State Street

State Street

Posted via Workday

India Business Information Security Officer - Assistant Vice President

Apply by Oct 12, 2026

Posted Oct 5, 2026

Role at a glance

Job function
Software Engineering & IT Cybersecurity
Salary
Not Disclosed
Location
Bangalore, India
Employment
Full-time
Education
Bachelor's

Spotted an issue?

We’ll check it against the original posting.

Log in to report

About the role

Original posting provided by State Street

View original

Job Description

The Assistant Vice President, India Business Information Security Officer supports the India Region BISO Head in delivering cybersecurity risk management, cyber resilience, and information security advisory activities across State Street's India operations and legal entities. The role aligns India business and regulatory priorities with the firm's global cybersecurity strategy, enterprise risk appetite, policies, standards, and client obligations.

Operating at the intersection of business, technology, operations, risk, and cybersecurity, the role partners with India stakeholders and global counterparts across Global Cyber Security and other enterprise functions. The individual will contribute to global cybersecurity programs and control activities, support their adoption and execution within India, and provide India business, operational, and regulatory context to global teams.

The role serves as a cybersecurity advisor to business and technology stakeholders and works closely with the India Region ISO Head, Business Information Security Officers, Global Cyber Security functions, Operational Risk, Compliance, Legal, Privacy, Architecture, and Third Party Risk Management. The individual is expected to assess and communicate cyber risk, support global and regional security initiatives, coordinate implementation and remediation activities through go-live, and help drive consistent and sustainable security outcomes.

Key Responsibilities

·    Support the India Region ISO Head in delivering cybersecurity engagement across India operations and legal entities while maintaining alignment with global cybersecurity priorities and operating models.

·    Partner with global cybersecurity counterparts and subject-matter experts to support enterprise security programs, control initiatives, assessments, and transformation activities that apply to India businesses and technology environments.

·    Act as a cybersecurity advisor to business, operations, and technology stakeholders, providing guidance on cyber risk, security controls, policy and standard requirements, remediation expectations, and risk treatment options.

·    Support the adoption and execution of global cybersecurity policies, standards, control frameworks, and programs across India, identifying local considerations, implementation dependencies, and potential gaps.

·    Collaborate with global teams across security architecture, identity and access management, data protection, application security, cloud security, vulnerability management, security operations, cyber resilience, and third-party security to address business and technology risks.

·    Contribute to global cybersecurity assessments, assurance activities, risk reviews, management reporting, and governance forums by coordinating India inputs, evidence, risk information, and follow-up actions.

·    Support incident preparedness, response coordination, tabletop exercises, crisis-management readiness, and post-incident actions in partnership with India stakeholders and global cyber response teams.

·    Support assessments of vendors, service providers, intragroup arrangements, and technology services in coordination with business stakeholders and global third-party risk management teams.

·    Support cybersecurity awareness, education, and stakeholder engagement activities, including global campaigns and targeted India sessions based on business and risk priorities.

·    Support India-specific cybersecurity, technology risk, audit, and regulatory compliance requirements, including applicable requirements issued by RBI, SEBI, CERT-In, the Digital Personal Data Protection framework, and other relevant authorities and frameworks.

·    Work with global and regional stakeholders to translate applicable India requirements into actionable cybersecurity controls and implementation activities aligned with enterprise standards.

·    Support regulatory examinations, internal and external audits, control reviews, and requests for cybersecurity evidence, including preparation of clear, accurate, and defensible documentation.

Required Experience & Qualifications

·    12+ years of progressive experience in cybersecurity, information security, technology risk, cyber audit, regulatory compliance, or a related discipline, preferably within financial services or another regulated industry.

·    Demonstrated experience supporting cybersecurity risk assessments, enterprise security programs, security reviews, remediation activities, audits, regulatory compliance, or cyber advisory engagements.

·    Experience working with global and regional business, technology, operations, risk, compliance, and cybersecurity stakeholders in a matrixed organization.

·    Experience coordinating activities across multiple cybersecurity domains and translating enterprise security requirements into practical implementation actions.

·    Working knowledge of cybersecurity and technology requirements applicable in India, with the ability to interpret regulatory expectations and support implementation within a global control environment.

·    Experience preparing cybersecurity documentation, risk assessments, control mappings, evidence packages, management presentations, or governance reporting.

·    Strong analytical, critical-thinking, problem-solving, written communication, and stakeholder-management skills.

·    Ability to translate technical, policy, and regulatory cybersecurity matters into practical, business-oriented recommendations and actions.

·    Bachelor's degree in Information Security, Computer Science, Engineering, Technology, Risk Management, Business Administration, or a related field.

·    Professional certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, CEH, or equivalent are highly valued.

Technical and Cyber Depth

·    Practical understanding of cybersecurity risk management, governance, policy and standards, regulatory compliance, and control-assurance processes.

·    Working knowledge of identity and access management, data protection and cryptography, application security, infrastructure and cloud security, platform security, endpoint security, security operations, vulnerability management, and cyber resilience.

·    Experience supporting cybersecurity assessments at the application, platform, system, process, program, or third-party level, including evaluation of threats, control effectiveness, impact, and remediation requirements.

·    Understanding of security architecture concepts and patterns, including defense in depth, zero trust, network segmentation, secure design reviews, and threat modelling.

·    Understanding of incident response, logging and monitoring, detection, crisis preparedness, recovery, and regulatory incident-reporting considerations.

·    Familiarity with enterprise security programs, global operating models, third-party cybersecurity risk, outsourcing risk, data protection, and technology-service-provider considerations.

·    Awareness of emerging technology risks, including cloud adoption, Generative AI, Agentic AI, software supply chain, digital assets, and other evolving technology areas.

·    Ability to connect global policies, standards, and control requirements with business processes, implementation activities, evidence expectations, and applicable India requirements.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

State Street

About the company

State Street

Large Enterprise

State Street is a leading financial services and bank holding company, headquartered in Boston, Massachusetts. With a strong focus on investment management and servicing solutions, State Street supports institutional investors worldwide by providing services such as asset management, investment research, and trading. Renowned for its commitment to innovation and sustainability, State Street leverages advanced technology and data analytics to enhance investment strategies and customer experiences. The company prioritizes diversity and inclusion within its workforce, reflecting its dedication to fostering a dynamic and collaborative environment.