Global Head of Third-Party Cyber Risk Management - State Street Corporation
Global Head of Third-Party Cyber Risk Management - State Street Corporation

Global Head of Third-Party Cyber Risk Management - State Street Corporation

London Full-Time 72000 - 108000 £ / year (est.) No home office possible
Go Premium
S

At a Glance

  • Tasks: Lead a global team to manage third-party cyber risks and protect client assets.
  • Company: Join State Street, a leading custodian bank and asset manager.
  • Benefits: Enjoy competitive pay, flexible work options, and comprehensive benefits.
  • Why this job: Make a real impact in cybersecurity while driving innovation in financial services.
  • Qualifications: 10+ years in IT/Risk, with 5+ years in senior cybersecurity leadership.
  • Other info: Diverse and inclusive workplace with opportunities for professional growth.

The predicted salary is between 72000 - 108000 £ per year.

Job Description

Who we are looking for

  • As a member of the External Cybersecurity Engagement team, this member will be responsible for Third-Party Cyber Risk Management (TPCRM), reporting to the Global Head of External Cybersecurity Engagement.
  • As the Global Head of Third-Party Cyber Risk Management, you'll be responsible for developing, implementing, and overseeing a comprehensive and global program to manage the cyber risks associated with our third-party relationships. This is a critical leadership role that requires a strategic vision and deep technical expertise to protect our firm and our clients' assets from an ever-evolving threat landscape. You'll lead a team of dedicated professionals and work closely with senior leadership across the organization, including risk, IT, and business units, to ensure our third-party ecosystem (inclusive of nth party risk) is resilient and secure.

What you will be responsible for:

  • Program Leadership: Define and execute the global third-party cyber risk management strategy, including policies, standards, and procedures.
  • Risk Assessment and Due Diligence: Oversee the entire lifecycle of third-party risk management, from initial due diligence and ongoing monitoring to contract termination. This includes conducting risk assessments to identify, measure, and mitigate cyber risks posed by vendors, suppliers, and other partners.
  • Team Management: Lead, mentor, and grow a team of third-party cyber risk professionals. Foster a culture of continuous improvement, expertise, and collaboration.
  • Governance and Reporting: Establish and maintain a robust governance framework. Provide regular reporting to senior management and the board on the state of third-party cyber risk, key metrics, and emerging threats.
  • Threat Intelligence: Stay abreast of the latest cyber threats, vulnerabilities, and regulatory changes relevant to third-party risk. Integrate threat intelligence into the risk assessment process.
  • Cross-Functional Collaboration: Partner with key stakeholders, including legal, procurement, business units, and information security to embed a risk-aware culture and ensure a consistent approach to third-party and nth party risk management.
  • Target Operating Model: Review and transform the current state of the TPCRM operating model in line with the best practice and integrate into the wider Third-Party Risk Management process, including executing on opportunities for automation.
  • External Engagement: Understanding and development of industry and sector knowledge, to ensure our TPCRM practices can leverage the enhancements in the evolving landscape.
  • Compliance: Ensure the program adheres to all relevant regulations and industry standards (e.g., NIST, ISO 27001, SOC 2).

What we value – These skills will help you succeed in this role

  • Independent, strategic thinker with an ability to operate with a global mindset and establish a long-term vision
  • Ability to courageously influence colleagues at levels
  • Strong written and oral communication skills with the ability to articulate complex technical concepts to both technical and non-technical audiences
  • Strong presentation skills
  • Multitask within multiple projects and programs
  • Thrives working within a fast-paced environment

Education & Preferred Qualifications

  • Bachelor degree or higher preferred
  • A minimum of 10 years' experience in the IT / Risk sector
  • A minimum of 5 years of experience in a senior leadership role within cyber security with a strong focus on third-party risk management, vendor risk, or supply chain security, preferably in the financial services sector
  • Relevant industry certifications such as CISSP, CISM, or CRISC are highly desirable

Additional requirements

  • Occasional travel within and outside US will be required (

Are you the right candidate? Yes!
We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don't necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team player, you could be a great fit.

Why this role is important to us
Our technology function, Global Technology Services (GTS), is vital to State Street and is the key enabler for our business to deliver data and insights to our clients. We're driving the company's digital transformation and expanding business capabilities using industry best practices and advanced technologies such as cloud, artificial intelligence and robotics process automation.

We offer a collaborative environment where technology skills and innovation are valued in a global organization. We're looking for top technical talent to join our team and deliver creative technology solutions that help us become an end-to-end, next-generation financial services company.

Join us if you want to grow your technical skills, solve real problems and make your mark on our industry.

About State Street
What we do. State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation we're making our mark on the financial services industry. For more than two centuries, we've been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment research & trading and investment management to institutional clients.
Work, Live and Grow. We make all efforts to create a great work environment. Our benefits packages are competitive and comprehensive. Details vary in locations, but you may expect generous medical care, insurance and savings plans among other perks. You'll have access to flexible Work Program to help you match your needs. And our wealth of development programs and educational support will help you reach your full potential.
Inclusion, Diversity and Social Responsibility. We truly believe our employees' diverse backgrounds, experiences and perspective are a powerful contributor to creating an inclusive environment where everyone can thrive and reach their maximum potential while adding value to both our organization and our clients. We warmly welcome the candidates of diverse origin, background, ability, age, sexual orientation, gender identity and personality. Another fundamental value at State Street is active engagement with our communities around the world, both as a partner and a leader. You will have tools to help balance your professional and personal life, paid volunteer days, matching gift program and access to employee networks that help you stay connected to what matters to you.
State Street is an equal opportunity and affirmative action employer.

Global Head of Third-Party Cyber Risk Management - State Street Corporation employer: State Street Corporation

State Street Corporation is an exceptional employer that prioritises employee growth and well-being, offering a collaborative work environment where innovation thrives. With competitive benefits, including generous medical care and flexible work programmes, employees are supported in achieving their full potential while contributing to meaningful projects in the financial services sector. The company's commitment to diversity and social responsibility further enhances its appeal, making it a great place for professionals looking to make a significant impact.
S

Contact Detail:

State Street Corporation Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Global Head of Third-Party Cyber Risk Management - State Street Corporation

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field, especially those who work at State Street or similar companies. A friendly chat can open doors and give you insights that might just land you an interview.

✨Tip Number 2

Prepare for the interview by brushing up on your knowledge of third-party cyber risk management. Be ready to discuss how you would tackle real-world scenarios and demonstrate your strategic vision. Show them you’re not just a candidate, but a future leader!

✨Tip Number 3

Don’t forget to showcase your soft skills! Communication is key in this role, so practice articulating complex ideas clearly. You want to impress them with your ability to connect with both technical and non-technical folks.

✨Tip Number 4

Finally, apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in being part of the State Street team. Let’s get you that dream job!

We think you need these skills to ace Global Head of Third-Party Cyber Risk Management - State Street Corporation

Third-Party Cyber Risk Management
Risk Assessment
Team Leadership
Governance Framework
Threat Intelligence
Cross-Functional Collaboration
Compliance with NIST and ISO 27001
Strategic Thinking
Communication Skills
Presentation Skills
Project Management
Vendor Risk Management
Industry Certifications (CISSP, CISM, CRISC)
Adaptability in Fast-Paced Environments
Data-Driven Decision Making

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Global Head of Third-Party Cyber Risk Management role. Highlight your relevant experience in cyber risk management and leadership, and don’t forget to mention any industry certifications you hold!

Showcase Your Strategic Vision: In your application, demonstrate your ability to think strategically about third-party cyber risk management. Share examples of how you've developed and implemented successful risk management strategies in the past.

Communicate Clearly: Strong written communication skills are key for this role. Ensure your application is clear and concise, articulating complex concepts in a way that’s easy to understand. This will show us you can communicate effectively with both technical and non-technical audiences.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at State Street!

How to prepare for a job interview at State Street Corporation

✨Know Your Cyber Risk Management Inside Out

Make sure you have a solid grasp of third-party cyber risk management principles. Brush up on the latest trends, regulations, and best practices in the field. Being able to discuss specific strategies you've implemented or seen work effectively will show your expertise and readiness for the role.

✨Showcase Your Leadership Skills

As this role involves leading a team, be prepared to share examples of how you've successfully managed and mentored others in the past. Highlight your ability to foster collaboration and continuous improvement within your team, as well as how you've influenced stakeholders at various levels.

✨Prepare for Technical Questions

Expect to face technical questions that assess your knowledge of cybersecurity frameworks like NIST and ISO 27001. Be ready to explain complex concepts in simple terms, as you'll need to communicate effectively with both technical and non-technical audiences.

✨Demonstrate Cross-Functional Collaboration

This role requires working closely with various departments. Prepare to discuss how you've successfully collaborated with legal, procurement, and IT teams in the past. Share specific examples of how you’ve embedded a risk-aware culture across different functions.

Global Head of Third-Party Cyber Risk Management - State Street Corporation
State Street Corporation
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

S
  • Global Head of Third-Party Cyber Risk Management - State Street Corporation

    London
    Full-Time
    72000 - 108000 £ / year (est.)

    Application deadline: 2027-09-19

  • S

    State Street Corporation

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>