Cybersecurity, Vice President
AI in this role
VP, Business Information Security Officer
The VP, Business Information Security Officer (India) drives compliance with global cybersecurity controls across the business unit, region, country, or functional area they represent, and sits within the first line of defense. The BISO serves as a trusted advisor to mid- and senior-level business management within India advising on cyber risk aligned to critical business services so that business leaders can make informed, fact-based risk decisions and prioritize remediation and trade-offs to protect the firm and its clients.
The BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting. The successful candidate will provide cyber advisory services, help execute the cybersecurity book of work, and deliver metrics and cyber-driven content that support the business’s enhanced decision-making framework.
Key Responsibilities
- Serve as the key cybersecurity advisor for local India business teams to bringing relevant and actionable data so teams can maintain compliance with India cybersecurity and data protection regulations including CERT-In Directions, DPDP Act, RBI, and SEBI.
- Lead and facilitate cybersecurity assessments and establish partnerships with business and technology teams to remediate cyber risk in India.
- Actively work with India business teams to translate global cybersecurity policies and standards into training and awareness materials to educate teams and improve cyber culture and practice.
- Engage directly with business and technology teams to bring line of sight into India’s cyber risk posture, cyber risk assessment outcomes, and material risk reporting into global governance forums.
- Provide cyber risk advisory services and issue escalation recommendations while balancing cyber risk prioritization with expected business outcomes.
- Escalation point for cybersecurity incidents impacting India‑based systems, data, and clients.
- Enable the business to grow through secure cloud, digital, outsourcing, and third‑party models within India regulatory requirements.
- Assist the third-party risk management team and take an active role in assessing India‑based vendors, service providers, and intra‑group outsourcing arrangements.
- Ensure service providers comply with India regulatory expectations for data localization, logging, monitoring, and incident reporting as part of the global cybersecurity standards.
- Represent cybersecurity in India leadership forums, meetings, and working groups.
Required Experience & Qualifications
- 8109+ years of progressive experience in domains such as cyber operations, data protection, information security management, and cyber risk remediation including leadership roles in regulated environments.
- Proven experience operating at a mid-leadership level and influencing teams to embrace cyber standards while clearly articulating open residual risk.
- Demonstrated hands‑on experience with India cyber regulations, including CERT‑In directives and sector‑specific frameworks.
- Experience supporting regulatory exams, audits, and enforcement actions in India.
- Experience with India cyber regulations and sector‑specific frameworks.
- Experience supporting regulatory exams and audits.
- Strong preference for financial services, payments, asset management, banking, or similarly regulated industries.
- Experience in global operating models and matrixed organizations.
Technical and Cyber Depth
- Strong experience with incident response and crisis management.
- Thorough understanding of data protection principles and privacy engineering standards.
- Understanding of Multi-Cloud and SaaS risk models.
- Experience with architecture patterns and cyber engineering concepts (i.e., Defense in Depth, zero trust, network segmentation, etc.)
- Control knowledge into identity and access management, logging and monitoring requirements, and cyber resiliency controls.
- Familiar with threat modelling concepts (i.e. data flow, trust boundaries, countermeasures, etc.)
- Ability to translate technical risk into executive‑level decision frameworks.
- Experience with conceptual security processes surrounding Generative AI (GenAI) and Agentic AI models.
- Functional experience with frontier large language Models (LLMs) i.e. Claude, Gemini, etc.
Highly Desirable Attributes
- Ability to quickly earn trust and credibility with regulators and senior stakeholders.
- Ability to multi-task and pass along sound judgment.
- Pragmatic, business – enabling security mindset.
- Being curious into ways that both processes and technology can improve to gain better visibility while ensuring better security for clients and customers.
- Strong willingness to learn new emerging technologies, how those are embraced within the business and how to best secure them.
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
How we rate this
Cybersecurity, Vice President at State Street rates 35 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What's a project where you used Claude hands-on?
- Walk me through how you've used Gemini in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Claude and Gemini. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new cybersecurity jobs by email
One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step