Data Protection, Managing Director
We are seeking a visionary security leader to define, govern, and scale the firm's enterprise-wide data protection strategy. This senior leadership role reports directly to the SVP of Data and AI Security and is responsible for establishing a modern, risk-based data security program that enables digital, cloud, AI, and data transformation while protecting critical information assets.
About the role
This role sits in the AI & Data Protection team within the Global Cybersecurity group at State Street. Global Cybersecurity is vital to the bank as it protects client trust, safeguards critical assets, enables business growth, and ensures safe operation in an increasingly complex threat and regulatory environment.
Responsibilities
- Define and execute the firm's multi-year Enterprise Data Protection Strategy, aligning with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.
- Establish a comprehensive framework for protecting sensitive information throughout its lifecycle, including:
- Data discovery
- Classification
- Access governance
- Retention and disposal
- Encryption and key management
- Monitoring and protection controls
- Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.
- Develop executive-level metrics and reporting that quantify data risk, control effectiveness, and remediation progress.
- Lead enterprise initiatives to identify, inventory, and reduce data risk at scale, including:
- Sensitive customer and firm data
- Regulated and restricted information
- Secrets and credentials
- Legacy data stores
- High-risk repositories
- Shadow data environments
- Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.
- Develop actionable intelligence to help business leaders and technology teams understand where sensitive data resides and how it is exposed.
- Lead the firm's strategy for protecting data from emerging AI-related threats and misuse, including:
- Prompt injection attacks
- Model misuse
- Data leakage through AI systems
- Retrieval-augmented generation (RAG) data exposure
- Adversarial AI attacks
- Model manipulation
- AI-enabled social engineering
- Partner with AI, Engineering, and Security Architecture teams to ensure AI capabilities are deployed using:
- Secure-by-default configurations
- Approved usage patterns
- Security guardrails
- Automated controls
- Enterprise-approved AI platforms
- Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.
- Establish rigorous enterprise-wide data lifecycle management and retention programs to:
- Eliminate obsolete and redundant data
- Reduce data longevity where business value no longer exists
- Improve defensibility and regulatory compliance
- Reduce attack surface through data minimization
- Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.
- Lead enterprise efforts to analyze, govern, and continuously monitor access to sensitive information, including:
- Data-centric access control models
- Risk-based authorization frameworks
- Privileged access controls
- Continuous entitlement reviews
- Excessive permissions identification
- Access anomaly detection
- Partner with Identity and Access Management teams to strengthen least-privilege principles across business and technology environments.
- Establish a comprehensive view of the firm's data protection control environment by conducting enterprise-wide assessments to:
- Map existing controls
- Identify security gaps
- Measure control effectiveness
- Assess residual risk
- Prioritize remediation activities
- Drive accountability across technology and business stakeholders to ensure timely remediation of material risks.
- Partner with the Data organization to embed security throughout the data ecosystem, influencing the design of:
- Data platforms
- Data pipelines
- Analytics environments
- Governance frameworks
- AI and ML platforms
- Data products
- Promote security-by-design principles that enable innovation while reducing operational friction.
- Lead strategic modernization initiatives supporting the future state of data security, including:
- Enterprise encryption programs
- Key management services
- Automated key rotation
- Secrets management
- Ephemeral infrastructure
- Machine identity controls
- Ensure data protection capabilities align with applicable regulatory and industry expectations, including:
- FFIEC
- NYDFS
- GDPR
- SEC requirements
- NIST frameworks
- ISO standards
- Serve as the executive leader for data protection reviews involving regulators, auditors, clients, and control assurance functions.
Skills
- Executive Leadership & Stakeholder Engagement: Serve as a trusted advisor to executive leadership, translating complex technical and data risks into clear business decisions. Build strong partnerships across Security, Technology, Data, Legal, Privacy, Compliance, and Risk organizations.
- Team Leadership & Development: Build and lead a high-performing global Data Protection organization, mentoring future leaders and fostering a culture of innovation, accountability, automation, and measurable outcomes.
- Recognized leader in Data Security and Data Protection with a strategic mindset and ability to execute.
- Strong business acumen and executive presence.
- Deep understanding of modern cloud, AI, and data architectures.
- Passion for automation, scale, and simplification.
- Ability to influence organizational boundaries and drive enterprise-wide change.
- Data-driven decision maker with strong risk management instincts.
- Customer-first mindset focused on trust, resilience, and protection of critical information assets.
Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or related discipline. Advanced degree preferred.
- Relevant certifications such as CISSP, CISM, CCSP, CDPSE, or cloud security certifications strongly preferred.
- 15+ years of progressive leadership experience in cybersecurity, data protection, data security, or related disciplines.
- Demonstrated success leading enterprise-scale data protection programs within large, highly regulated organizations.
- Deep expertise in data discovery, classification, DLP, encryption, key management, data governance, and access controls.
- Proven experience securing cloud-native data ecosystems and modern data platforms.
- Strong understanding of AI security risks and data protection requirements associated with GenAI and AI-enabled business processes.
- Experience partnering with Data, Engineering, Privacy, Legal, Compliance, and Risk organizations.
- Track record of driving large-scale transformation and modernization initiatives.
- Experience presenting to executive leadership, boards, regulators, and auditors.
Benefits
- Opportunity to define and lead the enterprise data protection strategy for a global systemically important financial institution.
- Executive-level visibility and influence across Security, Technology, and Data organizations.
- Direct impact on the firm's AI, cloud, and data transformation journey.
- Competitive compensation and comprehensive benefits, including:
- Retirement savings plan (401K) with company match
- Insurance coverage (basic life, medical, dental, vision, long-term disability, and other optional coverages)
- Paid-time off (vacation, sick leave, short-term disability, and family care responsibilities)
- Employee Assistance Program
- Incentive compensation (annual performance-based awards)
- Tax-advantaged savings plans
- Collaborative culture focused on innovation, engineering excellence, and client trust.
Pay
Salary Range: $170,000 - $282,500 Annual. The range applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location, the applicable range could differ.