> Markdown version of [/jobs/ext/184619-vp-cyber-technology-and-information-risk-manager](https://www.wearedevelopers.com/jobs/ext/184619-vp-cyber-technology-and-information-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # VP - Cyber, Technology, and Information Risk Manager - **Company:** Morgan Stanley - **Location:** Alpharetta, GA, United States - **Experience:** Expert - **Salary:** $95,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Technology, CIS Benchmarks - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=24bb812e6b114381 ## About the Role Do you have experience in Stakeholder relationship building?, > Degree required with a focus in Risk Management, Compliance, Computer Science, Information Technology or Cybersecurity preferred > 8+ years of relevant experience would be expected to find the skills required for this role, preferably risk management or compliance experience in the financial services industry, a regulator, a self-regulatory organization, or other heavily regulated industries > Familiarity with CTIS risk management best practices (e.g., CRI, NIST CSF, ISO 27001, CIS Controls) required > Strong understanding of financial industry CTIS risks, policies and controls, and the ability to critique relevant language with accuracy and confidence > Self-motivated with strong analytical, organizational, and problem-solving skills; ability to work independently, demonstrate resourcefulness, develop well-structured proposals, and drive complex tasks from start to finish with high accountability > Ability to work effectively in a cross-functional, global team > Excellent communication skills, both verbal and written; ability to tailor communication to technical vs non-technical, senior vs junior audiences ## Description Morgan Stanley is seeking a Risk professional to join the Cyber, Technology and Information Security (CTIS) Standards team within the Non-Financial Risk Organization in Alpharetta or Baltimore at the Vice-President level. The CTIS Standards team enables the firm to manage and comply with CTIS Rules and Risks by setting standards for controls and risk measurement. It defines the overall framework and standards for effective management of CTIS risks, including monitoring of framework activities. The role includes the following primary responsibilities: > Provide independent 2LoD review and challenge of 1LoD technology policy and control standards, ensuring that control objectives and control requirements are complete, risk-aligned, and fit for purpose across defined CTIS domains. > Work closely with 1LoD standard owners to ensure that 1LoD standards sufficiently address applicable rules, regulatory expectations, and key cyber/technology/information security risks. The portfolio comprises of several dozen domain-aligned standard documents and a few hundred control requirements in total. > Actively participate at senior governance forums to provide input (support, challenge, dissent etc.) and contribute to firm-wide decision-making. > Cross-Functional Collaboration: Work closely with other departments to ensure the alignment of risk management activities with broader organizational risk management frameworks. Build and maintain strong positive relationships with the broader risk community. Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing and advancing individuals based on their skills and talents. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)