ForgeApply · Job listing
Data Protection, Managing Director
State Street
Tailor your resume for this State Street job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for State Street's site. Free trial, no card required.
About this role
Who we are looking for
We are looking for a Data Protection Managing Director reporting directly to the SVP of Data and AI Security. The Managing Director, Data Protection is a senior leadership role responsible for defining, governing, and scaling the firm's enterprise-wide data protection strategy. This leader will establish a modern, risk-based data security program that enables the organization's digital, cloud, AI, and data transformation objectives while protecting the firm's most critical information assets. The role requires a visionary security leader who can balance business enablement with strong security outcomes. The successful candidate will drive the evolution from traditional data protection approaches toward a modern, intelligence-driven program focused on data discovery, classification, retention, access governance, AI security, and automated protection controls .
The Managing Director will serve as the firm's foremost authority on data security and protection, partnering across Security, Engineering, Data, Privacy, Legal, Risk, Compliance, Infrastructure, and Business teams to ensure security is embedded into platforms, pipelines, governance frameworks, and delivery processes.
Why this role is important to us
This role sits in the AI & Data Protection team which is part of the Global Cybersecurity group at State Street. Global Cybersecurity is vital to the bank because it protects client trust, safeguards critical assets, enables business growth, and ensures the bank can operate safely in an increasingly complex threat and regulatory environment.
What you will be responsible for
• Define and execute the firm's multi-year Enterprise Data Protection Strategy , ensuring alignment with business priorities, regulatory obligations, cloud transformation initiatives, and AI adoption.
• Establish a comprehensive framework for protecting sensitive information throughout its lifecycle, including:
• Data discovery
• Classification
• Access governance
• Retention and disposal
• Encryption and key management
• Monitoring and protection controls
• Drive a modern security model focused on protecting data regardless of location, platform, user, or technology stack.
• Develop executive-level metrics and reporting that quantify data risk, control effectiveness, and remediation progress.
• Lead enterprise initiatives to know, understand, and reduce data risk at scale .
• Establish programs to identify and continuously inventory:
• Sensitive customer and firm data
• Regulated and restricted information
• Secrets and credentials
• Legacy data stores
• High-risk repositories
• Shadow data environments
• Create risk-based approaches to classify, prioritize, and remediate high-risk data concentrations across on-premises, cloud, SaaS, and emerging AI environments.
• Develop actionable intelligence that enables business leaders and technology teams to understand where sensitive data resides and how it is exposed.
• AI Data security & Protection - Lead the firm's strategy for protecting data from emerging AI-related threats and misuse.
• Establish controls and protections against:
• Prompt injection attacks
• Model misuse
• Data leakage through AI systems
• Retrieval-augmented generation (RAG) data exposure
• Adversarial AI attacks
• Model manipulation
• AI-enabled social engineering
• Partner closely with AI, Engineering, and Security Architecture teams to ensure AI capabilities are deployed using:
• Secure-by-default configurations
• Approved usage patterns
• Security guardrails
• Automated controls
• Enterprise-approved AI platforms
• Develop data protection requirements for AI models, agents, copilots, and emerging autonomous systems.
• Establish rigorous enterprise-wide data lifecycle management and retention programs designed to minimize unnecessary data exposure.
• Drive initiatives to:
• Eliminate obsolete and redundant data
• Reduce data longevity where business value no longer exists
• Improve defensibility and regulatory compliance
• Reduce attack surface through data minimization
• Partner with Legal, Compliance, Privacy, and business stakeholders to implement practical retention schedules and automated disposal capabilities.
• Ensure retention policies are enforced through technology controls rather than manual processes whenever possible.
• Data Access Governance - Lead enterprise efforts to analyze, govern, and continuously monitor access to sensitive information.
• Develop and implement:
• Data-centric access control models
• Risk-based authorization frameworks
• Privileged access controls
• Continuous entitlement reviews
• Excessive permissions identification
• Access anomaly detection
• Partner with Identity and Access Management teams to strengthen least-privilege principles across business and technology environments .
• Ensure access decisions are informed by data sensitivity, business context, user risk, and regulatory requirements.
• Establish a comprehensive view of the firm's data protection control environment.
• Conduct enterprise-wide assessments to:
• Map existing controls
• Identify security gaps
• Measure control effectiveness
• Assess residual risk
• Prioritize remediation activities
• Develop risk-based roadmaps that focus resources on the most significant data protection exposures .
• Drive accountability across technology and business stakeholders to ensure timely remediation of material risks.
• Partner closely with the Data organization to ensure security is embedded throughout the data ecosystem.
• Influence the design of:
• Data platforms
• Data pipelines
• Analytics environments
• Governance frameworks
• AI and ML platforms
• Data products
• Promote security-by-design principles that enable innovation while reducing operational
Salary insight
The midpoint of this range ($226k) is about 41% above the median disclosed salary for Boston roles listed on ForgeApply ($160k across 1,625 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this State Street role before you apply.
Tailor my resume for this jobSimilar jobs
- Data Protection, Manager — Avanade · Chicago, Accenture Tower, Corp | OR - Portland | PA - Philadelphia
- Data Protection Consultant — Avanade · Chicago, Accenture Tower, Corp | MO - St. Louis | OR - Portland
- Privacy Manager & Data Protection Officer — G2 · Chicago, IL
- Head of Privacy — Abridge · SF Office
- Regulatory Compliance & Data Protection Specialist — Playson · European Union
- Manager, Privacy Compliance — The Coca-Cola Company · Remote
- Senior Director, Chief Privacy Lead — ZOLL Medical Corporation · Chelmsford, MA | US PA Pittsburgh Gamma
- Senior Manager, Client Data Permissions & Privacy Governance — Merceradvisors · Remote
More like this: More jobs at State Street · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)