Head of Service (Temporary) in London

Head of Service (Temporary) in London

London Temporary No working from home possible
S

Who we are looking forGlobal Cybersecurity (GCS) protects State Street and its clients from the impact of cyber-attacks against systems by understanding the risks these attacks present and mitigating them through a robust, continuously evolving cybersecurity program and control environment. Reporting to the Head of Identity & Access Management, the Head of Workforce Authentication Services, MD will lead the strategic direction, engineering, operations and compliance posture of all workforce authentication platforms at State Street. This role consolidates capabilities currently distributed across two towers into a single, accountable engineering and operations leadership role. What you will be responsible forScope of Platforms and Services The role owns engineering, operations, resilience and compliance for the workforce authentication platform stack, including but not limited to: Directory & Identity Plane: Active Directory (on-premises forests, domain controllers, Kerberos, Group Policy), Microsoft Entra ID, Entra Connect, Cloud Kerberos Trust, Conditional Access Federation & SSO: Identity Providers, SAML/OIDC federation, SSO onboarding intake and engineering Strong Authentication & MFA: MFA systems, FIDO2, MFA compliance reporting and exception management Passwordless Program (Workforce): Engineering leadership across the full passwordless roadmap β€” vendor assessments, CA policy design, OS/endpoint integration and other touch points in the technology stack. Resilience & Operations: 24x7 run of authentication services, DR/BCP, capacity, patching, DC exit programs, vulnerability and pen-test finding remediation across the authentication estate Key Responsibilities Strategic Leadership Develop and execute a single, unified Workforce Authentication strategy that consolidates all authentication services into one engineering and operations function with one accountable leader. Engineering Leadership – Workforce Passwordless Serve as the engineering owner of the Workforce Passwordless program, accountable for delivery against EC-committed milestones and the financial plan. Lead the technical design and rollout of supporting technologies required to enable transition to passwordless authentication. Standards, Compliance & Lines of Defence Own the Authentication compliance with IAM Standard (Account Authentication, Password Parameters, MFA, Federation/SSO, Session Management) and ensure alignment to NIST SP 800-53, NIST SP 800-63B, DORA, BAIT, UK PRA SS1/21, MAS TRM, HKMA SPM and APRA CPS 234. Support assurance compliance with the Second Line of Defence (Technology Risk Management), Third Line (Corporate Audit) and External Auditors (E&Y) β€” including evidence ownership, RCSA control mapping, and finding remediation. Provide a support and data for compliance management across the workforce authentication environment: control design, control testing readiness, KRI/KPI reporting to the IAM Governance Council, Cybersecurity Risk Committee (CRC) and Technology Risk Committee (TRC). Remediation & Audit/Pen-Test Findings Own end-to-end remediation of all audit, regulatory and penetration-test findings affecting workforce authentication. Resilience & Operations of Critical Systems Accountable for the availability, performance and resilience of Tier-0 authentication services including DR posture, recovery testing, capacity management, and major-incident command for authentication outages. Own the operational interface for Authentication Services with key partners including End User Computing, Platform Engineering, Production Management, Network and the regional IT heads. People & Operating Model Lead a globally distributed team across; evolve the operating model in line with the IAM portfolio management framework. Drive talent strategy, succession, and a culture of engineering excellence, multi-disciplinary delivery and accountable ownership. What we value These skills will help you succeed in this role15+ years in technology / engineering / security roles, with at least 8 years leading large-scale authentication engineering and operations functions ideally in a regulated financial services environment. Deep, hands-on technical depth across Active Directory, Microsoft Entra ID, Kerberos, LDAP, SAML, OIDC, FIDO2/WebAuthn, MFA, and federation platforms. Experience operating Tier-0 critical services with strict availability, DR and resilience SLAs. Experience leading globally distributed teams across US, EMEA and India. Bachelors Degree in Cyber Security or related technical disciplineSalary Range: $170,000 - $282,500 AnnualThe range quoted above applies to the role in the primary location specified. Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans. About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law. com/careersRead our CEO StatementJob Application Disclosure: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. London, EnglandType: Full time

Head of Service (Temporary) in London employer: State Street Bank

State Street Global Technology Services is an exceptional employer that prioritises employee growth and inclusivity, offering a dynamic work environment in London. With a strong commitment to professional development, flexible work-life balance, and vibrant employee networks, we empower our team members to thrive while driving impactful change in the financial services sector. Join us to be part of a culture that values collaboration, accountability, and innovation, ensuring that every voice is heard and every contribution matters.

S

Contact Details:

State Street Bank Recruitment Team