Non-Financial Risk Manager - CTIS - Vice President

Budapest Millennium Tower III, Hungary

Morgan Stanley

Discover how we help individuals, families, institutions and governments raise, manage and distribute the capital they need to achieve their goals.

View all jobs at Morgan Stanley

Apply now Apply later

Non-Financial Risk Manager - CTIS - Vice President

We’re seeking someone to join our team as a Non- Financial Risk Manager - CTIS - Vice President

The cornerstone of Morgan Stanley's risk management philosophy is the execution of risk-adjusted returns through prudent risk-taking that protects Morgan Stanley's capital base, liquidity and franchise. Non-Financial Risk (NFR) refers to the risk of actual or potential economic, reputational, regulatory, financial reporting and client impact, resulting from inadequate or failed internal processes, people, and systems, or from external events impacting the full scope of its business activities, including revenue-generating activities and infrastructure groups. NFR is part of the Second Line of Defence providing independent oversight and challenge to management across compliance and operational risks. Given the nature and breadth of operational risk, operational risks are managed at multiple levels e.g. Firmwide, as well as Regional, Business Unit, Infrastructure Group, Control Function and Legal Entity.

The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm’s information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm’s information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm’s key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events.

Morgan Stanley is seeking a Risk professional to join the Cyber, Technology and Information Security (CTIS) Oversight Department within the Non-Financial Risk Organisation in Budapest at the Vice-President level. CTIS Risk Oversight is the practice of monitoring risks related to the confidentiality, availability and integrity of the Firm’s systems and information including associated processes and controls. The successful candidate will be responsible for executing independent oversight and monitoring of risks and controls around the Firm’s CTIS along with relevant thought leadership. The role will report to the Head of CTIS NFR for Morgan Stanley EMEA.

Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our

clients and our communities in more than 40 countries around the world.

What you'll do in the role:

  • As a senior member of the NFR CTIS team support the Head of NFR CTIS of Morgan Stanley EMEA in setting up and maintaining non-financial risk framework to manage CTIS risks.

  • Provide thought leadership to drive strategic and tactical evolution necessary to maintain effective and efficient CTIS risk management for EMEA Legal Entities.

  • Provide independent oversight and monitoring of risks and controls around the Firm’s technology, cyber and security to help inform and drive the 2nd line response to the technology and security risk posture of the Firm and its underlying legal entities.

  • Prepare non-financial risk management reporting and governance.

  • Participate in preparation for regular regulatory meetings and responses to regulatory queries.

  • Directly support and manage existing and developing 2nd line cyber and information security focused risk governance processes and committees, including scenario analysis activities.

  • Build and maintain strong positive relationships with the existing cyber and information security risk community in the respective business and control groups, becoming a trusted advisor.

  • Work with relevant 1st line risk and control owners in assessing inherent and residual risk levels based on the non-financial risk framework and relative to business appetite, including developing and monitoring metrics for Top Operational Risks and Pathways.

  • Review and challenge CTIS risk incidents, issues and actions, metrics, Risk and Control Assessments; facilitate Scenario Analysis workshops on CTIS risks relevant to the entity

  • Provide valuable insights to assist 1st line stakeholders in articulating, managing and/or mitigating residual risks that remain beyond appetite.

  • Build and maintain strong engagement with 2nd line colleagues who cover Business Units and Infrastructure Groups, assessing impact of cybersecurity risks on business and support processes to drive an integrated risk management response.

  • Maintain an awareness of evolving and emerging technology, security risk issues as well as internal and external incidents.

  • Support NFR management and 1st line stakeholders in the delivery of the Firm’s regulatory obligations relating to CTIS risk management.

  • Manage, coach and oversee local resources within the NFR CTIS team.

What you'll bring to the role:

  • Degree (Computer Science or Information Security, preferable but not essential)

  • 10+ years’ worth of technology and or security risk related work experience, preferably in the financial services industry

  • Experience in Technology (IT) Risk Management and or Technology (IT) Audit including Information Security , Cyber Security or Resilience risk

  • Relevant industry certifications e.g. CISA. CISM, an added advantage

  • Excellent communication skills, both verbal and written; ability to tailor communication to technical and non-technical audiences

  • Strong and interpersonal skills in order to work in a team oriented environment

  • Strong leadership, stakeholder management and influencing skills

  • Strong project management and organization skills

  • Ability to multitask and prioritize, and,

  • Strong analytical and problem-solving skills.

#LI-HYBRID #BPGC #LI-VR1

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Certified Persons Regulatory Requirements:
If this role is deemed a Certified role and may require the role holder to hold mandatory regulatory qualifications or the minimum qualifications to meet internal company benchmarks.

Flexible work statement
Interested in flexible working opportunities? Morgan Stanley empowers employees to have greater freedom of choice through flexible working arrangements. Speak to our recruitment team to find out more.

Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index šŸ’°

Job stats:  1  0  0

Tags: CISA CISM Compliance Computer Science Governance Monitoring Risk management

Perks/benefits: Flex hours Team events

Region: Europe
Country: Hungary

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.