Head of Communications, Compliance and Reporting

State Street 路 Quincy, United States 路 Onsite 路 $120,000 - $217,500/year
Listed via Workday
Posted Oct 7, 2026 路 Apply by Dec 6
Recently checked

Last checked active on Oct 7, 2026.

Position Overview

Compensation: $120,000 - $217,500/year
Position: Mid
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: No
Deadline: Dec 6, 2026

Job Description

The Head of Communications, Compliance & Reporting (CCR) is a highly visible leadership role accountable for building the function that serves as the single front door for information requests, regulatory and audit response, senior leader directives, metrics and recurring reporting across Cyber Product, Platforms & Engineering. The function directly supports Vulnerability Operations, including frontier-AI model scanning, where the pace of discovery and the level of executive, audit and regulatory scrutiny demand disciplined, defensible reporting.

This leader designs and owns one signal stream for all inbound demand, including requests for information (RFIs), regulatory reporting and inquiries, internal audit and Lines of Defense (LOD) requests, bespoke Board and senior leader directives, and reporting-as-a-service content. Requests are ingested, prioritized, triaged and consolidated through a single intake; responses are reconciled, polished and tailored to the audience; and final outputs are distributed through controlled channels and retained in a searchable library of record.

The role is accountable for transparent prioritization; accurate, defensible and on-time responses; a modernized metrics framework, built with operations teams and application owners, that makes clear what is measured, why and how; reliable reporting-as-a-service content, cadence and access; and the responsible use of AI and automation to consolidate disparate datasets and eliminate manual effort. The Head of CCR serves as a trusted partner and liaison to the Managing Director, Cyber Product, Platforms & Engineering and the Deputy CISO.

Key Responsibilities

Strategy, Operating Model & Intake Design

  • Design, build and own a single intake for all inbound demand, replacing fragmented and ad hoc channels with one front door and a clear RACI across contributing teams and subject matter experts.
  • Establish a transparent prioritization and triage model with defined criteria, service levels and escalation paths, so that risk, urgency and audience drive sequencing rather than volume or proximity.
  • Govern the end-to-end request lifecycle from ingestion through consolidation, approval, distribution and archival, combining overlapping requests into coordinated responses to reduce the burden on contributing teams.
  • Baseline request volume, cycle time, on-time delivery and rework before scaling or automating, and reassess the operating model as priorities, regulatory expectations and organizational structures evolve.

Regulatory, Audit & Compliance Response

  • Serve as the coordinated intake and egress channel for regulatory, internal audit and LOD inquiries, ensuring responses and evidence are reconciled, reviewed and approved before internal and/or external distribution.
  • Own commitment tracking for regulatory and audit deliverables, including owners, due dates and dependencies, with proactive escalation of delivery risk.
  • Maintain an auditable record of what was requested, what was provided, by whom and when, ensuring consistency across repeated or related inquiries.
  • Partner with Risk, Compliance, Legal and Internal Audit to align response standards and evidence expectations with firm policy, and prepare leaders for regulatory, audit and client engagements.

Metrics, Reporting-as-a-Service & Automation

  • Partner with operations teams and application owners to modernize what the organization measures, moving toward outcome-based metrics that reflect real risk reduction, and clearly explain why each metric matters and how it is calculated, sourced and interpreted.
  • Partner with the Head of Threat & Vulnerability Operations to design and deliver the metrics and reporting narrative for Vulnerability Operations, including frontier-AI model scanning, translating emerging findings, program progress and data-quality considerations into consistent, defensible reporting.
  • Manage reporting as a product: own and scale Reporting-as-a-Service, a standardized, self-service model with defined content, format, cadence, quality control, stakeholder onboarding and access, whether built internally or delivered through third-party platforms.
  • Govern metric definitions, methodologies, templates and style guidance, and curate a library of prior responses, approved narratives and evidence organized for rapid retrieval, reuse and version control.
  • Apply AI and emerging technologies to consolidate disparate datasets, accelerate drafting and reconciliation, and automate repetitive manual processes, with appropriate human review and in partnership with data, engineering and platform teams.

Team Leadership & Build-Out

  • Build and lead a small, high-performing team spanning intake and coordination, metrics and reporting, and communications, with clear roles, standards and expectations.
  • Foster a culture of service, accountability and precision, developing team capability in structured writing, data storytelling and AI-enabled tooling so the function scales without single points of failure.

Executive & Stakeholder Engagement

  • Serve as a trusted partner and liaison to the Deputy CISO and the Managing Director, Cyber Product, Platforms & Engineering, managing senior leader directives through to closure and keeping leadership informed of status, risks and emerging themes.
  • Influence without authority across a federated organization, quickly building trusted, durable relationships with stakeholders who hold divergent priorities and definitions of success, and aligning them on shared definitions and outcomes.
  • Translate complex technical topics into clear, bottom-line-up-front briefings, Board and committee materials and regulatory narratives, tailoring depth and breadth to each audience and presenting to executives, the Board, regulators and auditors as required.

Qualifications

Education

  • Bachelor's degree in Communications, Business, Information Systems, Computer Science, or related field.
  • Advanced degree preferred.
  • Relevant certifications (CISA, CRISC, CISM, PMP, product management, or related) desired.

Experience

  • 8+ years of progressive experience in cybersecurity, technology risk, compliance or related functions in large, regulated environments, with significant depth in reporting, metrics, regulatory or audit response, or executive communications.
  • Product management experience, or experience owning reporting products or platforms, organic or third-party, subject to recurring audits, reviews, assessments and regulatory scrutiny in a complex, high-stakes operational environment.
  • Demonstrated success designing intake, workflow and prioritization processes that bring structure to high-volume, cross-functional demand.
  • Proven experience managing regulatory, audit and LOD engagements, including evidence coordination, commitment tracking and response quality control.
  • Track record building metrics frameworks and standardized reporting for executive, Board and regulatory audiences, ideally in vulnerability management or security operations.
  • Hands-on experience applying AI, automation and data tools to consolidate disparate datasets and streamline reporting.
  • Experience leading teams and influencing without authority, driving delivery through contributors outside the direct reporting line.

Skills & Characteristics

  • Exceptional written and oral communication, with the ability to concisely summarize technical topics and tailor depth and breadth to diverse stakeholder needs.
  • Relationship builder who earns trust quickly across senior, technical and control-function stakeholders, including those with competing priorities.
  • Intellectual curiosity and a drive to understand the substance behind the data before publishing answers.
  • Strength in process design and workflow management, with a bias toward simplicity, standardization and measurable outcomes.
  • Technical depth and comfort with AI and emerging technology, able to spot automation opportunities and apply them responsibly.
  • Comfort operating in ambiguity with frequent directional changes, able to adapt as priorities shift while maintaining quality and composure.
  • High attention to detail, sound judgment and discretion with sensitive information.

What We Offer

  • Opportunity to design and build a new, highly visible function at a global systemically important financial institution.
  • Direct partnership with senior cybersecurity leadership, including the Deputy CISO and the Managing Director, Cyber Product, Platforms & Engineering.
  • High-impact role at the intersection of regulatory engagement, frontier-AI risk, metrics modernization and AI-enabled reporting.
  • Competitive compensation and comprehensive benefits.
  • Collaborative culture focused on excellence, integrity and trust.

Information Classification: Limited Access





Salary Range:

$120,000 - $217,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street鈥檚 comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.


About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.


We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you鈥檒l benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.


As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.


Discover more information on jobs at StateStreet.com/careers


Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Compensation

$120,000 - $217,500/year

Practice Area

Position

Mid

Industry

Legal

Application Deadline

December 6, 2026

Employment Type

Full time

Members-only application to State Street

Unlock this application

See the complete description, requirements, and every detail of this role, then apply with unlimited human CV reviews from a real specialist.

✓ Apply to this job and future roles across 91 countries
✓ Get unlimited CV / resume reviews from real human experts
✓ Get added to a private, members-only group for legal professionals
✓ Carry verified member status across LegalAlphabet
✓ Return to this job immediately after checkout
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.