
India Business Information Security Officer - Assistant Vice President
State Street · Posted Oct 5
Investment servicing, custody, asset management, and trading solutions for institutional investors
Get a personal compatibility score
Add a resume for personal matches
About the role
State Street's India Business Information Security Office supports the India Region BISO Head in delivering cybersecurity risk management, cyber resilience, and information security advisory activities across State Street's India operations and legal entities, aligning India business and regulatory priorities with the firm's global cybersecurity strategy, risk appetite, policies, standards, and client obligations. The role operates at the intersection of business, technology, operations, risk, and cybersecurity, partnering with India stakeholders and global counterparts across Global Cyber Security and other enterprise functions. This AVP will serve as a cybersecurity advisor to business and technology stakeholders, support global and regional security initiatives, coordinate implementation and remediation through go-live, and address India-specific regulatory, audit, and control requirements.
What you will do
- Support the India Region ISO Head in delivering cybersecurity engagement across India operations and legal entities while maintaining alignment with global cybersecurity priorities and operating models.
- Partner with global cybersecurity counterparts and subject-matter experts to support enterprise security programs, control initiatives, assessments, and transformation activities that apply to India businesses and technology environments.
- Act as a cybersecurity advisor to business, operations, and technology stakeholders, providing guidance on cyber risk, security controls, policy and standard requirements, remediation expectations, and risk treatment options.
- Support the adoption and execution of global cybersecurity policies, standards, control frameworks, and programs across India, identifying local considerations, implementation dependencies, and potential gaps.
- Collaborate with global teams across security architecture, identity and access management, data protection, application security, cloud security, vulnerability management, security operations, cyber resilience, and third-party security to address business and technology risks.
- Contribute to global cybersecurity assessments, assurance activities, risk reviews, management reporting, and governance forums by coordinating India inputs, evidence, risk information, and follow-up actions.
- Support incident preparedness, response coordination, tabletop exercises, crisis-management readiness, and post-incident actions in partnership with India stakeholders and global cyber response teams.
- Support assessments of vendors, service providers, intragroup arrangements, and technology services in coordination with business stakeholders and global third-party risk management teams.
- Support cybersecurity awareness, education, and stakeholder engagement activities, including global campaigns and targeted India sessions based on business and risk priorities.
- Support India-specific cybersecurity, technology risk, audit, and regulatory compliance requirements, including applicable requirements issued by RBI, SEBI, CERT-In, the Digital Personal Data Protection framework, and other relevant authorities and frameworks.
- Work with global and regional stakeholders to translate applicable India requirements into actionable cybersecurity controls and implementation activities aligned with enterprise standards.
- Support regulatory examinations, internal and external audits, control reviews, and requests for cybersecurity evidence, including preparation of clear, accurate, and defensible documentation.
Skills used in this role
What the employer is looking for
- 12+ years of progressive experience in cybersecurity, information security, technology risk, cyber audit, regulatory compliance, or a related discipline, preferably within financial services or another regulated industry.
- Demonstrated experience supporting cybersecurity risk assessments, enterprise security programs, security reviews, remediation activities, audits, regulatory compliance, or cyber advisory engagements.
- Experience working with global and regional business, technology, operations, risk, compliance, and cybersecurity stakeholders in a matrixed organization.
- Experience coordinating activities across multiple cybersecurity domains and translating enterprise security requirements into practical implementation actions.
- Working knowledge of cybersecurity and technology requirements applicable in India, with the ability to interpret regulatory expectations and support implementation within a global control environment.
- Experience preparing cybersecurity documentation, risk assessments, control mappings, evidence packages, management presentations, or governance reporting.
- Strong analytical, critical-thinking, problem-solving, written communication, and stakeholder-management skills.
- Ability to translate technical, policy, and regulatory cybersecurity matters into practical, business-oriented recommendations and actions.
- Bachelor's degree in Information Security, Computer Science, Engineering, Technology, Risk Management, Business Administration, or a related field.
- Professional certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, CEH, or equivalent are highly valued.
- Practical understanding of cybersecurity risk management, governance, policy and standards, regulatory compliance, and control-assurance processes.
- Working knowledge of identity and access management, data protection and cryptography, application security, infrastructure and cloud security, platform security, endpoint security, security operations, vulnerability management, and cyber resilience.
- Experience supporting cybersecurity assessments at the application, platform, system, process, program, or third-party level, including evaluation of threats, control effectiveness, impact, and remediation requirements.
- Understanding of security architecture concepts and patterns, including defense in depth, zero trust, network segmentation, secure design reviews, and threat modelling.
- Understanding of incident response, logging and monitoring, detection, crisis preparedness, recovery, and regulatory incident-reporting considerations.
- Familiarity with enterprise security programs, global operating models, third-party cybersecurity risk, outsourcing risk, data protection, and technology-service-provider considerations.
- Awareness of emerging technology risks, including cloud adoption, Generative AI, Agentic AI, software supply chain, digital assets, and other evolving technology areas.
- Ability to connect global policies, standards, and control requirements with business processes, implementation activities, evidence expectations, and applicable India requirements.
Benefits and support
- inclusive development opportunities
- flexible work-life support
- paid volunteer days
- vibrant employee networks
About State Street
State Street Corporation is a leading global financial services holding company providing institutional investors with investment servicing, investment management, and investment research and trading. Operating in more than 100 geographic markets worldwide, the company manages and administers trillions of dollars in assets through its core divisions like State Street Global Advisors and State Street Alpha. Headquartered in Boston, Massachusetts, it traces its origins back to 1792.
- Industry
- Financial Services
- Company size
- 51000+ employees
- Founded
- 1792-06-25
- Location
- Boston, Massachusetts, USA
- Funding stage
- Public Company
Leadership
Chairman and Chief Executive Officer
John Woods
Chief Financial Officer
Mostapha Tahiri
President of State Street Alpha & Chairman of Asia Pacific
Ann Fogarty
Enterprise Chief Operating Officer
President and Chief Executive Officer of State Street Investment Management
Recent coverage
Business Wire
State Street Corporation Releases 2026 Digital Assets Study2026-10-06
State Street
State Street Appointed as Transfer Agent by Wellington Management on HKEX Integrated Fund Platform2026-09-29
State Street
State Street Corporation to Report Third-Quarter 2026 Financial Results and Host Conference Call Webcast on October 142026-09-23
State Street
Yuanta Funds Selects State Street for First Overseas Securities Lending Program2026-09-15