Morgan Stanley is seeking a Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead in the CTIS team within Non-Financial Risk.
The successful candidate will be responsible for leading a team focused on independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks, with a focus on areas including IT resilience, architecture and design, asset management, vulnerability and patch management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk and control lens.
What you'll do in the role:
- Provide independent oversight and challenge of the Firm's cybersecurity and technology organizations risk management activities.
- Manage the team in assessing the effectiveness of risk and control frameworks supporting new technology infrastructure, applications, cyber defenses, and information security programs.
- Lead the team in review and challenge of risk assessments, control evaluations, issue remediation plans, and risk acceptance decisions.
- Build and maintain strong positive relationships and partner with Technology, Non-Financial Risk, Legal, Audit, and business stakeholders to identify and address emerging risks.
- Evaluate new technology initiatives and strategic transformation programs from a risk perspective.
- Manage the team in monitoring key risk indicators (KRIs), metrics, and trends to identify areas requiring enhanced oversight or escalation.
- Support regulatory examinations, internal audits, and governance committee reporting related to technology and cyber risk.
- Drive consistency in risk management practices, ensuring policy requirements, governance standards, and other risk guidance are appropriately addressed.
- Manage the team in preparing executive-level risk reporting and deliver presentations for senior management and at risk governance forums.
- Contribute to the development and enhancement of Enterprise Risk Management and NFR programs.
- Provide thought leadership on emerging technology, cyber threats, and regulatory developments.
What you'll bring to the role:
- College degree (STEM or Information Security, preferable but not essential)
- 10+ years of technology and or security risk related work experience, preferably in the financial services industry
- Experience in Technology (IT) Risk Management and/or Technology (IT) Audit including Information Security and or Cyber Security
- Strong leadership, people management, stakeholder management and influencing skills
- Strong interpersonal skills to work in a team-oriented environment
- Excellent communication skills, both verbal and written; ability to produce concise and effective presentations tailored to technical and non-technical audiences
- Strong project management and organization skills
- Ability to multitask and prioritize
- Ability to work under pressure and to tight deadlines
- Flexible and self-motivator
- Strong analytical and problem-solving skills
- Proficiency in MS Office and related applications (e.g. Word, Excel, Powerpoint)
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Expected base pay rates for the role will be between $120000 and $210000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.