Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

NFR CTIS Asia Lead, Executive Director

AT Morgan Stanley
Morgan Stanley

NFR CTIS Asia Lead, Executive Director

Hong Kong

Department Profile:
The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks, globally. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm's information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm's information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm's key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events.

Want more jobs like this?

Get Unknown jobs in Hong Kong delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


Position Description:
Morgan Stanley is seeking a Risk professional to lead the Asia Cyber, Technology and Information Security (CTIS) Oversight Department within the Non-Financial Risk Organisation in Hong Kong at the Executive Director level. CTIS Risk Oversight is the practice of monitoring risks related to the confidentiality, availability and integrity of the Firm's systems and information including associated processes and controls. The successful candidate will be responsible for running a team focused on executing independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks.

Primary Responsibilities
The role includes the following primary responsibilities:
>Be a senior member of the global NFR CTIS team, providing regional and global views on CTIS risk management.
>As a senior member of the NFR CTIS team support and maintain the non-financial risk framework across the Asia entities to manage CTIS risks.
>Provide thought leadership to drive strategic and tactical evolution necessary to maintain effective and efficient CTIS risk management.
>Provide independent oversight and monitoring of risks and controls CTIS to help inform and drive the 2nd line response to the CTIS risk posture of the Firm and its underlying legal entities.
>Prepare for supervisory review non-financial risk management reporting.
>Participate and lead operational risk regulatory meetings and responses to regulatory queries.
>Directly lead and manage existing and developing 2nd line CTIS risk governance processes and committees, including scenario analysis activities.
>Keep up-to-date with local operational risk regulations, supporting our rules management function on the applicability of changing or new regulations in region.
>Build and maintain strong positive relationships with the CTIS community in the respective business and control groups, becoming a trusted advisor.
>Work with relevant 1st line risk and control owners in assessing inherent and residual risk levels based on the non-financial risk framework and relative to business appetite, including developing and monitoring metrics for Top Operational Risks and Pathways.
>Manage the team in the review and challenge of operational risk incidents, issues and actions, metrics, Risk and Control Assessments; facilitate Scenario Analysis workshops on CTIS risks relevant to the entity Qualifications and Essential Skills:
>Degree (Computer Science or Information Security, preferable but not essential)
>15+ years' worth of technology and or security risk related work experience, preferably in the financial services industry
>Experience in Technology (IT) Risk Management and or Technology (IT) Audit including Information Security , Cyber Security or Resilience risk
>Relevant industry certifications e.g. CISA. CISM, an added advantage
>Excellent communication skills, both verbal and written; ability to tailor communication to technical and non-technical audiences
>Strong interpersonal skills in order to work in a team oriented environment
>Strong leadership, people management, stakeholder management and influencing skills
>Strong project management and organization skills
>Ability to multitask and prioritize, and,
>Strong analytical and problem-solving skills.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 85 years. At our foundation are five core values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - that guide our more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find trusted colleagues, committed mentors and a culture that values diverse perspectives, individual intellect and cross-collaboration. We Firm is differentiated by the caliber of our diverse team. While our company culture and commitment to inclusion define our legacy and shape our future, helping to strengthen our business and bring value to clients around the world. Learn more about how we put this commitment to action: morganstanley.com/diversity. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry.

We're committed to bringing passion and customer focus to the business.

Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.

Client-provided location(s): Hong Kong
Job ID: Morgan-549783540837
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • Long-Term Disability
    • Fitness Subsidies
    • On-Site Gym
    • Pet Insurance
    • Mental Health Benefits
    • FSA
    • Virtual Fitness Classes
    • HSA
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
    • Return-to-Work Program
    • Birth Parent or Maternity Leave
    • Non-Birth Parent or Paternity Leave
    • Adoption Leave
  • Work Flexibility

    • Hybrid Work Opportunities
  • Office Life and Perks

    • Commuter Benefits Program
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Leave of Absence
    • Volunteer Time Off
    • Personal/Sick Days
  • Financial and Retirement

    • 401(K) With Company Matching
    • Stock Purchase Program
    • Performance Bonus
    • Relocation Assistance
    • Financial Counseling
  • Professional Development

    • Tuition Reimbursement
    • Promote From Within
    • Mentor Program
    • Access to Online Courses
    • Lunch and Learns
    • Work Visa Sponsorship
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Internship Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)