VP Cyber Technology and Information Security Risk Oversight Lead
Morgan Stanley · Financial Services · 10,000+ employees
New York, NY · Onsite · full_time
Listed by the employer as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead”. Title normalized for comparability.
CLI Career Level
SVP-equivalent
Moderate confidence
Opportunity Score
66/100
Solid
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 3, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — VP / Head of Security (US)
CLI Take
Broader than the title suggests
This role reads SVP-equivalent despite being advertised as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate. The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
66/100 — solid opportunity quality. CLI reads this as a SVP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
SVP-equivalent — The employer lists this as “Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead”. CLI reads it as SVP-equivalent because the role shows global responsibility, 10,000+ employee organization.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- The role carries more scope than the employer's title suggests.
- Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.
What to probe before applying
- The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk.
Scoring components · Solid
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
The reporting line sits below the executive team — the role reports to Head of CTIS within Non-Financial Risk.
Scope language covers global responsibility.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure: not disclosed.
The role carries more scope than the employer's title suggests.
Employer profile: 10,000+ employee organization, publicly traded, revenue over 10b.
Team size: not disclosed.
Budget ownership: not disclosed.
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$120,000 – $210,000 base salary, disclosed by employer
Compensation includes a base pay range plus potential commission, incentive compensation, and discretionary bonuses.
The mandate
Serve as a Vice President leading the Cyber, Technology and Information Security (CTIS) Risk Oversight team within the Non-Financial Risk department. The leader is responsible for the independent oversight, monitoring, and challenge of the firm's risks and controls related to IT resilience, architecture, asset management, and cyber threat intelligence.
This role sits within the Non-Financial Risk (NFR) department, specifically leading the CTIS team. The remit covers independent oversight of cyber, technology, and information security risks across the global firm.
Scope
- Reports to Head of CTIS within Non-Financial Risk
Domains and regulation
- Cyber Defense
- Infrastructure Security
- Identity
- GRC
- Compliance
- Threat Intelligence
- Resilience
Requirements
Must have
- Experience in Technology (IT) Risk Management and/or Technology (IT) Audit including Information Security and or Cyber Security
- Strong leadership, people management, stakeholder management and influencing skills
- Ability to produce concise and effective presentations tailored to technical and non-technical audiences
- Strong analytical and problem-solving skills
Preferred / bonus
- 10+ years of technology and or security risk related work experience, preferably in the financial services industry
- Preferred: College degree (STEM or Information Security)
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Leading independent oversight and challenge of the Firm's cybersecurity and technology organizations risk management activities.
- Managing a team to assess risk and control frameworks across new technology infrastructure, applications, and cyber defenses.
- Ensuring consistency in risk management practices across policy requirements and governance standards.
- Evaluating new technology initiatives and strategic transformation programs from a risk perspective.
Not stated in the posting: Explicit reporting line by title not provided beyond the department name.; Specific team size not disclosed.; Specific board-level interaction not explicitly stated, though governance committee reporting is mentioned..
About Morgan Stanley
Morgan Stanley is a global investment bank and financial services firm providing capital markets, wealth management, and investment management services. It serves a diverse client base including corporations, governments, institutions, and individuals across more than 40 countries. For a security leader, the organization represents a high-stakes environment focused on protecting global financial data, maintaining regulatory compliance, and securing complex trading infrastructure.
- Industry
- Financial Services
- Headcount
- 10,000+ employees
- Headquarters
- New York, NY
- Founded
- 1935
- Ownership
- Public company · NYSE:MS
- Funding
- Publicly traded
- Revenue
- Over $10B
Full company profile for Morgan Stanley →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.