Senior Business Information Security Officer- Managing Director
About this role
MD, Senior Business Information Security Officer (India)
The MD, Senior Business Information Security Officer (India) serves as the accountable executive for information security risk management and cyber resilience across India‑based operations. The role ensures adherence to applicable India cyber and data protection regulations while aligning with the global cybersecurity strategy, enterprise risk appetite, and client obligations.
The Senior BISO acts as the primary cybersecurity advisor to India executives, regulators, legal entities, risk committees, and business leaders, while coordinating closely with global cybersecurity functions to drive consistent security outcomes and regulatory compliance across the India region.
The role balances global cybersecurity standards with regional business and regulatory requirements while driving execution across complex environments. The Senior BISO is expected to operate as a trusted advisor to executive leadership, while being able to translate complex cybersecurity issues into business-oriented risk decisions.
Key Responsibilities
Serve as the senior cybersecurity advisor for local India business teams bringing relevant and actional data so teams can maintain compliance with India cybersecurity and data protection regulations including CERT-In Directions, DPDP Act, RBI, and SEBI.
Lead cybersecurity assessments and establish partnerships with business and technology teams to remediate cyber risk in India.
Actively work with Operational Risk and Compliance teams to translate India regulations into actionable enterprise security controls aligned with global standards.
Manage India cyber risk posture, risk assessments, and material risk reporting into global governance forums.
Provide executive risk advisory services and issue escalation recommendations.
Senior escalation points for cybersecurity incidents impacting India‑based systems, data, and clients.
Support business growth by enabling compliant cloud, digital, outsourcing, and third‑party models within India regulatory requirements.
Take an active role in assessing India‑based vendors, service providers, and intra‑group outsourcing arrangements working locally and with global third-party risk management teams.
Ensure service providers comply with India regulatory expectations for data localization, logging, monitoring, and incident reporting as part of the global cybersecurity standards.
Represent cybersecurity in India executive leadership forums.
Required Experience & Qualifications
10+ years in information security / cyber risk, including senior leadership experience in regulated environments.
Proven experience operating at a leadership level, engaging regulators, boards, and senior business leadership.
Demonstrated hands‑on experience with India cyber regulations, including CERT‑In directives and sector‑specific frameworks.
Experience supporting regulatory exams, audits, and enforcement actions in India.
Strong preference for financial services, payments, asset management, banking, or similarly regulated industries.
Experience in global operating models and matrixed organizations.
Technical and Cyber Depth
Strong firsthand experience with incident response and crisis management.
Thorough understanding of data protection principles and privacy engineering standards.
Understanding of Multi-Cloud and SaaS risk models.
Experience with architecture patterns and cyber engineering concepts (i.e., Defense in Depth, zero trust, network segmentation, etc.)
Control knowledge into identity and access management, logging and monitoring requirements, and cyber resiliency controls.
Functional experience with frontier large language Models (LLMs) i.e. GPT, Claude, Gemini, etc.
Familiar with threat model applicability (i.e., SDLC integration, security design reviews, etc.)
Ability to translate technical risk into executive‑level decision frameworks.
Experience with conceptual security processes surrounding Generative AI (GenAI) and Agentic AI models.
Highly Desirable Attributes
Ability to quickly earn trust and credibility with regulators and senior stakeholders.
Ability to multi-task and pass along sound judgment.
Pragmatic, business – enabling security mindset.
Being curious into ways that both processes and technology can improve to gain better visibility while ensuring better security for clients and customers.
Success Measures
Reduction in material cybersecurity risk across the India businesses.
Strong regulatory adherence and cyber exam outcomes.
Cybersecurity culture program maturity.
Business satisfaction and executive stakeholder engagement.
Talent development and organizational effectiveness.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Company at a glance
At State Street, we deliver leading investment platforms, data, expertise, and solutions that accelerate performance and better decision making.
With over 200 years of global financial leadership, we equip institutional investors through a comprehensive suite of capabilities:
Investment Services: Integrated front-to-back solutions across custody, accounting, and operations.
Investment Management: Index and active strategies from one of the world’s largest asset managers.
Markets: Multi-asset trading, FX solutions, and data-driven research to enhance portfolio value.
Who We Are
- 50,000+ employees worldwide
- Active in 100+ markets
- #1 in ETF servicing
What You’ll Find Here
- Executive perspectives and thought leadership
- Timely market commentary and macro insights
- Our views on investment operations, ETFs, private markets, and digital finance
- Stories reflecting our culture, values and commitment to diversity and inclusion
Top Benefits
- Inclusive development opportunities
- Flexible work-life support
- Paid volunteer days
- Employee networks
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?