Head of Communications, Compliance and Reporting
statestreet · Quincy, Massachusetts · United States · On-site
Pay: USD 120,000 – 217,500 a year
Posted Oct 7, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
The Head of Communications, Compliance & Reporting (CCR) is a highly visible leadership role accountable for building the function that serves as the single front door for information requests, regulatory and audit response, senior leader directives, metrics and recurring reporting across Cyber Product, Platforms & Engineering. The function directly supports Vulnerability Operations, including frontier-AI model scanning, where the pace of discovery and the level of executive, audit and regulatory scrutiny demand disciplined, defensible reporting.
This leader designs and owns one signal stream for all inbound demand, including requests for information (RFIs), regulatory reporting and inquiries, internal audit and Lines of Defense (LOD) requests, bespoke Board and senior leader directives, and reporting-as-a-service content. Requests are ingested, prioritized, triaged and consolidated through a single intake; responses are reconciled, polished and tailored to the audience; and final outputs are distributed through controlled channels and retained in a searchable library of record.
The role is accountable for transparent prioritization; accurate, defensible and on-time responses; a modernized metrics framework, built with operations teams and application owners, that makes clear what is measured, why and how; reliable reporting-as-a-service content, cadence and access; and the responsible use of AI and automation to consolidate disparate datasets and eliminate manual effort. The Head of CCR serves as a trusted partner and liaison to the Managing Director, Cyber Product, Platforms & Engineering and the Deputy CISO.
Key Responsibilities
Strategy, Operating Model & Intake Design
Design, build and own a single intake for all inbound demand, replacing fragmented and ad hoc channels with one front door and a clear RACI across contributing teams and subject matter experts.
Establish a transparent prioritization and triage model with defined criteria, service levels and escalation paths, so that risk, urgency and audience drive sequencing rather than volume or proximity.
Govern the end-to-end request lifecycle from ingestion through consolidation, approval, distribution and archival, combining overlapping requests into coordinated responses to reduce the burden on contributing teams.
Baseline request volume, cycle time, on-time delivery and rework before scaling or automating, and reassess the operating model as priorities, regulatory expectations and organizational structures evolve.
Regulatory, Audit & Compliance Response
Serve as the coordinated intake and egress channel for regulatory, internal audit and LOD inquiries, ensuring responses and evidence are reconciled, reviewed and approved before internal and/or external distribution.
Own commitment tracking for regulatory and audit deliverables, including owners, due dates and dependencies, with proactive escalation of delivery risk.
Maintain an auditable record of what was requested, what…