MD GRC Risk Management and Governance in London
MD GRC Risk Management and Governance

MD GRC Risk Management and Governance in London

London Full-Time No home office possible
State Street

At a Glance

  • Tasks: Lead a team in designing and overseeing cyber risk management frameworks.
  • Company: Join State Street, a global leader in institutional investing.
  • Benefits: Enjoy competitive salary, comprehensive benefits, and flexible work-life support.
  • Other info: Inclusive culture with development opportunities and vibrant employee networks.
  • Why this job: Make a real impact in cybersecurity while shaping the future of risk management.
  • Qualifications: 10+ years in cybersecurity risk management and strong leadership skills required.

The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ensures cyber risk is consistently identified, assessed, governed, and reported in alignment with the Enterprise Risk Framework, regulatory expectations, and the firm’s risk appetite. The role serves as a central coordination point, with a strong focus on framework governance, risk management, findings oversight and management, and executive‑level reporting.

Responsibilities

  • Own and evolve the Cyber Risk Management Framework, ensuring alignment with the Enterprise Risk Framework and regulatory expectations.
  • Govern cyber risk taxonomies, risk appetite statements, risk metrics, and assessment methodologies.
  • Support embedding cyber risk practices across the L3 Cyber risk methodology and support functional and business risk owners in their efforts to improve and sustain cyber risk posture.
  • Provide oversight of control assurance and remediation execution and quality, including challenge, escalation, and consistency.
  • Ensure consistent linkage between assessment outcomes, risk appetite, and remediation priorities.
  • Enable and guide Enterprise Process Owner (EPO) / Metric Owners with challenges related to processes area / Key Risk Indicator improvement, ensuring clear accountability and effective operation.
  • Support the second line of defense in defining, maintaining, and overseeing Cyber Key Risk Indicators (KRIs) and thresholds, ensuring they provide meaningful insight into risk posture and trends.
  • Coordinate cyber risk matters for management‑level and executive Risk Committees, including agenda development, materials, and escalation.
  • Produce and oversee executive‑level cyber risk reporting, including risk posture, trends, material issues, and emerging risks.
  • Ensure reporting is concise, decision‑oriented, and aligned with enterprise and Board risk governance expectations.
  • Serve as the primary cyber risk interface with Technology Risk Advisors (TRAs), coordinating inputs, challenge, outcomes, and follow‑through.
  • Oversee LOD and legal entity cyber risk reporting, ensuring a consistent Global Cybersecurity view.
  • Coordinate with Cyber Compliance teams to provide accurate data sharing for regulatory engagement and legal entities.
  • Provide governance oversight for issues that impact cyber risk, including intake, severity assessment, challenge, escalation, and closure monitoring.
  • Oversee cyber risk acceptance governance, ensuring decisions are risk‑informed, appropriately documented, time‑bound, and approved at the correct level.
  • Ensure alignment between issues, risk acceptances, and risk appetite.
  • Lead the intake and governance of cyber findings from audits, regulatory reviews, assessments, and testing activities.
  • Ensure findings are consistently risk‑rated, challenged where appropriate, and tracked through remediation to closure.
  • Monitor remediation progress, aging, and systemic themes, escalating concerns as needed to governance/management committees.

Qualifications

  • 10+ years of experience in cybersecurity risk management, technology risk, or enterprise risk governance, with significant experience at a senior leadership level.
  • Bachelor’s degree in information systems, computer science, data analytics, cybersecurity or related field (or equivalent experience).
  • Deep understanding of cyber risk frameworks, enterprise risk management, and regulatory expectations within a large, complex financial services or regulated environment.
  • Proven experience with risk governance, control assurance and assessments, KRIs, issue management, and executive reporting.
  • Strong ability to build relationships across the three lines of defense and influence at executive and Board levels.
  • Exceptional communication skills, with the ability to translate technical and risk concepts into executive‑level insights.
  • Experience leading highly successful teams in achieving objectives and key results.

Preferred Skills

  • Cybersecurity Certifications such as: CISSP, CISM or equivalent.
  • Experience implementing automated and/or continuous controls monitoring in cloud and hybrid environments.
  • Strong analytical mindset with the ability to translate ambiguous risk or control questions into measurable metrics and repeatable tests.
  • Clear written and verbal communication skills, including the ability to explain complex technical findings and trends to leadership.

Salary Range

$170,000 - $282,500 Annual

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long‑term disability, and other optional additional coverages; paid‑time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance‑based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

MD GRC Risk Management and Governance in London employer: State Street

State Street is an exceptional employer that prioritises the growth and well-being of its employees, offering a comprehensive benefits package including retirement savings plans, health insurance, and generous paid time off. The company fosters a collaborative and inclusive work culture, empowering team members to reach their full potential while providing opportunities for professional development and engagement in vibrant employee networks. Located in a dynamic financial services environment, State Street is committed to innovation and excellence, making it an ideal place for those seeking meaningful and rewarding careers in cyber risk management.
State Street

Contact Detail:

State Street Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land MD GRC Risk Management and Governance in London

✨Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the lookout for opportunities. A personal recommendation can go a long way in landing that dream job.

✨Tip Number 2

Prepare for interviews by brushing up on your knowledge of cyber risk frameworks and governance. Be ready to discuss how you can contribute to the company's risk management strategies and demonstrate your understanding of regulatory expectations.

✨Tip Number 3

Showcase your leadership skills! When speaking with potential employers, highlight your experience in leading teams and driving results in risk management. They want to see that you can guide others and make impactful decisions.

✨Tip Number 4

Don't forget to apply through our website! It's the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in joining our team at State Street.

We think you need these skills to ace MD GRC Risk Management and Governance in London

Cyber Risk Management
Governance Framework Design
Risk Assessment Methodologies
Control Assurance
Executive-Level Reporting
Key Risk Indicators (KRIs)
Regulatory Compliance
Stakeholder Engagement
Analytical Skills
Communication Skills
Team Leadership
Problem-Solving Skills
Technical Understanding of Cybersecurity
Relationship Building
Risk Appetite Alignment

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the role. Highlight your experience in cyber risk management and governance, and show how it aligns with our needs at StudySmarter.

Showcase Your Achievements: Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Use metrics where possible to quantify your success in managing cyber risks.

Be Clear and Concise: When writing your application, keep it clear and to the point. We appreciate well-structured documents that make it easy for us to see your qualifications and fit for the role.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role you’re interested in!

How to prepare for a job interview at State Street

✨Know Your Cyber Risk Frameworks

Before the interview, make sure you have a solid understanding of various cyber risk frameworks and how they align with enterprise risk management. Be prepared to discuss how you've applied these frameworks in your previous roles, as this will show your expertise and relevance to the position.

✨Prepare for Executive-Level Communication

Since this role involves reporting to executive levels, practice translating complex technical concepts into clear, concise insights. Think about examples from your past where you successfully communicated risk findings to senior management, and be ready to share those stories.

✨Showcase Your Leadership Experience

Highlight your experience in leading teams and achieving objectives. Prepare specific examples that demonstrate your ability to build relationships across different lines of defence and influence decision-making at the executive level. This will help illustrate your fit for a senior leadership role.

✨Understand Regulatory Expectations

Familiarise yourself with the regulatory landscape relevant to cyber risk management. Be ready to discuss how you've navigated compliance challenges in the past and how you would ensure alignment with regulatory expectations in this new role.

MD GRC Risk Management and Governance in London
State Street
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>