Cybersecurity, Vice President

Statestreet · Mumbai

  • Experience8109–8110 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted24 Sept 2026

About Statestreet

Statestreet is hiring in Mumbai in financial services. This role looks for around 8109+ years of experience.

Skills

  • cyber risk management
  • incident response
  • data protection
  • cybersecurity regulations
  • cybersecurity assessments
  • third-party risk management
  • cloud security
  • identity and access management
  • logging and monitoring
  • threat modeling
  • network segmentation
  • zero trust
  • cyber resiliency
  • privacy engineering
  • Generative AI
  • large language models

The role

A cybersecurity advisor at a financial services company guides cyber risk management, incident response, and data protection across regulated business operations. The role also applies threat modeling and cloud security to strengthen governance and executive risk decisions.

Full job description

VP, Business Information Security Officer

The VP, Business Information Security Officer (India) drives compliance with global cybersecurity controls across the business unit, region, country, or functional area they represent, and sits within the first line of defense. The BISO serves as a trusted advisor to mid- and senior-level business management within India advising on cyber risk aligned to critical business services so that business leaders can make informed, fact-based risk decisions and prioritize remediation and trade-offs to protect the firm and its clients.

The BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting. The successful candidate will provide cyber advisory services, help execute the cybersecurity book of work, and deliver metrics and cyber-driven content that support the business’s enhanced decision-making framework.

Key Responsibilities

Serve as the key cybersecurity advisor for local India business teams to bringing relevant and actionable data so teams can maintain compliance with India cybersecurity and data protection regulations including CERT-In Directions, DPDP Act, RBI, and SEBI.

Lead and facilitate cybersecurity assessments and establish partnerships with business and technology teams to remediate cyber risk in India.

Actively work with India business teams to translate global cybersecurity policies and standards into training and awareness materials to educate teams and improve cyber culture and practice.

Engage directly with business and technology teams to bring line of sight into India’s cyber risk posture, cyber risk assessment outcomes, and material risk reporting into global governance forums.

Provide cyber risk advisory services and issue escalation recommendations while balancing cyber risk prioritization with expected business outcomes.

Escalation point for cybersecurity incidents impacting India‑based systems, data, and clients.

Enable the business to grow through secure cloud, digital, outsourcing, and third‑party models within India regulatory requirements.

Assist the third-party risk management team and take an active role in assessing India‑based vendors, service providers, and intra‑group outsourcing arrangements.

Ensure service providers comply with India regulatory expectations for data localization, logging, monitoring, and incident reporting as part of the global cybersecurity standards.

Represent cybersecurity in India leadership forums, meetings, and working groups.

Required Experience & Qualifications

8109+ years of progressive experience in domains such as cyber operations, data protection, information security management, and cyber risk remediation including leadership roles in regulated environments.

Proven experience operating at a mid-leadership level and influencing teams to embrace cyber standards while clearly articulating open residual risk.

Demonstrated hands‑on experience with India cyber regulations, including CERT‑In directives and sector‑specific frameworks.

Experience supporting regulatory exams, audits, and enforcement actions in India.

Experience with India cyber regulations and sector‑specific frameworks.

Experience supporting regulatory exams and audits.

Strong preference for financial services, payments, asset management, banking, or similarly regulated industries.

Experience in global operating models and matrixed organizations.

Technical and Cyber Depth

Strong experience with incident response and crisis management.

Thorough understanding of data protection principles and privacy engineering standards.

Understanding of Multi-Cloud and SaaS risk models.

Experience with architecture patterns and cyber engineering concepts (i.e., Defense in Depth, zero trust, network segmentation, etc.)

Control knowledge into identity and access management, logging and monitoring requirements, and cyber resiliency controls.

Familiar with threat modelling concepts (i.e. data flow, trust boundaries, countermeasures, etc.)

Ability to translate technical risk into executive‑level decision frameworks.

Experience with conceptual security processes surrounding Generative AI (GenAI) and Agentic AI models.

Functional experience with frontier large language Models (LLMs) i.e. Claude, Gemini, etc.

Highly Desirable Attributes

Ability to quickly earn trust and credibility with regulators and senior stakeholders.

Ability to multi-task and pass along sound judgment.

Pragmatic, business – enabling security mindset.

Being curious into ways that both processes and technology can improve to gain better visibility while ensuring better security for clients and customers.

Strong willingness to learn new emerging technologies, how those are embraced within the business and how to best secure them.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement