> Markdown version of [/jobs/ext/2705761-vice-president-cyber-technology-and-information-security-ctis-risk-oversight-lead](https://www.wearedevelopers.com/jobs/ext/2705761-vice-president-cyber-technology-and-information-security-ctis-risk-oversight-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead - **Company:** Morgan Stanley - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $210,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Identity and Access Management, Network Security, Microsoft Office, Microsoft PowerPoint, Cyber Threat Analysis, Cybercrime, Patch Management - **Published:** September 4, 2026 - **Apply:** https://www.themuse.com/jobs/morganstanley/vice-president-cyber-technology-and-information-security-ctis-risk-oversight-lead ## About the Role * College degree (STEM or Information Security, preferable but not essential) * 10+ years of technology and or security risk related work experience, preferably in the financial services industry * Experience in Technology (IT) Risk Management and/or Technology (IT) Audit including Information Security and or Cyber Security * Strong leadership, people management, stakeholder management and influencing skills * Strong interpersonal skills to work in a team-oriented environment * Excellent communication skills, both verbal and written; ability to produce concise and effective presentations tailored to technical and non-technical audiences * Strong project management and organization skills * Ability to multitask and prioritize * Ability to work under pressure and to tight deadlines * Flexible and self-motivator * Strong analytical and problem-solving skills * Proficiency in MS Office and related applications (e.g. Word, Excel, Powerpoint) ## Description Morgan Stanley is seeking a Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead in the CTIS team within Non-Financial Risk. The successful candidate will be responsible for leading a team focused on independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks, with a focus on areas including IT resilience, architecture and design, asset management, vulnerability and patch management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk and control lens. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. What you'll do in the role: * Provide independent oversight and challenge of the Firm's cybersecurity and technology organizations risk management activities. * Manage the team in assessing the effectiveness of risk and control frameworks supporting new technology infrastructure, applications, cyber defenses, and information security programs. * Lead the team in review and challenge of risk assessments, control evaluations, issue remediation plans, and risk acceptance decisions. * Build and maintain strong positive relationships and partner with Technology, Non-Financial Risk, Legal, Audit, and business stakeholders to identify and address emerging risks. * Evaluate new technology initiatives and strategic transformation programs from a risk perspective. * Manage the team in monitoring key risk indicators (KRIs), metrics, and trends to identify areas requiring enhanced oversight or escalation. * Support regulatory examinations, internal audits, and governance committee reporting related to technology and cyber risk. * Drive consistency in risk management practices, ensuring policy requirements, governance standards, and other risk guidance are appropriately addressed. * Manage the team in preparing executive-level risk reporting and deliver presentations for senior management and at risk governance forums. * Contribute to the development and enhancement of Enterprise Risk Management and NFR programs. * Provide thought leadership on emerging technology, cyber threats, and regulatory developments. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)