Morgan Stanley

Internal Audit Executive Director - Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience

Morgan Stanley • $165K — $275K *
Finance & Insurance
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Advanced understanding of cybersecurity, information security, and cyber resilience risks, particularly in banking regulations.
  • Experience assessing emerging technology risks, including AI, cryptocurrency, and quantum computing.
  • Strong knowledge of cybersecurity frameworks like NIST CSF and ISO 27001, with auditing experience in cloud security and network architecture.
  • Expertise in audit principles, methodologies, and tools, including risk assessments and continuous monitoring.
  • Ability to analyze data and prioritize audit activities based on risk criticality.
  • Strong communication skills to articulate risks to senior stakeholders and regulators.
  • Proven leadership skills in mentoring and developing audit teams.

Responsibilities

  • Lead coverage of emerging risks related to AI and frontier models, assessing lifecycle controls and data protection.
  • Provide assurance on risks from cryptocurrency and digital assets, focusing on custody and security threats.
  • Evaluate readiness for quantum computing and ensure risks are included in the audit plan.
  • Monitor the threat landscape and incorporate emerging threats into audit strategies.
  • Deliver independent assurance on the effectiveness of controls protecting technology environments and customer data.
  • Set a multi-year, risk-based audit strategy for cybersecurity across the Firm.
  • Direct execution of the audit plan in core cyber and information security domains, including incident response and vendor security.

Benefits

  • Comprehensive health and wellness programs.
  • Retirement savings plans with company matching.
  • Professional development and training opportunities.
  • Flexible work arrangements and work-life balance initiatives.
  • Access to employee resource groups and diversity programs.
Full Job Description
The cyber risk landscape is changing rapidly, and the Firm requires audit leadership equipped to meet the moment. We are seeking an Executive Director to lead internal audit technology coverage across the global Firm and its banking entities, including Morgan Stanley Bank, N.A. (MSBNA) and Morgan Stanley Private Bank, N.A. (MSPBNA). This role demands a forward-looking leader who can address both today's threats and the emerging risks now reshaping cybersecurity, information security, and cyber resilience - with deep cyber risk expertise and a strong understanding of how artificial intelligence, agentic and frontier AI models, cloud transformation, and digital assets are actively changing the risk landscape and regulatory expectations. The successful candidate will translate these developments into practical, risk-based audit strategies, deliver insightful challenge to management, and evolve the Firm's assurance approach to address current and emerging threats.

The Internal Audit Division (IAD) drives attention and resources to vulnerabilities by providing an independent and well-informed view and impactful messages about the most important risks facing our Firm. This is accomplished by performing a range of assurance activities to independently assess the quality and effectiveness of Morgan Stanley's system of internal control, including risk management and governance systems and processes. IAD serves as an objective and independent function within the Firm's risk management framework to foster continual improvement of risk management processes. This is an Executive Director (P6) level position within the Technical Specialist function, which is responsible for providing extensive subject matter expertise and reinforcing the ability of business and technology audit teams to appropriately assess risk and determine and execute coverage.

What you'll do in the role
  • Prioritize and lead coverage of emerging risks related to artificial intelligence and frontier models - including generative and agentic AI - assessing build time, run time, and life cycle controls, data protection, identity and entitlements for autonomous agents, and the expanded attack surface these capabilities create, as well as adversaries' growing use of AI to accelerate and scale attacks.
  • Provide coverage of the idiosyncratic risks arising from cryptocurrency and digital assets, including digital asset custody, private key generation and lifecycle management, and the security of both online (network-connected) and offline (air-gapped) custody infrastructure - highlighting the associated cyber threats such as private key compromise, transaction and address manipulation, smart contract exploitation, and the irreversible loss of assets.
  • Assess quantum computing and post-quantum cryptography readiness, and other frontier technology risks, ensuring these are reflected in the audit plan and in the Firm's forward-looking resilience posture.
  • Monitor the intensifying threat landscape - including advanced attack techniques and regulatory change - and continuously factor emerging threats into audit scoping and assurance coverage.
  • Provide independent assurance over the design and operating effectiveness of the controls that protect the Firm's and Banks' technology environment, customer data, and critical business services
  • Set and lead the multi-year, risk-based audit strategy for cybersecurity, information security, and cyber resilience across the Firm and its Banks, spanning the full technology stack (infrastructure, network, platform, application, and data layers) and each business unit to form an integrated, Firm-wide view of control effectiveness, and how cyber threats, information loss, and a cyber attach could affect business lines, critical services, and legal entities across the Firm.
  • Direct execution of the audit plan across the core cyber and information security domains - identity and access management, endpoint security, network security, data protection, threat detection and response, and vulnerability management.
  • Lead assurance activities assessing cyber resilience capabilities, including incident response, disaster recovery, business continuity, and third-party/vendor security.
  • Evaluate compliance with regulatory expectations (e.g., FFIEC, OCC, FDIC, NYDFS, GLBA, RGF, DORA) and industry frameworks (CRI Profile, NIST CSF, ISO 27001).
  • Oversee root cause analysis on control failures and audit findings, and track remediation to closure.
  • Comprehensively articulate actionable insights regarding the criticality and impact of cyber risk, and how well it is managed, to senior management and regulators. Prepare materials for the Chief Audit Executive's updates to the Audit Committee and the Board,
  • Coordinate with second-line risk and compliance functions and with external auditors and regulators, and collaborate with global peers to identify risk themes and implications across business segments and legal entities.
  • Mentor and develop audit staff and manage a global team; help inform and address talent needs and identify stretch and development opportunities for team members.


What you'll bring to the role
  • Advanced understanding of cybersecurity, information security, and cyber resilience risks and the relevant regulations, including banking regulatory requirements.
  • Experience assessing emerging technology risks and their control implications - including AI and agentic AI, frontier models, cryptocurrency and digital asset custody, and quantum/post-quantum cryptography - and the ability to translate a rapidly changing threat landscape into practical audit coverage.
  • Strong knowledge of cybersecurity frameworks (NIST CSF, ISO 27001, CRI Profile) and experience auditing identity and access management, cloud security, and network architecture.
  • Expertise in audit principles, methodology, tools, and processes (e.g., risk assessments, planning, testing, reporting, and continuous monitoring).
  • Ability to analyze data and prioritize coverage and assurance activities based on the criticality of risk.
  • Ability to articulate risk and impact clearly and succinctly to different audiences, including senior stakeholders, the Board, and regulators.
  • Ability to inspire and support others to do their best work through active coaching, feedback, and development opportunities, and by ensuring trust and inclusion among team members.
  • Experience in overseeing resource utilization and monitoring progress against deliverables.
  • A bachelor's degree in Information Security, Computer Science, or a related field.
  • At least 12-15 years' relevant experience in IT/cyber audit, information security, or risk management - ideally in banking or financial services - would generally be expected to fulfill the skills required for this role.
  • Relevant certifications (e.g., CISA, CISSP, CISM, or equivalent) preferred.


Preferred qualifications
  • Experience with incident response or red team/penetration testing programs.
  • Familiarity with the MITRE ATT&CK framework.
  • Prior experience at a large financial institution or a Big 4 consulting firm.


Expected base pay rates for the role will be between $165,000 and $275,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

About Morgan Stanley

Morgan Stanley Investment Management are active managers of capital, working to outperform the market and deliver results for their clients. Morgan Stanley Investment Management's long-tenured professionals apply their experience and expertise across public and private markets, in single-sector, multi-asset and custom solutions.

Morgan Stanley Careers

Joining Morgan Stanley today means becoming part of a global team dedicated to strengthening communities, pioneering innovation, and fostering diversity. As a leading global financial services firm, Morgan Stanley offers unparalleled job opportunities, career growth, and a culture of leadership that together create an exceptional employment experience. Work You’ll Do At Morgan Stanley, you will collaborate with knowledgeable professionals to drive innovation and deliver solutions in financial services. Our team is composed of diverse, talented individuals who bring their unique skills and perspectives to work every day, setting the standard for leadership in the global market. Morgan Stanley is not just a company; it's a place where ambitious, creative, and skilled individuals can build a rewarding career. Here, you can experience the benefits of a vibrant culture dedicated to professional growth and diversity training. Internship Programs Kickstart your career with Morgan Stanley’s internship programs. These positions offer invaluable industry insights and professional experience to students and recent graduates. Interns at Morgan Stanley gain hands-on experience, working alongside seasoned experts in a dynamic, supportive environment. Innovation and Professional Growth We believe in the power of innovation to solve complex problems and encourage our team to think differently and act boldly. Morgan Stanley supports your career development through comprehensive training, development programs, and leadership workshops, ensuring that every employee has the tools they need to succeed. Join Our Team Explore the various job opportunities at Morgan Stanley, from entry-level positions to executive roles. We are hiring individuals who are passionate about finance and eager to contribute to a team that values integrity, excellence, and a forward-thinking mindset. Enhance your skills through our networking events, mentorship opportunities, and ongoing professional development. Stay Connected Keep up to date with the latest from Morgan Stanley Careers by subscribing to our job alert emails. Tailor your preferences to receive updates about new postings, career tips, and exclusive insights from our team leaders. Apply Now Ready to take the next step in your career? Search open positions that match your skills and interests on the Morgan Stanley Jobs portal. Prepare your resume, refine your interview techniques, and join a company that values innovation and leadership. At Morgan Stanley, we’re not just building careers—we’re developing leaders. Discover how far your talents can take you by joining our team today.
Learn more about Morgan Stanley
Size
77,000 employees
Market Cap
$144.1 billion
Industry
Net Income
$10.9 billion
Founded
1935
5 Year Trend
+10%
Revenue
$52 billion
NASDAQ

Similar Jobs

More Jobs at Morgan Stanley

More Finance & Insurance Jobs

Find similar Internal Audit Executive Director - Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience jobs: