State Street

State Street

Posted via Workday

AI Security and Data Protection Governance and Controls VP

Apply by Oct 30, 2026

Posted Sep 12, 2026

Role at a glance

Job function
Software Engineering & IT Cybersecurity
Salary
$120K – $202.5K/yr
Location
Quincy, Massachusetts, United States
Work arrangement
Hybrid
Employment
Full-time
Education
Bachelor's

Spotted an issue?

We’ll check it against the original posting.

Log in to report

About the role

Original posting provided by State Street

View original

Who we are looking for

We are looking for a Vice President, AI Security and Data Protection Governance and Controls reporting directly to the Managing Director, Data Protection. You will establish and oversee the enterprise governance framework for secure and resilient AI and data protection capabilities, translating strategy into policies, standards, controls, risk decisions, and measurable remediation programs. You will partner across Security, Technology, Risk, Compliance, Legal, Procurement, and the business to embed security-by-design, resilient controls, and adaptable technology standards and AI security and data protection requirements across enterprise platforms, applications, and third-party services.

Why this role is important to us

The team you will be joining is part of Global Cybersecurity, a function vital to protecting the confidentiality, integrity, availability, and resilience of the firm’s information and technology environment. This role is critical to preparing the organization for emerging AI, data, and emerging technology risks, reducing long-term security and data protection risk, supporting regulatory and audit readiness, and coordinating a controlled transition to secure and resilient AI and data protection capabilities.

What you will be responsible for

In this role, you will:

• Establish and maintain the enterprise governance framework, policies, standards, decision rights, and accountability model for AI security, data protection, and emerging technology risk.

• Govern the discovery, inventory, classification, and risk assessment of AI models, data assets, security controls, platforms, applications, integrations, and technology dependencies.

• Define risk-based prioritization criteria using data sensitivity, retention period, business criticality, external exposure, and migration complexity, including long-term data exposure and emerging technology risk.

• Design minimum control requirements, testing procedures, evidence standards, exception processes, compensating controls, and remediation expectations across applications, infrastructure, cloud, networks, identity, and data platforms.

• Establish and oversee the enterprise roadmap for transitioning vulnerable security and data protection implementations to approved approved secure technologies and control solutions, including delivery milestones, control gates, dependencies, and risk escalation.

• Partner with Security Architecture and Engineering to embed AI security and data protection and security-by-design and adaptable control requirements into solution design, architecture reviews, engineering standards, and reusable implementation patterns.

• Define AI security and data protection requirements and due-diligence criteria for third-party products, cloud services, strategic vendors, contracts, and technology evaluations.

• Serve as the subject-matter authority for AI security and data protection governance in engagements with senior leadership, Risk, Compliance, Internal Audit, external auditors, clients, and regulators.

• Establish dashboards, key risk indicators, and performance measures for inventory coverage, AI and data risk exposure, control compliance, exceptions, migration progress, remediation, and residual risk.

• Lead and develop a team responsible for governance, control oversight, risk assessment, program coordination, and cross-functional execution.

What we value

These skills will help you succeed in this role:

• Deep understanding of AI security, data protection, security architecture, governance, risk, and control principles, AI security and data protection, and security-by-design, resilient controls, and adaptable technology standards.

• Ability to translate complex technical and emerging risks into clear policies, standards, controls, investment priorities, and executive decisions.

• Strong governance, technology risk, control design, exception management, and assurance capabilities within a large, regulated organization.

• Proven leadership of complex, cross-functional cybersecurity or technology transformation programs with measurable outcomes and clear accountability.

• Executive communication and influencing skills across Security, Engineering, Infrastructure, Cloud, Application Development, Risk, Legal, Procurement, Audit, and business teams.

• Data-driven, risk-based decision making with strong attention to detail, strategic judgment, and a focus on sustainable risk reduction.

• Commitment to simplification, standardization, collaboration, and scalable governance.

Education & Preferred Qualifications

Degree required: Bachelor’s degree in Information Security, Computer Science, Engineering, Mathematics, AI Security and Data Protection, or a related discipline; advanced degree preferred.

• Years of experience: 10+ years of progressive experience in cybersecurity, AI security, data protection, security architecture, technology risk, or control governance.

• Certifications required or preferred: CISSP, CISM, CRISC, CCSP, cloud security, or comparable industry certifications preferred.

• Knowledge of tools or technologies: Security and Data Protection discovery and inventory capabilities; PKI; certificate and key management; cloud and enterprise security architectures; asset, configuration, governance, risk, and compliance platforms; and reporting or dashboard technologies.

• Additional language requirements: N/A.

• Other qualifications: Experience developing enterprise security policies, standards, and controls; leading cross-functional transformation; engaging vendors; and communicating with executive, audit, regulatory, and non-technical audiences in a large, highly regulated organization.

Additional Requirements

Additional requirements for this role include the ability to coordinate across global teams and time zones, support regulatory and audit engagements as needed, and manage sensitive information in accordance with company requirements. Travel may be required based on business needs.

Work Requirement

• Hybrid Work Requirement: Hybrid, subject to company and location-specific requirements.

• Shift Timings: Standard business hours with flexibility to support global stakeholders and critical program or regulatory needs.

Salary Range:

$120,000 - $202,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

State Street

About the company

State Street

Large Enterprise

State Street is a leading financial services and bank holding company, headquartered in Boston, Massachusetts. With a strong focus on investment management and servicing solutions, State Street supports institutional investors worldwide by providing services such as asset management, investment research, and trading. Renowned for its commitment to innovation and sustainability, State Street leverages advanced technology and data analytics to enhance investment strategies and customer experiences. The company prioritizes diversity and inclusion within its workforce, reflecting its dedication to fostering a dynamic and collaborative environment.