Head of Threat & Vulnerability Operations
Job description
The Head of Threat & Vulnerability Operations (TVO) is a senior leadership role accountable for scaling the firm's threat and vulnerability capability into a modern, product-led, data-driven operations platform. This is a digital transformation mandate at enterprise scale, and the leader we are looking for is energized by building durable operating capability, not just running one.
This leader owns the firm's transition to a frontier-AI-ready operating model, where every discovery signal, including enterprise and infrastructure scanning, static and dynamic code analysis, first-party code, open source, external attack surface, red team and penetration testing, and frontier-AI model scanning, is consolidated into one authoritative, reconciled exposure picture; findings are validated, tracked and escalated at machine speed; and reporting to executives, the Board and regulators is standardized, evidence-based and self-service. The function owns discovery, validation, prioritization, communication, tracking, reporting and governance across the findings lifecycle, while engineering, infrastructure and application teams own remediation.
The role is accountable for total exposure visibility across every signal; threat-informed prioritization that surfaces genuinely exploitable risk ahead of raw volume; machine-speed tracking and escalation that drives remediation faster than adversaries can exploit findings; design and deployment of end-to-end architecture that accelerates attack-surface reduction with appropriate human validation and guardrails; and provable, trusted assurance for the Board, regulators and clients. The Head of TVO builds and leads the team, sets modernization priorities, and serves as the primary point of accountability for exposure data quality, scoring methodology and regulatory commitments, centralizing reporting-as-a-service and defining the frequency, format and content therein.
Key Responsibilities
Strategy, Modernization & Transformation
- Own and drive the modernization of the firm's threat and vulnerability capability into a scalable, product-led operations platform, organizing the function around the outcomes of total exposure visibility, machine-speed tracking and escalation, threat-informed prioritization, architecture-led attack-surface reduction, and provable assurance.
- Set and sequence the transformation roadmap deliberately, establishing measurement before commitment and consolidation before automation, so that change is evidence-led and sustainable at enterprise scale.
- Lead consolidation of all discovery signals into one backlog with a single severity language and a single SLA clock, establishing one authoritative, reconciled exposure count across enterprise scanning, code analysis and remediation orchestration platforms.
- Own evolution of the vulnerability scoring model and Key Risk Indicators (KRIs), advancing from control-presence measures to threat-informed, outcome and velocity metrics (e.g., MTTD/MTTR) mapped to business-aligned risk-tolerance thresholds and reconciled to the firm's enterprise control and assurance framework.
- Set and continuously reassess SLA and remediation-timeline strategy in response to the accelerated pace of frontier-AI and adversary discovery, including differentiated treatment for context enriched, intel driven prioritized tranches of risk exposure.
- Establish and uphold a consistent set of architectural principles across the platform, including flexibility with no single-vendor or single-model dependency, one view of findings, one backlog and one clock, threat-informed prioritization over volume, automation of the path with human governance of the risk, and closure that is proven rather than asserted.
Exposure Intelligence, Discovery & Findings Oversight
- Own Exposure Intelligence & Attack Surface Management: a single normalized exposure picture ingesting every signal, including external attack surface, infrastructure scanning, AI and frontier-model findings, cloud, open source, and threat intelligence, and govern the advisory and known-exploited-vulnerability clearinghouse and coverage-exclusions process.
- Direct continuous, exposure-tiered discovery and frontier-AI scanning across first-party code, open source, infrastructure and cloud via a governed AI-scanning framework, and own pre-production tollgate criteria and decisions.
- Own tracking, routing, escalation and consequence management for remediation executed by application owners and infrastructure teams, using a unified work plane and enterprise system of record to enforce SLAs, and define, publish and report the metrics that objectively evidence progress and risk reduction (e.g., MTTR, SLA compliance).
- Build end-to-end findings lifecycle governance, defining the outcomes, processes and tolerances that oversee remediation activities from discovery through closure, extending consequence management into a durable, auditable governance model.
- Lead permanent attack-surface reduction, including curated and assured open source, hardened base images and maintained upstream dependencies, decommissioning, and secure-by-default guardrails, in partnership with platform, architecture and engineering leadership.
- Partner with Red Team, Threat Hunt, Threat Intelligence, penetration testing and bug bounty functions to continuously validate that controls hold against AI-enabled adversaries.
- Drive the shift-left agenda so that secure, pre-approved, evidence-producing build paths are the fastest and simplest way to deliver.
Reporting, Governance & Regulatory Engagement
- Own Exposure Governance & Reporting as the function's metrics engine and system of record, and stand up “Reporting-as-a-Service”: a standardized, published, self-service reporting model with defined intake, SLAs and quality control to ensure consistency, accuracy and timeliness of internal and external RFIs.
- Serve as the single intake and egress channel for Lines of Defense, audit and regulatory response and evidence, ensuring findings are reconciled across sources before external distribution.
- Own the end-to-end exception and waiver management process, establishing and maintaining a defined RACI, transparent policies and standard operating procedures, documented approval criteria, time-bound expiries and visible aging to ensure consistent, auditable decisions aligned with the firm’s risk tolerance.
- undefined
- Deliver clear, concise, executive-ready briefings on exposure posture, remediation velocity, data-quality considerations and regulatory commitments to the Deputy CISO and senior leadership.
Team Leadership & Build-Out
- Build and lead the permanent Threat & Vulnerability Operations team, standing up a resourced, product-led function including dedicated product management, compliance and reporting, and data analytics capacity.
- Own vendor and platform roadmap strategy across discovery, code analysis, data and remediation orchestration capabilities, translating vendor direction and industry and peer practice into a coherent automation, remediation and telemetry strategy, including deliberate buy-versus-build decisions against stated control outcomes.
- Act as a multiplier across engineering and platform teams, fostering a culture of accountability, evidence-based reporting and continuous modernization.
Executive & Stakeholder Engagement
- Serve as a trusted advisor to the Deputy CISO and the Managing Director, Cyber Product, Platforms & Engineering, on exposure posture, program status and regulatory asks.
- Establish clear, named accountability across contributing teams and partner effectively across a federated delivery model where remediation is executed by engineering, infrastructure and application owners.
- Represent Threat & Vulnerability Operations in cross-functional forums, including risk governance, audit and lines-of-defense committees, and coordinate closely with frontier-AI scanning and security platform workstreams.
- Support regulatory, audit and client discussions with credible, well-reconciled, defensible data and narrative.
Qualifications
Education
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field.
- Advanced degree preferred.
- Relevant certifications (CISSP, CISM, cloud security, or related) desired.
Experience
- 10+ years of progressive experience in cybersecurity, with significant depth in threat and vulnerability management, security operations, or cyber risk leadership roles, including in large, regulated environments.
- Demonstrated success leading digital transformation or large-scale operational modernization, building consolidated, automated, data-driven platforms and operating models while sustaining day-to-day delivery.
- Proven leadership designing and scaling enterprise vulnerability and exposure management programs and consolidating disparate signal sources into a single reconciled exposure picture.
- Hands-on experience with vulnerability scoring and risk-prioritization models (e.g., context-driven and threat-informed scoring, exploit-likelihood inputs, business-criticality and exposure weighting) and evolving KRIs from control-presence to outcome-based measures.
- Experience operating in a federated accountability model, owning risk and measurement centrally while remediation is executed by engineering, infrastructure and application teams.
- Strong background in regulatory and audit engagement and executive-level risk communication.
- Experience leading global, multidisciplinary security operations or engineering teams, including building out product management, compliance and reporting, and data analytics functions.
Skills & Characteristics
- Deep technical credibility in threat and vulnerability operations combined with executive-ready communication skills.
- Strong bias toward automation, scale and measurable outcomes, including remediation velocity, SLA compliance, backlog age and verified closure.
- Product-minded and data-driven, able to define outcomes, sequence delivery and hold design decisions to a consistent set of principles.
- Ability to translate complex technical risk and data-quality issues into practical, business-aligned decisions.
- Change-agent mindset with a track record of modernizing security operations functions and sustaining momentum through multi-year transformation.
- Ownership mindset, able to operate as the single accountable owner for exposure data, reporting and regulatory response.
What We Offer
- Opportunity to define and scale a modernized, product-led threat and vulnerability operations platform at a global systemically important financial institution.
- A genuine transformation mandate with executive sponsorship, spanning signal consolidation, scoring methodology, automation and enterprise reporting strategy.
- High-impact leadership role at the intersection of frontier-AI risk, regulatory engagement and security operations modernization.
- Competitive compensation and comprehensive benefits.
- Collaborative culture focused on engineering excellence and trust.
Salary Range:
$120,000 - $217,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.