State Street logo

India Business Information Security Officer - Assistant Vice President

State Street · Posted Oct 5

Investment servicing, custody, asset management, and trading solutions for institutional investors

Bangalore, Karnātaka, IndiaFull-timeHybridLead/Staff12+ years₹35.0L–₹60.0L yearly67 applicants
Financial ServicesBankingInvestment ManagementAsset ServicingCustodyPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

State Street's India Business Information Security Office supports the India Region BISO Head in delivering cybersecurity risk management, cyber resilience, and information security advisory activities across State Street's India operations and legal entities, aligning India business and regulatory priorities with the firm's global cybersecurity strategy, risk appetite, policies, standards, and client obligations. The role operates at the intersection of business, technology, operations, risk, and cybersecurity, partnering with India stakeholders and global counterparts across Global Cyber Security and other enterprise functions. This AVP will serve as a cybersecurity advisor to business and technology stakeholders, support global and regional security initiatives, coordinate implementation and remediation through go-live, and address India-specific regulatory, audit, and control requirements.

What you will do

  • Support the India Region ISO Head in delivering cybersecurity engagement across India operations and legal entities while maintaining alignment with global cybersecurity priorities and operating models.
  • Partner with global cybersecurity counterparts and subject-matter experts to support enterprise security programs, control initiatives, assessments, and transformation activities that apply to India businesses and technology environments.
  • Act as a cybersecurity advisor to business, operations, and technology stakeholders, providing guidance on cyber risk, security controls, policy and standard requirements, remediation expectations, and risk treatment options.
  • Support the adoption and execution of global cybersecurity policies, standards, control frameworks, and programs across India, identifying local considerations, implementation dependencies, and potential gaps.
  • Collaborate with global teams across security architecture, identity and access management, data protection, application security, cloud security, vulnerability management, security operations, cyber resilience, and third-party security to address business and technology risks.
  • Contribute to global cybersecurity assessments, assurance activities, risk reviews, management reporting, and governance forums by coordinating India inputs, evidence, risk information, and follow-up actions.
  • Support incident preparedness, response coordination, tabletop exercises, crisis-management readiness, and post-incident actions in partnership with India stakeholders and global cyber response teams.
  • Support assessments of vendors, service providers, intragroup arrangements, and technology services in coordination with business stakeholders and global third-party risk management teams.
  • Support cybersecurity awareness, education, and stakeholder engagement activities, including global campaigns and targeted India sessions based on business and risk priorities.
  • Support India-specific cybersecurity, technology risk, audit, and regulatory compliance requirements, including applicable requirements issued by RBI, SEBI, CERT-In, the Digital Personal Data Protection framework, and other relevant authorities and frameworks.
  • Work with global and regional stakeholders to translate applicable India requirements into actionable cybersecurity controls and implementation activities aligned with enterprise standards.
  • Support regulatory examinations, internal and external audits, control reviews, and requests for cybersecurity evidence, including preparation of clear, accurate, and defensible documentation.

Skills used in this role

CISSPCISACRISCISO 27001CEHIdentity and Access ManagementData ProtectionCryptographyApplication SecurityCloud SecurityEndpoint SecuritySecurity OperationsVulnerability ManagementIncident ResponseZero TrustNetwork SegmentationThreat ModelingThird-Party Risk ManagementGenerative AIAgentic AICybersecurity Risk ManagementProblem SolvingCommunicationStakeholder ManagementCritical Thinking

What the employer is looking for

  • 12+ years of progressive experience in cybersecurity, information security, technology risk, cyber audit, regulatory compliance, or a related discipline, preferably within financial services or another regulated industry.
  • Demonstrated experience supporting cybersecurity risk assessments, enterprise security programs, security reviews, remediation activities, audits, regulatory compliance, or cyber advisory engagements.
  • Experience working with global and regional business, technology, operations, risk, compliance, and cybersecurity stakeholders in a matrixed organization.
  • Experience coordinating activities across multiple cybersecurity domains and translating enterprise security requirements into practical implementation actions.
  • Working knowledge of cybersecurity and technology requirements applicable in India, with the ability to interpret regulatory expectations and support implementation within a global control environment.
  • Experience preparing cybersecurity documentation, risk assessments, control mappings, evidence packages, management presentations, or governance reporting.
  • Strong analytical, critical-thinking, problem-solving, written communication, and stakeholder-management skills.
  • Ability to translate technical, policy, and regulatory cybersecurity matters into practical, business-oriented recommendations and actions.
  • Bachelor's degree in Information Security, Computer Science, Engineering, Technology, Risk Management, Business Administration, or a related field.
  • Professional certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, CEH, or equivalent are highly valued.
  • Practical understanding of cybersecurity risk management, governance, policy and standards, regulatory compliance, and control-assurance processes.
  • Working knowledge of identity and access management, data protection and cryptography, application security, infrastructure and cloud security, platform security, endpoint security, security operations, vulnerability management, and cyber resilience.
  • Experience supporting cybersecurity assessments at the application, platform, system, process, program, or third-party level, including evaluation of threats, control effectiveness, impact, and remediation requirements.
  • Understanding of security architecture concepts and patterns, including defense in depth, zero trust, network segmentation, secure design reviews, and threat modelling.
  • Understanding of incident response, logging and monitoring, detection, crisis preparedness, recovery, and regulatory incident-reporting considerations.
  • Familiarity with enterprise security programs, global operating models, third-party cybersecurity risk, outsourcing risk, data protection, and technology-service-provider considerations.
  • Awareness of emerging technology risks, including cloud adoption, Generative AI, Agentic AI, software supply chain, digital assets, and other evolving technology areas.
  • Ability to connect global policies, standards, and control requirements with business processes, implementation activities, evidence expectations, and applicable India requirements.

Benefits and support

  • inclusive development opportunities
  • flexible work-life support
  • paid volunteer days
  • vibrant employee networks

About State Street

State Street Corporation is a leading global financial services holding company providing institutional investors with investment servicing, investment management, and investment research and trading. Operating in more than 100 geographic markets worldwide, the company manages and administers trillions of dollars in assets through its core divisions like State Street Global Advisors and State Street Alpha. Headquartered in Boston, Massachusetts, it traces its origins back to 1792.

Industry
Financial Services
Company size
51000+ employees
Founded
1792-06-25
Location
Boston, Massachusetts, USA
Funding stage
Public Company

Leadership

RP
Ronald P. O'Hanley

Chairman and Chief Executive Officer

JW

John Woods

Chief Financial Officer

MT

Mostapha Tahiri

President of State Street Alpha & Chairman of Asia Pacific

AF

Ann Fogarty

Enterprise Chief Operating Officer

YH
Yie-Hsin Hung

President and Chief Executive Officer of State Street Investment Management