We are looking for a Data Protection Managing Director reporting directly to the SVP of Data and AI Security. The Managing Director, Data Protection is a senior leadership role responsible for defining, governing, and scaling the firm's enterprise-wide data protection strategy. This leader will establish a modern, risk-based data security program that enables the organization's digital, cloud, AI, and data transformation objectives while protecting the firm's most critical information assets. The role requires a visionary security leader who can balance business enablement with strong security outcomes. The successful candidate will drive the evolution from traditional data protection approaches toward a modern, intelligence-driven program focused on data discovery, classification, retention, access governance, AI security, and automated protection controls.
The Managing Director will serve as the firm's foremost authority on data security and protection, partnering across Security, Engineering, Data, Privacy, Legal, Risk, Compliance, Infrastructure, and Business teams to ensure security is embedded into platforms, pipelines, governance frameworks, and delivery processes.
Why this role is important to us
This role sits in the AI & Data Protection team which is part of the Global Cybersecurity group at State Street. Global Cybersecurity is vital to the bank because it protects client trust, safeguards critical assets, enables business growth, and ensures the bank can operate safely in an increasingly complex threat and regulatory environment.
What you will be responsible for
Define and execute the firm's multi-year Enterprise Data Protection Strategy, ensuring alignment with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.
Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.
Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.
Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.
Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.
Ensure access decisions are informed by data sensitivity, business context, user risk, and regulatory requirements.
Serve as the executive leader for data protection reviews involving regulators, auditors, clients, and control assurance functions.
These skills will help you succeed in this role:
Executive Leadership & Stakeholder Engagement - Serve as a trusted advisor to executive leadership, including the CISO, CIO, CDO, Risk leadership, and business executives.
Build strong partnerships across Security, Technology, Data, Legal, Privacy, Compliance, and Risk organizations.
Mentor future leaders and establish a culture focused on innovation, accountability, automation, and measurable outcomes.
Education and Preferred Qualifications
Bachelor's degree in Information Security, Computer Science, Engineering, Data Science, or related discipline.
Relevant certifications such as CISSP, CISM, CCSP, CDPSE, or cloud security certifications strongly preferred.
15+ years of progressive leadership experience in cybersecurity, data protection, data security, or related disciplines.
Deep expertise in data discovery, classification, DLP, encryption, key management, data governance, and access controls.
Experience partnering with Data, Engineering, Privacy, Legal, Compliance, and Risk organizations.
Salary Range:
$170,000 - $282,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range co...