State Street

Head of Communications, Compliance and Reporting

State Street  •  $120k - $218k/yr  •  Quincy, MA (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

The Head of Communications, Compliance & Reporting (CCR) is a highly visible leadership role accountable for building the function that serves as the single front door for information requests, regulatory and audit response, senior leader directives, metrics and recurring reporting across Cyber Product, Platforms & Engineering. The function directly supports Vulnerability Operations, including frontier-AI model scanning, where the pace of discovery and the level of executive, audit and regulatory scrutiny demand disciplined, defensible reporting.

This leader designs and owns one signal stream for all inbound demand, including requests for information (RFIs), regulatory reporting and inquiries, internal audit and Lines of Defense (LOD) requests, bespoke Board and senior leader directives, and reporting-as-a-service content. Requests are ingested, prioritized, triaged and consolidated through a single intake; responses are reconciled, polished and tailored to the audience; and final outputs are distributed through controlled channels and retained in a searchable library of record.

The role is accountable for transparent prioritization; accurate, defensible and on-time responses; a modernized metrics framework, built with operations teams and application owners, that makes clear what is measured, why and how; reliable reporting-as-a-service content, cadence and access; and the responsible use of AI and automation to consolidate disparate datasets and eliminate manual effort. The Head of CCR serves as a trusted partner and liaison to the Managing Director, Cyber Product, Platforms & Engineering and the Deputy CISO.

Key Responsibilities

Strategy, Operating Model & Intake Design

  • Design, build and own a single intake for all inbound demand, replacing fragmented and ad hoc channels with one front door and a clear RACI across contributing teams and subject matter experts.
  • Establish a transparent prioritization and triage model with defined criteria, service levels and escalation paths, so that risk, urgency and audience drive sequencing rather than volume or proximity.
  • Govern the end-to-end request lifecycle from ingestion through consolidation, approval, distribution and archival, combining overlapping requests into coordinated responses to reduce the burden on contributing teams.
  • Baseline request volume, cycle time, on-time delivery and rework before scaling or automating, and reassess the operating model as priorities, regulatory expectations and organizational structures evolve.

Regulatory, Audit & Compliance Response

  • Serve as the coordinated intake and egress channel for regulatory, internal audit and LOD inquiries, ensuring responses and evidence are reconciled, reviewed and approved before internal and/or external distribution.
  • Own commitment tracking for regulatory and audit deliverables, including owners, due dates and dependencies, with proactive escalation of delivery risk.
  • Maintain an auditable record of what was requested, what was provided, by whom and when, ensuring consistency across repeated or related inquiries.
  • Partner with Risk, Compliance, Legal and Internal Audit to align response standards and evidence expectations with firm policy, and prepare leaders for regulatory, audit and client engagements.

Metrics, Reporting-as-a-Service & Automation

  • Partner with operations teams and application owners to modernize what the organization measures, moving toward outcome-based metrics that reflect real risk reduction, and clearly explain why each metric matters and how it is calculated, sourced and interpreted.
  • Partner with the Head of Threat & Vulnerability Operations to design and deliver the metrics and reporting narrative for Vulnerability Operations, including frontier-AI model scanning, translating emerging findings, program progress and data-quality considerations into consistent, defensible reporting.
  • Manage reporting as a product: own and scale Reporting-as-a-Service, a standardized, self-service model with defined content, format, cadence, quality control, stakeholder onboarding and access, whether built internally or delivered through third-party platforms.
  • Govern metric definitions, methodologies, templates and style guidance, and curate a library of prior responses, approved narratives and evidence organized for rapid retrieval, reuse and version control.
  • Apply AI and emerging technologies to consolidate disparate datasets, accelerate drafting and reconciliation, and automate repetitive manual processes, with appropriate human review and in partnership with data, engineering and platform teams.

Team Leadership & Build-Out

  • Build and lead a small, high-performing team spanning intake and coordination, metrics and reporting, and communications, with clear roles, standards and expectations.
  • Foster a culture of service, accountability and precision, developing team capability in structured writing, data storytelling and AI-enabled tooling so the function scales without single points of failure.

Executive & Stakeholder Engagement

  • Serve as a trusted partner and liaison to the Deputy CISO and the Managing Director, Cyber Product, Platforms & Engineering, managing senior leader directives through to closure and keeping leadership informed of status, risks and emerging themes.
  • Influence without authority across a federated organization, quickly building trusted, durable relationships with stakeholders who hold divergent priorities and definitions of success, and aligning them on shared definitions and outcomes.
  • Translate complex technical topics into clear, bottom-line-up-front briefings, Board and committee materials and regulatory narratives, tailoring depth and breadth to each audience and presenting to executives, the Board, regulators and auditors as required.

Qualifications

Education

  • Bachelor's degree in Communications, Business, Information Systems, Computer Science, or related field.
  • Advanced degree preferred.
  • Relevant certifications (CISA, CRISC, CISM, PMP, product management, or related) desired.

Experience

  • 8+ years of progressive experience in cybersecurity, technology risk, compliance or related functions in large, regulated environments, with significant depth in reporting, metrics, regulatory or audit response, or executive communications.
  • Product management experience, or experience owning reporting products or platforms, organic or third-party, subject to recurring audits, reviews, assessments and regulatory scrutiny in a complex, high-stakes operational environment.
  • Demonstrated success designing intake, workflow and prioritization processes that bring structure to high-volume, cross-functional demand.
  • Proven experience managing regulatory, audit and LOD engagements, including evidence coordination, commitment tracking and response quality control.
  • Track record building metrics frameworks and standardized reporting for executive, Board and regulatory audiences, ideally in vulnerability management or security operations.
  • Hands-on experience applying AI, automation and data tools to consolidate disparate datasets and streamline reporting.
  • Experience leading teams and influencing without authority, driving delivery through contributors outside the direct reporting line.

Skills & Characteristics

  • Exceptional written and oral communication, with the ability to concisely summarize technical topics and tailor depth and breadth to diverse stakeholder needs.
  • Relationship builder who earns trust quickly across senior, technical and control-function stakeholders, including those with competing priorities.
  • Intellectual curiosity and a drive to understand the substance behind the data before publishing answers.
  • Strength in process design and workflow management, with a bias toward simplicity, standardization and measurable outcomes.
  • Technical depth and comfort with AI and emerging technology, able to spot automation opportunities and apply them responsibly.
  • Comfort operating in ambiguity with frequent directional changes, able to adapt as priorities shift while maintaining quality and composure.
  • High attention to detail, sound judgment and discretion with sensitive information.

What We Offer

  • Opportunity to design and build a new, highly visible function at a global systemically important financial institution.
  • Direct partnership with senior cybersecurity leadership, including the Deputy CISO and the Managing Director, Cyber Product, Platforms & Engineering.
  • High-impact role at the intersection of regulatory engagement, frontier-AI risk, metrics modernization and AI-enabled reporting.
  • Competitive compensation and comprehensive benefits.
  • Collaborative culture focused on excellence, integrity and trust.

Information Classification: Limited Access

Salary Range:

$120,000 - $217,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

State Street

About State Street

At State Street, we deliver leading investment platforms, data, expertise, and solutions that accelerate performance and better decision making.

With over 200 years of global financial leadership, we equip institutional investors through a comprehensive suite of capabilities:

Investment Services: Integrated front-to-back solutions across custody, accounting, and operations.

Investment Management: Index and active strategies from one of the world’s largest asset managers.

Markets: Multi-asset trading, FX solutions, and data-driven research to enhance portfolio value.

Who We Are

• 50,000+ employees worldwide

• Active in 100+ markets

• #1 in ETF servicing

What You’ll Find Here

• Executive perspectives and thought leadership

• Timely market commentary and macro insights

• Our views on investment operations, ETFs, private markets, and digital finance

• Stories reflecting our culture, values and commitment to diversity and inclusion

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Boston, Massachusetts
Year Founded
1792
Social Media