Internal Audit Executive Director – Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience

Reposted Yesterday
Be an Early Applicant
New York, NY, USA
In-Office
165K-275K Annually
Expert/Leader
Fintech • Financial Services
The Role
Leads Morgan Stanley’s global internal audit strategy for cybersecurity, information security, and cyber resilience across the Firm and banking entities. Directs risk-based coverage of AI, digital assets, quantum readiness, cloud, identity, network, data, incident response, resilience, and third-party security. Evaluates controls against regulatory and industry frameworks, oversees findings and remediation, advises senior management, regulators, the Board, and Audit Committee, and manages and develops a global audit team.
Summary Generated by Built In

The cyber risk landscape is changing rapidly, and the Firm requires audit leadership equipped to meet the moment. We are seeking an Executive Director to lead internal audit technology coverage across the global Firm and its banking entities, including Morgan Stanley Bank, N.A. (MSBNA) and Morgan Stanley Private Bank, N.A. (MSPBNA). This role demands a forward-looking leader who can address both today's threats and the emerging risks now reshaping cybersecurity, information security, and cyber resilience — with deep cyber risk expertise and a strong understanding of how artificial intelligence, agentic and frontier AI models, cloud transformation, and digital assets are actively changing the risk landscape and regulatory expectations. The successful candidate will translate these developments into practical, risk-based audit strategies, deliver insightful challenge to management, and evolve the Firm's assurance approach to address current and emerging threats.


The Internal Audit Division (IAD) drives attention and resources to vulnerabilities by providing an independent and well-informed view and impactful messages about the most important risks facing our Firm. This is accomplished by performing a range of assurance activities to independently assess the quality and effectiveness of Morgan Stanley’s system of internal control, including risk management and governance systems and processes. IAD serves as an objective and independent function within the Firm’s risk management framework to foster continual improvement of risk management processes. This is an Executive Director (P6) level position within the Technical Specialist function, which is responsible for providing extensive subject matter expertise and reinforcing the ability of business and technology audit teams to appropriately assess risk and determine and execute coverage.​


Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you’ll do in the role

  • Prioritize and lead coverage of emerging risks related to artificial intelligence and frontier models — including generative and agentic AI — assessing build time, run time, and life cycle controls, data protection, identity and entitlements for autonomous agents, and the expanded attack surface these capabilities create, as well as adversaries’ growing use of AI to accelerate and scale attacks.
  • Provide coverage of the idiosyncratic risks arising from cryptocurrency and digital assets, including digital asset custody, private key generation and lifecycle management, and the security of both online (network-connected) and offline (air-gapped) custody infrastructure — highlighting the associated cyber threats such as private key compromise, transaction and address manipulation, smart contract exploitation, and the irreversible loss of assets.
  • Assess quantum computing and post-quantum cryptography readiness, and other frontier technology risks, ensuring these are reflected in the audit plan and in the Firm’s forward-looking resilience posture.
  • Monitor the intensifying threat landscape — including advanced attack techniques and regulatory change — and continuously factor emerging threats into audit scoping and assurance coverage.
  • Provide independent assurance over the design and operating effectiveness of the controls that protect the Firm’s and Banks’ technology environment, customer data, and critical business services
  • Set and lead the multi-year, risk-based audit strategy for cybersecurity, information security, and cyber resilience across the Firm and its Banks, spanning the full technology stack (infrastructure, network, platform, application, and data layers) and each business unit to form an integrated, Firm-wide view of control effectiveness, and how cyber threats, information loss, and a cyber attach could affect business lines, critical services, and legal entities across the Firm.
  • Direct execution of the audit plan across the core cyber and information security domains — identity and access management, endpoint security, network security, data protection, threat detection and response, and vulnerability management.
  • Lead assurance activities assessing cyber resilience capabilities, including incident response, disaster recovery, business continuity, and third-party/vendor security.
  • Evaluate compliance with regulatory expectations (e.g., FFIEC, OCC, FDIC, NYDFS, GLBA, RGF, DORA) and industry frameworks (CRI Profile, NIST CSF, ISO 27001).
  • Oversee root cause analysis on control failures and audit findings, and track remediation to closure.
  • Comprehensively articulate actionable insights regarding the criticality and impact of cyber risk, and how well it is managed, to senior management and regulators. Prepare materials for the Chief Audit Executive’s updates to the Audit Committee and the Board,
  • Coordinate with second-line risk and compliance functions and with external auditors and regulators, and collaborate with global peers to identify risk themes and implications across business segments and legal entities.
  • Mentor and develop audit staff and manage a global team; help inform and address talent needs and identify stretch and development opportunities for team members.

What you’ll bring to the role

  • Advanced understanding of cybersecurity, information security, and cyber resilience risks and the relevant regulations, including banking regulatory requirements.
  • Experience assessing emerging technology risks and their control implications — including AI and agentic AI, frontier models, cryptocurrency and digital asset custody, and quantum/post-quantum cryptography — and the ability to translate a rapidly changing threat landscape into practical audit coverage.
  • Strong knowledge of cybersecurity frameworks (NIST CSF, ISO 27001, CRI Profile) and experience auditing identity and access management, cloud security, and network architecture.
  • Expertise in audit principles, methodology, tools, and processes (e.g., risk assessments, planning, testing, reporting, and continuous monitoring).
  • Ability to analyze data and prioritize coverage and assurance activities based on the criticality of risk.
  • Ability to articulate risk and impact clearly and succinctly to different audiences, including senior stakeholders, the Board, and regulators.
  • Ability to inspire and support others to do their best work through active coaching, feedback, and development opportunities, and by ensuring trust and inclusion among team members.
  • Experience in overseeing resource utilization and monitoring progress against deliverables.
  • A bachelor’s degree in Information Security, Computer Science, or a related field.
  • At least 12-15 years’ relevant experience in IT/cyber audit, information security, or risk management — ideally in banking or financial services — would generally be expected to fulfill the skills required for this role.
  • Relevant certifications (e.g., CISA, CISSP, CISM, or equivalent) preferred.

Preferred qualifications

  • Experience with incident response or red team/penetration testing programs.
  • Familiarity with the MITRE ATT&CK framework.
  • Prior experience at a large financial institution or a Big 4 consulting firm.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY


We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values — putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back — aren’t just beliefs, they guide the decisions we make every day to do what’s best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.


Expected base pay rates for the role will be between $165,000 and $275,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.


Morgan Stanley’s goal is to build and maintain a workforce that is diverse in experience and background but uniform in reflecting our standards of integrity and excellence. Consequently, our recruiting efforts reflect our desire to attract and retain the best and brightest from all talent pools. We want to be the first choice for prospective employees.


It is the policy of the Firm to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, creed, age, sex, sex stereotype, gender, gender identity or expression, transgender, sexual orientation, national origin, citizenship, disability, marital and civil partnership/union status, pregnancy, veteran or military service status, genetic information, or any other characteristic protected by law.


Morgan Stanley is an equal opportunity employer committed to diversifying its workforce (M/F/Disability/Vet).

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years.  Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background.  Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Skills Required

  • Bachelor's degree in Information Security, Computer Science, or a related field
  • At least 12–15 years of relevant experience in IT/cyber audit, information security, or risk management
  • Advanced understanding of cybersecurity, information security, cyber resilience risks, and banking regulations
  • Experience assessing emerging technology risks, including AI, agentic AI, frontier models, cryptocurrency, digital asset custody, and quantum or post-quantum cryptography
  • Strong knowledge of NIST CSF, ISO 27001, and CRI Profile
  • Experience auditing identity and access management, cloud security, and network architecture
  • Expertise in audit principles, methodologies, tools, and processes, including risk assessments, planning, testing, reporting, and continuous monitoring
  • Ability to analyze data and prioritize audit coverage based on risk criticality
  • Ability to communicate risk and impact clearly to senior stakeholders, Board members, and regulators
  • Experience coaching, developing, and managing audit staff and global teams
  • Experience overseeing resource utilization and monitoring progress against deliverables
  • Relevant certification such as CISA, CISSP, CISM, or equivalent
  • Experience with incident response or red team and penetration testing programs
  • Familiarity with the MITRE ATT&CK framework
  • Prior experience at a large financial institution or Big Four consulting firm

Morgan Stanley Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Morgan Stanley and has not been reviewed or approved by Morgan Stanley.

  • Parental & Family Support — Family support is extensive, with paid parental leave for all parents, adoption and fertility assistance, backup childcare, and eldercare resources. Feedback suggests these programs meaningfully enhance the overall package and help with retention.
  • Healthcare Strength — Health coverage spans medical, dental, vision, mental‑health access, care navigation, and expert second opinions. Convenient primary care access and condition‑specific support reinforce the depth of healthcare coverage.
  • Equity Value & Accessibility — Equity compensation and stock ownership are positioned as core motivators that encourage commitment and retention. Feedback suggests education and support are provided to help participants manage equity and related financial benefits.

Morgan Stanley Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
87,899 Employees

What We Do

Morgan Stanley mobilizes capital to help governments, corporations, institutions and individuals around the world achieve their financial goals. For over 85 years, the firm’s reputation for using innovative thinking to solve complex problems has been well earned and rarely matched. A consistent industry leader throughout decades of dramatic change in modern finance, Morgan Stanley will continue to break new ground in advising, serving and providing new opportunities for its clients. Morgan Stanley is committed to maintaining the first-class service and high standard of excellence that have always defined the firm. At its foundation are five core values — putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back — that guide its more than 60,000 employees in 1,200 offices across 41 countries.

Similar Jobs

MongoDB Logo MongoDB

Corporate Legal Director - Securities, M&A

Big Data • Cloud • Software • Database
Easy Apply
Hybrid
New York City, NY, USA
5550 Employees
0-0 Annually

Snap Inc. Logo Snap Inc.

Client Partner

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
4 Locations
5000 Employees
91K-161K Annually

Snap Inc. Logo Snap Inc.

Senior Client Partner

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
4 Locations
5000 Employees
121K-214K Annually

CoreWeave Logo CoreWeave

Manager, Strategic Finance

Cloud • Information Technology • Machine Learning
In-Office
New York, NY, USA
1450 Employees
127K-168K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account