Full-Time

Data Protection

Deadline 9/1/26
State Street

State Street

10,001+ employees

Asset management and custody for institutions

Compensation Overview

$170k - $282.5k/yr

+ Annual performance-based awards + 401(k) company match

Company Historically Provides H1B Sponsorship

Boston, MA, USA + 5 more

More locations: Austin, TX, USA | Berwyn, PA, USA | Clifton, NJ, USA | Princeton, NJ, USA | Quincy, MA, USA

In Person

Bachelor's

Category
Engineering Management (1)
Required Skills
Data Science
Machine Learning
Data Engineering
RAG
Cybersecurity
Risk Management
Cryptography
Data Analysis

Get referred to State Street

See people who can refer or advise you

Requirements
  • A Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or a related discipline is required.
  • At least 15 years of progressive leadership experience in cybersecurity, data protection, data security, or related disciplines is required.
  • Demonstrated success leading enterprise-scale data protection programs within large, highly regulated organizations is required.
  • Deep expertise in data discovery, classification, data loss prevention, encryption, key management, data governance, and access controls is required.
  • Proven experience securing cloud-native data ecosystems and modern data platforms is required.
  • Strong understanding of artificial intelligence security risks and data protection requirements associated with generative artificial intelligence and AI-enabled business processes is required.
  • Experience partnering with Data, Engineering, Privacy, Legal, Compliance, and Risk organizations is required.
  • A track record of driving large-scale transformation and modernization initiatives is required.
  • The role requires executive leadership, stakeholder engagement, strategic execution, business acumen, executive presence, organizational influence, risk management, and data-driven decision-making.
  • The role requires the ability to build strong partnerships across Security, Technology, Data, Legal, Privacy, Compliance, and Risk organizations.
  • The role requires a deep understanding of modern cloud, AI, and data architectures.
Responsibilities
  • Define and execute the firm's multi-year Enterprise Data Protection Strategy, aligning it with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.
  • Establish a comprehensive framework for protecting sensitive information throughout its lifecycle, including data discovery, classification, access governance, retention and disposal, encryption and key management, and monitoring and protection controls.
  • Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.
  • Develop executive-level metrics and reporting that quantify data risk, control effectiveness, and remediation progress.
  • Lead enterprise initiatives to identify, understand, and reduce data risk at scale.
  • Establish programs to identify and continuously inventory sensitive customer and firm data, regulated and restricted information, secrets and credentials, legacy data stores, high-risk repositories, and shadow data environments.
  • Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.
  • Develop actionable intelligence showing business leaders and technology teams where sensitive data resides and how it is exposed.
  • Lead the firm's strategy for protecting data from emerging AI-related threats and misuse.
  • Establish controls against prompt injection attacks, model misuse, data leakage through AI systems, retrieval-augmented generation data exposure, adversarial AI attacks, model manipulation, and AI-enabled social engineering.
  • Partner with AI, Engineering, and Security Architecture teams to deploy AI capabilities using secure-by-default configurations, approved usage patterns, security guardrails, automated controls, and enterprise-approved AI platforms.
  • Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.
  • Establish enterprise-wide data lifecycle management and retention programs designed to minimize unnecessary data exposure.
  • Eliminate obsolete and redundant data, reduce data longevity where business value no longer exists, improve defensibility and regulatory compliance, and reduce attack surface through data minimization.
  • Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.
  • Ensure retention policies are enforced through technology controls rather than manual processes whenever possible.
  • Lead enterprise efforts to analyze, govern, and continuously monitor access to sensitive information.
  • Develop and implement data-centric access control models, risk-based authorization frameworks, privileged access controls, continuous entitlement reviews, excessive permissions identification, and access anomaly detection.
  • Partner with Identity and Access Management teams to strengthen least-privilege principles across business and technology environments.
  • Ensure access decisions are informed by data sensitivity, business context, user risk, and regulatory requirements.
  • Establish a comprehensive view of the firm's data protection control environment.
  • Conduct enterprise-wide assessments to map existing controls, identify security gaps, measure control effectiveness, assess residual risk, and prioritize remediation activities.
  • Develop risk-based roadmaps focused on the most significant data protection exposures and drive accountability for timely remediation of material risks.
  • Partner with the Data organization to embed security throughout the data ecosystem.
  • Influence the design of data platforms, data pipelines, analytics environments, governance frameworks, AI and machine learning platforms, and data products.
  • Promote security-by-design principles and establish scalable security patterns that integrate into engineering workflows, automation pipelines, and platform services.
  • Lead strategic modernization initiatives supporting the future state of data security.
  • Drive improvements across enterprise encryption programs, key management services, automated key rotation, secrets management, ephemeral infrastructure, and machine identity controls.
  • Partner with Infrastructure, Cloud Engineering, and Enterprise Architecture teams to strengthen cryptographic hygiene and reduce operational risk.
  • Develop forward-looking strategies supporting emerging technology requirements and evolving regulatory expectations.
  • Ensure data protection capabilities align with FFIEC, NYDFS, GDPR, SEC requirements, NIST frameworks, and ISO standards.
  • Serve as the executive leader for data protection reviews involving regulators, auditors, clients, and control assurance functions.
  • Provide defensible and transparent reporting on the firm's data protection posture and remediation activities.
  • Serve as a trusted advisor to executive leadership, including the CISO, CIO, CDO, Risk leadership, and business executives.
  • Translate complex technical and data risks into clear business decisions and investment priorities.
  • Build and lead a high-performing global Data Protection organization.
  • Develop teams responsible for Data Security Engineering, Data Discovery and Classification, Data Governance Security, Data Loss Prevention, Data Access Governance, and Encryption and Key Management.
  • Mentor future leaders and establish a culture focused on innovation, accountability, automation, and measurable outcomes.
Desired Qualifications
  • An advanced degree is preferred.
  • Relevant certifications such as CISSP, CISM, CCSP, CDPSE, or cloud security certifications are strongly preferred.
  • Experience presenting to executive leadership, boards, regulators, and auditors.

State Street provides asset management and custody banking services for institutional investors worldwide, with State Street Global Advisors managing portfolios and offering advisory services. It generates revenue from asset management fees, transaction fees, and custody/administration fees, plus income from its own investments and lending activities. The company differentiates itself through its global scale and focus on institutional clients, offering integrated asset management, custody, administration, research, and trading across a broad network. Its goal is to help institutional clients meet their financial objectives by delivering comprehensive investment, risk management, and custody solutions on a global platform.

Company Size

10,001+

Company Stage

IPO

Headquarters

Boston, Massachusetts

Founded

1792

Get referred to State Street

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue rose 16.7% to $4.05 billion; EPS beat by 9.2%.
  • State Street won $87 million servicing fees and $384 billion new AUC/A in Q2.
  • The August 2026 preferred offering raised about $497 million for capital flexibility.

What critics are saying

  • State Street plans $500 million severance through 2029 for cloud automation and headcount cuts.
  • The LatAm acquisition needs regulatory approval, delaying synergies until 2027.
  • If asset-servicing fees keep falling, State Street becomes a low-return utility.

What makes State Street unique

  • State Street controls $57.86 trillion AUC/A and $6.28 trillion AUM, dominating institutional plumbing.
  • The Santander CACEIS Latam deal adds $470 billion custody in Brazil, Mexico, Colombia.
  • Dublin and Kilkenny investments deepen State Street’s global operations and cybersecurity footprint.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Flexible Work Hours

Remote Work Options

Professional Development Budget

Tuition Reimbursement

Paid Holidays

Employee Referral Bonus

Company News

AktienSensor
Aug 9th, 2026
State Street launches Series L perpetual preferred stock with 500,000 depositary shares offering

State Street Corporation has launched a public offering of 500,000 depositary shares, each representing one-hundredth of a Series L perpetual preferred stock share. The new Series L class features fixed-rate reset dividends aligned with risk-free rates. The company filed a Form 8-K on 5 August 2026 detailing the preferred stock amendments and offering structure. The depositary shares allow both institutional and retail investors to access the Series L preferred stock without committing to full shares, potentially broadening the investor base. State Street also announced it is changing its fiscal year to align with the calendar year, improving comparability with industry peers and streamlining tax filings. The company confirmed compliance with SEC regulations and reported no material adverse events. The perpetual structure provides State Street with capital structure flexibility whilst offering investors long-term income opportunities.

Crypto Reporter
Aug 7th, 2026
BlackRock positions tokenized cash for the stablecoin era.

BlackRock positions tokenized cash for the stablecoin era. BlackRock is expanding deeper into tokenized finance, this time targeting one of the fastest-growing opportunities created by U.S. stablecoin regulation: managing the assets that sit behind digital dollars. The world's largest asset manager has introduced two blockchain-based money market products designed to qualify as reserve assets for permitted U.S. payment stablecoin issuers under the GENIUS Act. The first, BlackRock Select Treasury Based Liquidity Fund, or BSTBL, is a tokenized share class of an existing BlackRock money market fund. Shares are available on Ethereum, giving institutional investors blockchain-based access to a traditional Treasury-focused liquidity product. The second, BlackRock Daily Reinvestment Stablecoin Reserve Vehicle, or BRSRV, is a newly created money market fund designed specifically with stablecoin reserves in mind. It offers daily dividend reinvestment and is being made accessible across multiple blockchains. Securitize serves as its transfer agent and tokenization provider. The launches point to a potentially significant consequence of stablecoin regulation. Stablecoin issuers generally need highly liquid, low-risk assets backing the tokens they put into circulation. Under the U.S. regulatory framework, that means instruments such as cash, Treasury securities and qualifying investment products. For large asset managers, those reserve requirements create a new pool of institutional money to manage. BlackRock has made clear that it wants a significant role in that market. The company already manages about $60 billion in reserves for Circle, the issuer of USDC, according to comments from BlackRock Chief Financial Officer Martin Small during its second-quarter earnings call. That represents a substantial share of a stablecoin market now valued at roughly $300 billion. BlackRock is not entering tokenized finance from scratch. In 2024, it launched the BlackRock USD Institutional Digital Liquidity Fund, better known as BUIDL, with Securitize. The tokenized money market fund has since grown to approximately $2.5 billion in assets and has increasingly been used within crypto markets as collateral. BSTBL and BRSRV take the strategy a step further. Instead of simply putting an investment fund on a blockchain, BlackRock is positioning tokenized funds as part of the financial infrastructure supporting regulated stablecoins. The opportunity has also attracted competitors. State Street, Franklin Templeton, Invesco and other large asset managers are developing products aimed at the growing market for stablecoin reserves and tokenized cash. This could create an unusual relationship between traditional asset management and digital currencies. Stablecoins are sometimes portrayed as competitors to traditional finance because they can move money outside conventional banking and payment networks. Yet their growth may simultaneously create demand for some of Wall Street's most traditional products: Treasury securities and money market funds. Tokenization adds another layer. Reserve assets themselves can increasingly exist in blockchain-compatible form, potentially allowing issuers to manage liquidity, collateral and settlement within the same digital infrastructure used for stablecoins. BlackRock has argued to U.S. regulators that tokenized versions of eligible reserve assets should not face additional limits merely because they are recorded on a distributed ledger. The company maintains that credit quality, duration and liquidity - rather than the underlying technology - should determine an asset's risk. That position offers a clue to where the market may be heading. Stablecoins may be crypto-native products, but the infrastructure beneath them is rapidly becoming institutional. As regulation defines what issuers can hold, major asset managers are competing to manage those reserves and bring them on-chain. BlackRock's latest launches suggest that the stablecoin boom may ultimately create as much opportunity for traditional finance as it does for crypto companies.

Kalkine Media
Aug 6th, 2026
State Street Corporation Acquires 5.01% Stake in Kingsgate Consolidated as Substantial Holder

Catch the latest updates from Australia's premier stock exchange & market indices.

Kalkine Media
Aug 6th, 2026
State Street Corporation Acquires 5.01% Stake in Mesoblast Limited, Becoming a Substantial Shareholder

Catch the latest updates from Australia's premier stock exchange & market indices.

PitchOnNet
Aug 6th, 2026
State Street appoints Kenneth Vamshi as Managing Director.

State Street appoints Kenneth Vamshi as Managing Director. Prior to joining State Street, Vamshi was associated with HSBC for more than 22 years State Street has appointed Kenneth Vamshi as Managing Director, with Hyderabad serving as his base of operations. A seasoned finance and transformation leader, Vamshi brings deep expertise in finance operations, digital transformation and the establishment of global capability centres (GCCs). Over the course of his career, he has spearheaded finance transformation programmes and built GCCs across complex, multi-country business environments. Vamshi joins State Street after spending more than 22 years at HSBC. In his most recent role, he served as Senior Vice President, Head of Digital Finance and GCC Site Head, where he led digital finance initiatives and oversaw the company's GCC operations.