follow‑through, and escalation in matrixed environments.
  • Strong analytical, organizational, and stakeholder‑management skills.

Preferred Qualifications

  • Experience within financial services, insurance, or other highly regulated industries.
  • Familiarity wi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

State Street

View company profile →