Technical Cyber Security Advisory, Vice President in London

Technical Cyber Security Advisory, Vice President in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
State Street

At a Glance

  • Tasks: Lead cyber security initiatives and provide expert advice across the bank.
  • Company: Join a global leader in financial services with a commitment to innovation.
  • Benefits: Flexible hybrid work, inclusive culture, and opportunities for professional growth.
  • Other info: Collaborative environment with a focus on employee empowerment and development.
  • Why this job: Make a real impact on cyber resilience in a rapidly evolving threat landscape.
  • Qualifications: 10-15 years in cyber security with strong technical and advisory skills.

The predicted salary is between 63000 - 77000 £ per year.

We are looking for a Vice President of Cyber Security reporting to the Regional CISO, UK & Ireland. You will act as a senior cyber advisor across the bank, working with business, technology, risk, compliance, and Global Cybersecurity teams to identify practical security improvements and drive change that strengthens cyber resilience.

The successful candidate will bring strong technical credibility utilising a breadth of knowledge from offensive security, cyber risk, and security solution architecture experience. You will be comfortable reviewing complex technology and control issues, challenging proposed approaches constructively, and translating technical risk into clear, actionable decisions for senior stakeholders.

The team you will be joining is part of the Regional CISO organization within Global Cybersecurity (GCS), a key function to the bank because it connects global cyber capabilities with regional business, regulatory, legal entity, and client priorities. This is a vital role to determine technical cyber requirements for the regional to global stakeholder and provide implementation guidance, helping the bank remain secure in a rapidly evolving threat landscape.

In this role, you will:

  • Provide senior cyber advisory and constructive challenge to business, technology, and cyber teams on cyber security matters.
  • Review complex cyber issues and support solution design, including findings from offensive security testing, vulnerability management, incident lessons learned, and architecture reviews.
  • Translate security insights into practical risk based remediation plans that reduce risk exposure for the organization.
  • Lead or materially contribute to regulatory alignment activities, including impact assessments, evidence reviews, responses to supervisory queries, readiness reviews, and remediation tracking.
  • Drive change across the bank by identifying recurring control weaknesses, root causes, and opportunities to simplify or improve cyber processes, governance, metrics, and accountability.
  • Prepare clear briefings, papers, risk narratives, and executive updates for senior stakeholders, governance forums, legal entity committees, and Regional CISO leadership.
  • Act as a regional point of orchestration for cross-functional cyber activities, ensuring issues are owned, prioritised, and progressed through to measurable outcomes.
  • Support client, business, and external engagement where specialist cyber input is required, presenting the bank's cyber posture and improvement activity in a clear and credible manner.

We are looking for a strong technical candidate with hands-on experience who is able to translate complex technical solutions to both senior technology and business stakeholders. Technical cyber knowledge with the credibility to engage senior engineers, architects, offensive security specialists, risk teams, and senior business stakeholders is essential.

Practical offensive security awareness, including attack paths, common enterprise weaknesses, penetration testing outputs, red/purple team findings, exploitability, and risk-based remediation is important. Security solution architecture knowledge across cloud, identity and access management, network security, application security, endpoint, data protection, third-party connectivity, and resilience controls is also required.

Strong influencing and change leadership skills, with the confidence to challenge constructively and bring teams together around executable solutions are necessary. The ability to convert regulatory expectations and audit findings into pragmatic implementation plans that work in a complex banking environment is crucial.

Excellent written and verbal communication skills, including the ability to explain technical risk in concise, business-relevant language, are needed. Sound judgement, ownership mindset, and the ability to balance risk reduction, regulatory expectations, business delivery, and operational practicality are essential.

Education & Preferred Qualifications:

  • Degree: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Risk Management, or a related discipline preferred; equivalent industry experience will always be considered.
  • Years of experience: Typically 10-15 years of experience in cyber security, technology risk, security architecture, offensive security, cyber consulting, operational resilience, or a related financial services role.
  • Certifications: Relevant certification to support relevant experience such as CISSP, CISM, CRISC, OSCP, CREST, GIAC/SANS, SABSA and vendor specific certification.
  • Knowledge of tools or technologies: Practical and demonstrable knowledge of MITRE ATT&CK, NIST CSF, ISO 27001, CIS Controls, threat-led penetration testing, vulnerability management, cloud security, IAM, SIEM/SOAR, EDR, application security, network security, and secure architecture design.

Additional requirements for this role include:

  • Some travel may be required for regional stakeholder, client, industry, or regulatory engagement.
  • The role may occasionally support urgent cyber, regulatory, or incident-related activity outside standard working hours.
  • The candidate must be able to handle confidential and sensitive information appropriately.

Hybrid Work Requirement: London-based hybrid working arrangement, with regular presence in the London office in line with business and team requirements.

Shift Timings: UK business hours, with flexibility required to support global stakeholders and time-sensitive cyber or regulatory matters.

About State Street: Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Technical Cyber Security Advisory, Vice President in London employer: State Street

State Street is an exceptional employer, offering a dynamic work environment in the heart of the UK financial sector. With a strong commitment to employee development, inclusive culture, and flexible work-life balance, we empower our team members to thrive while contributing to meaningful governance initiatives. Join us to be part of a collaborative team that values your insights and fosters your professional growth.

State Street

Contact Details:

State Street Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Technical Cyber Security Advisory, Vice President in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including State Street, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through State Street

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at State Street. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Technical Cyber Security Advisory, Vice President in London

Cyber Security Advisory
Offensive Security Knowledge
Cyber Risk Assessment
Security Solution Architecture
Vulnerability Management
Incident Response
Regulatory Compliance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at State Street insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to State Street that you’re committed to staying ahead in the game.

How to prepare for a job interview at State Street

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at State Street to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at State Street.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.