Morgan Stanley Investment Management (MSIM) is seeking an experienced Vice President / Executive Director to lead its Third-Party Risk and Resilience function. This individual will oversee MSIM's compliance with Firm third-party risk management policies, procedures, and standards, as well as resilience obligations, while driving strong partnership and collaboration across business, technology, operations, and Firmwide stakeholder groups.
The Third-Party Risk & Resilience Lead will direct third-party risk and resilience oversight for MSIM, with particular focus on third-party services which support critical business processes, outsourcing arrangements, third-party incidents, regulatory-driven initiatives, and remediation of control gaps. The role is accountable for ensuring appropriate governance, documentation, testing, reporting, escalation, evidence, and issue closure across all third-party risk and resilience obligations.
The successful candidate will lead a team responsible for executing third-party risk program requirements and resilience obligations, delivering first-line governance across the full third-party lifecycle including risk assessment, ongoing monitoring, issue management, resilience planning, testing, governance, and reporting. Candidates should bring at least 10 years of relevant experience, with a demonstrated ability to lead a function, manage competing priorities across a team, influence within a matrixed organization, provide credible challenge, and drive execution through a practical, collaborative approach.
Key Responsibilities
Leadership & Operating Model
- Lead the MSIM Third-Party Risk and Resilience function, including management of a team responsible for governance, reporting, issue management, Contingency and Exit Plan (CP/EP) execution, testing coordination, and stakeholder engagement.
- Set priorities, allocate work, and oversee deliverables to ensure the team meets Firm requirements and MSIM business needs on time and to a consistent standard.
- Support enhancement of the MSIM third-party risk and resilience operating model, including roles and responsibilities, escalation paths, reporting standards, and evidence expectations.
- Serve as MSIM's lead point of contact for third-party risk and resilience matters, partnering closely with Service Owners, Third-Party Program Management, Operational Risk, Business Unit Risk Officers (BUROs), Legal, Compliance, and other Firm stakeholders.
Third-Party Lifecycle Governance
- Oversee governance across the full third-party risk lifecycle including service selection, due diligence, inherent risk assessment, criticality determination, ongoing monitoring, issue remediation, risk acceptance, termination, and offboarding.
- Partner with Service Owners to ensure execution of required vendor management activities, including service validations, meeting minutes, training, and ongoing monitoring.
- Review and approve new or modified service records and criticality ratings where required; support accurate maintenance of firm tooling including iShield, Third-Party Application Inventory (TAI), Service Provider Risk Level (SPRL), and related resilience data sources.
Resilience & Contingency Planning
- Own the creation, maintenance, and ongoing governance of Resilience Plans for critical or regulatory in-scope third-party services which includes Contingency Plans (CPs) for temporary provider disruptions and Exit Plans (EPs) for permanent provider transitions.
- Manage the end-to-end CP/EP lifecycle, including refreshes, approvals, evidence collection, and testing coordination, while evaluating plan quality and associated risk.
- Lead operational mapping and dependency identification across critical third-party services, documenting dependencies among business processes, applications, vendors, data flows, recovery requirements, and exit strategies.
- Lead incident preparedness for critical third-party services, including documented response actions for vendor failure scenarios and Incident Management Playbooks where no viable workaround exists.
Reporting & Escalation
- Develop senior management reporting, including metrics, dashboards, Key Risk Indicators (KRIs), issue summaries, CP/EP status, and testing outcomes; present material issues, plan gaps, and remediation status to governance committees as required.
- Track, escalate, and drive remediation of third-party issues, findings, overdue actions, and control or resilience gaps including failed or partially effective tests through closure.
Qualifications
- Minimum of 10 years of relevant experience in third-party risk management, operational resilience, operational risk, business controls, vendor management, outsourcing governance, business continuity, or a related discipline. Financial services experience required; asset management experience preferred.
- Experience leading a function, team, or cross-functional program, including setting priorities, managing deliverables, and driving accountability.
- Strong understanding of third-party risk lifecycle management, operational resilience, criticality assessment, issue management, risk acceptance, operational mapping, incident preparedness, and testing governance.
- Ability to interpret policies, procedures, standards, and expectations, and translate them into practical business requirements.
- Strong relationship management skills, with the ability to partner across business, risk, control, technology, operations, and Firmwide teams; influence without direct authority; and provide credible challenge.
- Strong analytical and written communication skills; experience supporting audit, compliance review, or management review activity preferred.
- Experience with vendor risk management tools and resilience data sources preferred, including iShield, TAI, and SPRL.