About this role
Location: Boston/Quincy, Massachusetts, United States
Who we are looking for
State Street is seeking a Security Platform Governance & Resilience Lead for our Security Platforms team, which is part of the State Street Cyber Fusion Center. The Security Platforms team designs, manages and supports the security technologies that enable cybersecurity operations across State Street. These platforms are critical to the firm's security posture, enabling threat detection, incident response, threat hunting, vulnerability management, data protection, automation and other key cybersecurity functions.
This role will be responsible for driving governance, operational resilience, service management, process maturity and performance management across the Security Platforms portfolio. The successful candidate will partner closely with platform engineering, security operations, risk, compliance, audit and regulatory stakeholders to ensure security platforms remain resilient, well governed, measurable and audit ready.
Success in this role will require strong operational leadership, governance expertise, stakeholder management skills and a solid understanding of cybersecurity operations and supporting technologies.
What you will be responsible for
As Security Platform Governance & Resilience Lead, you will:
- Establish and maintain governance processes across the Security Platforms organisation.
- Develop and manage platform health, operational performance and resilience metrics.
- Create executive, operational and management reporting for platform services.
- Own governance of platform roadmaps, strategic initiatives and service improvement programmes.
- Build and operate demand intake, prioritisation and governance processes for Security Platforms.
- Coordinate audit, regulatory examination and compliance activities affecting the platform portfolio.
- Establish repeatable evidence collection processes supporting internal and external audits.
- Develop, maintain and continuously improve platform SOPs, standards, control documentation and operating procedures.
- Drive operational resilience planning, testing and continuous improvement activities.
- Partner with platform engineering teams to improve operational maturity and consistency across services.
- Identify, track and drive remediation of operational risks, issues and control gaps.
- Develop service management practices including KPIs, SLAs, service reviews and continual improvement programmes.
- Coordinate governance activities across Cyber Defence, Incident Response, Detection Engineering, Identity & Access Management, Risk Management, Compliance and Internal Audit teams.
- Support leadership decision-making through meaningful metrics, dashboards and performance reporting.
- Promote a culture of operational excellence, accountability and continuous improvement.
What we value
These skills will help you succeed in this role:
- Strong understanding of cybersecurity operations and supporting platform functions.
- Experience operating in highly regulated financial services or similarly regulated environments.
- Excellent governance, process design and operational management capabilities.
- Experience supporting internal audit, regulatory examinations and compliance activities.
- Strong analytical skills with the ability to translate operational data into meaningful insights.
- Experience developing service health metrics, dashboards and executive reporting.
- Understanding of operational resilience, risk management and control frameworks.
- Strong programme and stakeholder management skills.
- Ability to influence senior stakeholders across technology, cybersecurity and business functions.
- Experience building sustainable operating models and scalable governance processes.
- Strong written and verbal communication skills.
- Ability to balance operational, regulatory and strategic priorities across a global organisation.
Education & Preferred Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Business Management or a related discipline is beneficial but not required.
- Equivalent practical experience in cybersecurity operations, governance, service management, risk management or technology operations will be considered in lieu of formal education.
- 10+ years of experience in cybersecurity, technology operations, governance, risk, compliance or service management functions.
- Experience supporting cybersecurity operations, engineering or security platform organisations.
- Working knowledge of security technologies such as EDR, SIEM, SOAR, DLP, Identity Security and Cloud Security platforms.
- Experience managing audit deliverables, evidence requests and regulatory engagements.
- Experience developing governance frameworks, operating models and service management processes.
- Familiarity with Archer, ServiceNow, Jira or similar governance and workflow platforms.
- Industry certifications such as CISSP, CISM, CRISC, ITIL or equivalent are desirable but not required.
Why this role is important to us
Security Platforms provides and operates many of the foundational technologies used by State Street's Cyber Fusion Center and broader cybersecurity organisation. As our platform portfolio continues to expand in scope, capability and regulatory obligations, maintaining strong governance, operational resilience and service management practices becomes increasingly important.
The Security Platform Governance & Resilience Lead will help ensure platform services remain scalable, resilient, measurable and aligned with regulatory expectations while enabling engineering teams to focus on delivering secure and reliable cybersecurity capabilities. This role will serve as a key partner to platform leadership, helping drive operational maturity, audit readiness, resilience planning, governance excellence and continual improvement across the Security Platforms function.
Salary Range:
$120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home .
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
