Â
Who we are looking forÂ
We are looking for a Data Protection Managing Director reporting directly to the SVP of Data and AI Security. The Managing Director, Data Protection is a senior leadership role responsible for defining, governing, and scaling the firm's enterprise-wide data protection strategy. This leader will establish a modern, risk-based data security program that enables the organization's digital, cloud, AI, and data transformation objectives while protecting the firm's most critical information assets. The role requires a visionary security leader who can balance business enablement with strong security outcomes. The successful candidate will drive the evolution from traditional data protection approaches toward a modern, intelligence-driven program focused on data discovery, classification, retention, access governance, AI security, and automated protection controls.Â
The Managing Director will serve as the firm's foremost authority on data security and protection, partnering across Security, Engineering, Data, Privacy, Legal, Risk, Compliance, Infrastructure, and Business teams to ensure security is embedded into platforms, pipelines, governance frameworks, and delivery processes.Â
Why this role is important to usÂ
This role sits in the AI & Data Protection team which is part of the Global Cybersecurity group at State Street.Global Cybersecurity isvital to the bank because it protects client trust, safeguards critical assets, enables business growth, and ensures the bank can operate safely in an increasingly complex threat and regulatory environment.Â
Â
What you will be responsible forÂ
Define and execute the firm's multi-year Enterprise Data Protection Strategy, ensuring alignment with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.Â
Establish a comprehensive framework for protecting sensitive information throughout its lifecycle, including:Â
Data discoveryÂ
ClassificationÂ
Access governanceÂ
Retention and disposalÂ
Encryption and key managementÂ
Monitoring and protection controlsÂ
Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.Â
Develop executive-level metrics and reporting that quantify data risk, control effectiveness, and remediation progress.Â
Lead enterprise initiatives to know, understand, and reduce data risk at scale.Â
Establish programs to identify and continuously inventory:Â
Sensitive customer and firm dataÂ
Regulated and restricted informationÂ
Secrets and credentialsÂ
Legacy data storesÂ
High-risk repositoriesÂ
Shadow data environmentsÂ
Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.Â
Develop actionable intelligence that enables business leaders and technology teams to understand where sensitive data resides and how it is exposed.Â
AI Data security & Protection - Lead the firm's strategy for protecting data from emerging AI-related threats and misuse.Â
Establish controls and protections against:Â
Prompt injection attacksÂ
Model misuseÂ
Data leakage through AI systemsÂ
Retrieval-augmented generation (RAG) data exposureÂ
Adversarial AI attacksÂ
Model manipulationÂ
AI-enabled social engineeringÂ
Partner closely with AI, Engineering, and Security Architecture teams to ensure AI capabilities are deployed using:Â
Secure-by-default configurationsÂ
Approved usage patternsÂ
Security guardrailsÂ
Automated controlsÂ
Enterprise-approved AI platformsÂ
Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.Â
Establish rigorous enterprise-wide data lifecycle management and retention programs designed to minimize unnecessary data exposure.Â
Drive initiatives to:Â
Eliminate obsolete and redundant dataÂ
Reduce data longevity where business value no longer existsÂ
Improve defensibility and regulatory complianceÂ
Reduce attack surface through data minimizationÂ
Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.Â
Ensure retention policies are enforced through technology controls rather than manual processes whenever possible.Â
Data Access Governance - Lead enterprise efforts to analyze, govern, and continuously monitor access to sensitive information.Â
Develop and implement:Â
Data-centric access control modelsÂ
Risk-based authorization frameworksÂ
Privileged access controlsÂ
Continuous entitlement reviewsÂ
Excessive permissions identificationÂ
Access anomaly detectionÂ
Partner with Identity and Access Management teams to strengthen least-privilege principles across business and technology environments.Â
Ensure access decisions are informed by data sensitivity, business context, user risk, and regulatory requirements.Â
Establish a comprehensive view of the firm's data protection control environment.Â
Conduct enterprise-wide assessments to:Â
Map existing controlsÂ
Identify security gapsÂ
Measure control effectivenessÂ
Assess residual riskÂ
Prioritize remediation activitiesÂ
Develop risk-based roadmaps that focus resources on the most significant data protection exposures.Â
Drive accountability across technology and business stakeholders to ensure timely remediation of material risks.Â
Partner closely with the Data organization to ensure security is embedded throughout the data ecosystem.Â
Influence the design of:Â
Data platformsÂ
Data pipelinesÂ
Analytics environmentsÂ
Governance frameworksÂ
AI and ML platformsÂ
Data productsÂ
Promote security-by-design principles that enable innovation while reducing operational friction.Â
Establish scalable security patterns that integrate directly into engineering workflows, automation pipelines, and platform services.Â
Lead strategic modernization initiatives supporting the future state of data security.Â
Drive improvements across:Â
Enterprise encryption programsÂ
Key management servicesÂ
Automated key rotationÂ
Secrets managementÂ
Ephemeral infrastructureÂ
Machine identity controlsÂ
Partner with Infrastructure, Cloud Engineering, and Enterprise Architecture teams to strengthen cryptographic hygiene and reduce operational risk.Â
Develop forward-looking strategies that support emerging technology requirements and evolving regulatory expectations.Â
Ensure data protection capabilities align with applicable regulatory and industry expectations, including:Â
FFIECÂ
NYDFSÂ
GDPRÂ
SEC requirementsÂ
NIST frameworksÂ
ISO standardsÂ
Serve as the executive leader for data protection reviews involving regulators, auditors, clients, and control assurance functions.Â
Provide defensible and transparent reporting on the firm's data protection posture and remediation activities.Â
Â
What we valueÂ
These skills will help you succeed in this role:Â
Executive Leadership & Stakeholder Engagement - Serve as a trusted advisor to executive leadership, including the CISO, CIO, CDO, Risk leadership, and business executives.Â
Translate complex technical and data risks into clear business decisions and investment priorities.Â
Build strong partnerships across Security, Technology, Data, Legal, Privacy, Compliance, and Risk organizations.Â
Champion a culture where protecting sensitive data is viewed as a business imperative rather than a compliance exercise.Â
Team Leadership & Development - Build and lead a high-performing global Data Protection organization.Â
Develop teams responsible for:Â
Data Security EngineeringÂ
Data Discovery & ClassificationÂ
Data Governance SecurityÂ
Data Loss PreventionÂ
Data Access GovernanceÂ
Encryption & Key ManagementÂ
Mentor future leaders and establish a culture focused on innovation, accountability, automation, and measurable outcomes.Â
Recognized leader in Data Security and Data Protection.Â
Strategic thinker with the ability to execute and deliver measurable outcomes.Â
Strong business acumen and executive presence.Â
Deep understanding of modern cloud, AI, and data architectures.Â
Passion for automation, scale, and simplification.Â
Ability to influence organizational boundaries and drive enterprise-wide change.Â
Data-driven decision maker with strong risk management instincts.Â
Customer-first mindset focused on trust, resilience, and protection of critical information assets.Â
Â
Education and Preferred QualificationsÂ
Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or related discipline.Â
Advanced degree preferred.Â
Relevant certifications such as CISSP, CISM, CCSP, CDPSE, or cloud security certifications strongly preferred.Â
15+ years of progressive leadership experience in cybersecurity, data protection, data security, or related disciplines.Â
Demonstrated success leading enterprise-scale data protection programs within large, highly regulated organizations.Â
Deep expertise in data discovery, classification, DLP, encryption, key management, data governance, and access controls.Â
Proven experience securing cloud-native data ecosystems and modern data platforms.Â
Strong understanding of AI security risks and data protection requirements associated with GenAI and AI-enabled business processes.Â
Experience partnering with Data, Engineering, Privacy, Legal, Compliance, and Risk organizations.Â
Track record of driving large-scale transformation and modernization initiatives.Â
Experience presenting to executive leadership, boards, regulators, and auditors.Â
Â
What we offerÂ
Opportunity to define and lead the enterprise data protection strategy for a global systemically important financial institution.Â
Executive-level visibility and influence across Security, Technology, and Data organizations.Â
Direct impact on the firm's AI, cloud, and data transformation journey.Â
Competitive compensation and comprehensive benefits.Â
Collaborative culture focused on innovation, engineering excellence, and client trust.Â
Salary Range:
$170,000 - $282,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Learn more about this Employer on their Career Site
