Apply with hirly
Internal Audit Executive Director – Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience
Ms · New York, New York, United States of America
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Already have an account? Sign in to see your saved application
The cyber risk landscape is changing rapidly, and the Firm requires audit leadership equipped to meet the moment. We are seeking an Executive Director to lead internal audit technology coverage across the global Firm and its banking entities, including Morgan Stanley Bank, N.A. (MSBNA) and Morgan Stanley Private Bank, N.A. (MSPBNA). This role demands a forward-looking leader who can address both today's threats and the emerging risks now reshaping cybersecurity, information security, and cyber resilience — with deep cyber risk expertise and a strong understanding of how artificial intelligence, agentic and frontier AI models, cloud transformation, and digital assets are actively changing the risk landscape and regulatory expectations. The successful candidate will translate these developments into practical, risk-based audit strategies, deliver insightful challenge to management, and evolve the Firm's assurance approach to address current and emerging threats. The Internal Audit Division (IAD) drives attention and resources to vulnerabilities by providing an independent and well-informed view and impactful messages about the most important risks facing our Firm. This is accomplished by performing a range of assurance activities to independently assess the quality and effectiveness of Morgan Stanley’s system of internal control, including risk management and governance systems and processes. IAD serves as an objective and independent function within the Firm’s risk management framework to foster continual improvement of risk management processes. This is an Executive Director (P6) level position within the Technical Specialist function, which is responsible for providing extensive subject matter expertise and reinforcing the ability of business and technology audit teams to appropriately assess risk and determine and execute coverage. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. What you’ll do in the role
- Prioritize and lead coverage of emerging risks related to artificial intelligence and frontier models — including generative and agentic AI — assessing build time, run time, and life cycle controls, data protection, identity and entitlements for autonomous agents, and the expanded attack surface these capabilities create, as well as adversaries’ growing use of AI to accelerate and scale attacks.
- Provide coverage of the idiosyncratic risks arising from cryptocurrency and digital assets, including digital asset custody, private key generation and lifecycle management, and the security of both online (network-connected) and offline (air-gapped) custody infrastructure — highlighting the associated cyber threats such as private key compromise, transaction and address manipulation, smart contract exploitation, and the irreversible loss of assets.
- Assess quantum computing and post-quantum cryptography readiness, and other frontier technology risks, ensuring these are reflected in the audit plan and in the Firm’s forward-looking resilience posture.
- Monitor the intensifying threat landscape — including advanced attack techniques and regulatory change — and continuously factor emerging threats into audit scoping and assurance coverage.
- Provide independent assurance over the design and operating effectiveness of the controls that protect the Firm’s and Banks’ technology environment, customer data, and critical business services
- Set and lead the multi-year, risk-based audit strategy for cybersecurity, information security, and cyber resilience across the Firm and its Banks, spanning the full technology stack (infrastructure, network, platform, application, and data layers) and each business unit to form an integrated, Firm-wide view of control effectiveness, and how cyber threats, information loss, and a cyber attach could affect business lines, critical services, and legal entities across the Firm.
- Direct execution of the audit plan across the core cyber and information security domains — identity and access management, endpoint security, network security, data protection, threat detection and response, and vulnerability management.
- Lead assurance activities assessing cyber resilience capabilities, including incident response, disaster recovery, business continuity, and third-party/vendor security.
- Evaluate compliance with regulatory expectations (e.g., FFIEC, OCC, FDIC, NYDFS, GLBA, RGF, DORA) and industry frameworks (CRI Profile, NIST CSF, ISO 27001).
- Oversee root cause analysis on control failures and audit findings, and track remediation to closure.
- Comprehensively articulate actionable insights regarding the criticality and impact of cyber risk, and how well it is managed, to senior management and regulators. Prepare materials for the Chief Audit Executive’s updates to the Audit Committee and the Board,
- Coordinate with second-line risk and compliance functions and with external auditors and regulators, and collaborate with global peers to identify risk themes and implications across business segments and legal entities.
- Mentor and develop audit staff and manage a global team; help inform and address talent needs and identify stretch and development opportunities for team members. What you’ll bring to the role
- Advanced understanding of cybersecurity, information security, and cyber resilience risks and the relevant regulations, including banking regulatory requirements.
- Experience assessing emerging technology risks and their control implications — including AI and agentic AI, frontier models, cryptocurrency and digital asset custody, and quantum/post-quantum cryptography — and the ability to translate a rapidly changing threat landscape into practical audit coverage.
- Strong knowledge of cybersecurity frameworks (NIST CSF, ISO 27001, CRI Profile) and experience auditing identity and access management, cloud security, and network architecture.
- Expertise in audit principles, methodology, tools, and processes (e.g., risk assessments, planning, testing, reporting, and continuous monitoring).
- Ability to analyze data and prioritize coverage and assurance activities based on the criticality of risk.
- Ability to articulate risk and impact clearly and succinctly to different audiences, including senior stakeholders, the Board, and regulators.
- Ability to inspire and support others to do their best work through active coaching, feedback, and development opportunities, and by ensuring trust and inclusion among team members.
- Experience in overseeing resource utilization and monitoring progress against deliverables.
- A bachelor’s degree in Information Security, Computer Science, or a related field.
- At least 12-15 years’ relevant experience in IT/cyber audit, information security, or risk management — ideally in banking or financial services — would generally be expected to fulfill the skills required for this role.
- Relevant certifications (e.g., CISA, CISSP, CISM, or equivalent) preferred. Preferred qualifications
- Experience with incident response or red team/penetration testing programs.
- Familiarity with the
Mitre Att&ck
framework.
- Prior experience at a large financial institution or a Big 4 consulting firm.
What You Can Expect from Morgan Stanley
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values — putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back — aren’t just beliefs, they guide the decisions we make every day to do what’s best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are su