← All roles
VP

VP Cyber Technology and Information Security Risk Oversight Lead

Morgan Stanley · Financial Services · 10,000+ employees

New York, NY · Onsite · full_time

Listed by the employer as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead”. Title normalized for comparability.

CLI Career Level

SVP-equivalent

Moderate confidence

Opportunity Score

66/100

Solid

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 3, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Broader than the title suggests

This role reads SVP-equivalent despite being advertised as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate. The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk. Team size is not disclosed and remains the main open question before pursuing it.

Why this role scores the way it does

66/100 — solid opportunity quality. CLI reads this as a SVP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

SVP-equivalent — The employer lists this as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead”. CLI reads it as SVP-equivalent because the role shows global responsibility, 10,000+ employee organization.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.

What to probe before applying

  • The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk.

Scoring components · Solid

Compensation versus comparable roles55 · weight 15%

The employer discloses a base range, but there is no comparable set to benchmark it against yet.

Reporting level0 · weight 12%

The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk.

Functional and geographic scope43 · weight 12%

Scope language covers global responsibility.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposureNot disclosed · excluded from the score

Executive and board exposure: not disclosed.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory100 · weight 10%

Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals100 · weight 5%

No adverse signals identified in the posting.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

$120,000 – $210,000 base salary, disclosed by employer

Sample size not yet sufficient for a market comparison

Compensation includes a base pay range plus potential commission, incentive compensation, and discretionary bonuses.

See the full benchmark bands by level and region

The mandate

Serve as a Vice President leading the Cyber, Technology and Information Security (CTIS) Risk Oversight team within the Non-Financial Risk department. The leader is responsible for the independent oversight, monitoring, and challenge of the firm's risks and controls related to IT resilience, architecture, asset management, and cyber threat intelligence.

This role sits within the Non-Financial Risk (NFR) department, specifically leading the CTIS team. The remit covers independent oversight of cyber, technology, and information security risks across the global firm.

Scope

  • Reports to Head of CTIS within Non-Financial Risk

Domains and regulation

  • Cyber Defense
  • Infrastructure Security
  • Identity
  • GRC
  • Compliance
  • Threat Intelligence
  • Resilience

Requirements

Must have

  • Experience in Technology (IT) Risk Management and/or Technology (IT) Audit including Information Security and or Cyber Security
  • Strong leadership, people management, stakeholder management and influencing skills
  • Ability to produce concise and effective presentations tailored to technical and non-technical audiences
  • Strong analytical and problem-solving skills

Preferred / bonus

  • 10+ years of technology and or security risk related work experience, preferably in the financial services industry
  • Preferred: College degree (STEM or Information Security)

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Not stated in the posting: Explicit reporting line by title not provided beyond the department name.; Specific team size not disclosed.; Specific board-level interaction not explicitly stated, though governance committee reporting is mentioned..

About Morgan Stanley

Morgan Stanley is a global investment bank and financial services firm providing capital markets, wealth management, and investment management services. It serves a diverse client base including corporations, governments, institutions, and individuals across more than 40 countries. For a security leader, the organization represents a high-stakes environment focused on protecting global financial data, maintaining regulatory compliance, and securing complex trading infrastructure.

Industry
Financial Services
Headcount
10,000+ employees
Headquarters
New York, NY
Founded
1935
Ownership
Public company · NYSE:MS
Funding
Publicly traded
Revenue
Over $10B

Full company profile for Morgan Stanley →

View original job description
Morgan Stanley is seeking a Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead in the CTIS team within Non-Financial Risk.The successful candidate will be responsible for leading a team focused on independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks, with a focus on areas including IT resilience, architecture and design, asset management, vulnerability and patch management, cyber threat intelligence, network security, IAM, change management, and other related areas. The ideal candidate will bring operational knowledge and experience paired with a strong risk and control lens.Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.What You'll Do In The RoleProvide independent oversight and challenge of the Firm's cybersecurity and technology organizations risk management activities.Manage the team in assessing the effectiveness of risk and control frameworks supporting new technology infrastructure, applications, cyber defenses, and information security programs.Lead the team in review and challenge of risk assessments, control evaluations, issue remediation plans, and risk acceptance decisions.Build and maintain strong positive relationships and partner with Technology, Non-Financial Risk, Legal, Audit, and business stakeholders to identify and address emerging risks.Evaluate new technology initiatives and strategic transformation programs from a risk perspective.Manage the team in monitoring key risk indicators (KRIs), metrics, and trends to identify areas requiring enhanced oversight or escalation.Support regulatory examinations, internal audits, and governance committee reporting related to technology and cyber risk.Drive consistency in risk management practices, ensuring policy requirements, governance standards, and other risk guidance are appropriately addressed.Manage the team in preparing executive-level risk reporting and deliver presentations for senior management and at risk governance forums.Contribute to the development and enhancement of Enterprise Risk Management and NFR programs.Provide thought leadership on emerging technology, cyber threats, and regulatory developments.What You'll Bring To The RoleCollege degree (STEM or Information Security, preferable but not essential)10+ years of technology and or security risk related work experience, preferably in the financial services industryExperience in Technology (IT) Risk Management and/or Technology (IT) Audit including Information Security and or Cyber SecurityStrong leadership, people management, stakeholder management and influencing skillsStrong interpersonal skills to work in a team-oriented environmentExcellent communication skills, both verbal and written; ability to produce concise and effective presentations tailored to technical and non-technical audiencesStrong project management and organization skillsAbility to multitask and prioritizeAbility to work under pressure and to tight deadlinesFlexible and self-motivatorStrong analytical and problem-solving skillsProficiency in MS Office and related applications (e.g. Word, Excel, Powerpoint)What You Can Expect From Morgan StanleyAt Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.Expected base pay rates for the role will be between $120000 and $210000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.