Technical Program Manager – Cyber / Data Security

Morgan Stanley

New York, New York, United States of AmericaFull-timePosted 23h ago

Get more Cybersecurity openings

A short daily email when similar roles appear in New York. No account needed.

We're seeking someone to join our team as a Data Security Program Manager. Positioned to be the best in class of program execution across Technology at Morgan Stanley, the Strategic Programs Execution (SPE) is a Super Department in Cyber, Data, Risk and Resilience (CDRR). This function facilitates enhanced delivery capability to effectively manage the increasing pipeline of critical technology, regulatory, risk and control-based programs.

Job Summary
Responsible for leading complex data security programs that reduce firmwide risk, strengthen control execution, and advance the Firm's Data Security Strategy. This individual will manage cross-divisional delivery across Technology, Cyber, Business, Risk, and Control stakeholders, with accountability for planning, governance, milestone execution, risk and issue management, metrics reporting, and executive communication. The candidate should bring strong program management discipline, data security domain awareness, and the ability to translate technical control delivery into risk-reducing outcomes for senior leadership.

Initial Assignment
As Data Security Program Manager, responsible for driving execution of data security risk reduction initiatives across the Data Security Risk Execution (DSRE) portfolio, supporting governance through the Data Security Execution Governance Committee (DSEGC), and ensuring delivery aligns to the Firm's Data Security Strategy, applicable policy requirements, and risk appetite.
The program scope includes oversight of data security capabilities including Data Leakage Prevention, Data Discovery, Data Masking, Secure Logging, Encryption at Rest, Encryption in Transit, Post-Quantum Cryptography readiness, API security, identity and access management, anomalous behavior detection, incident management, external website controls, network security, vendor risk management, and third-party data protection.

This is a hands-on leadership role requiring close partnership with control owners, delivery leads, Business Unit sponsors, 1LOD/2LOD/3LOD stakeholders, and senior governance forums to drive transparent execution, timely escalation, and sustainable transition of mature capabilities to business-as-usual monitoring. The program is currently in its execution phase but detailed approach and plan for BAU transition yet to be agreed.

Responsibilities
Lead data security risk reduction execution: coordinate delivery across DSRE workstreams, ensuring milestones, action plans, dependencies, and risk-reducing outcomes are clearly defined, tracked, and achieved.
Manage governance and executive reporting: prepare high-quality updates for DSEGC and related governance forums, including program status, risks, issues, decisions, metrics, and path-to-green plans.
Drive milestone-based delivery plans and BAU transition: establish integrated plans that support control implementation, adoption, operational readiness, evidence capture, and sustainable metrics-based monitoring.
Manage cross-program dependencies: partner with related technology, cyber, risk, policy, and business programs to align scope, delivery sequencing, control requirements
Strengthen data security metrics and risk reporting: partner with metrics owners to define KPIs, KRIs, thresholds, trends, and executive narratives that demonstrate measurable control effectiveness and risk reduction.
Support emerging technology and AI security integration: identify opportunities to improve data protection governance for AI-enabled use cases, external websites, APIs, SaaS platforms, and other evolving data movement channels.
Develop program artifacts: maintain charters, roadmaps, stakeholder maps, RAID logs, action trackers, decision logs, program briefs, meeting materials, and executive-level communications.
Translate data into actionable insights for senior audiences: analyze program status, delivery trends, control metrics, risks, dependencies

Requirements

  • At least 10 years demonstrable project management experience

  • Demonstrable track record of operating and delivering at program manager level - 3 years minimum

  • Demonstrable experience leading change in a data security, cyber risk, technology controls, compliance, or regulatory environment.

  • Experience producing executive-ready program reporting, including milestone plans, RAID logs, KPI/KRI dashboards, OpenPages Issue and Action Plan status, and governance materials for senior committees.

  • Experienced of leading projects/programs using waterfall and agile methodologies

Skills

  • Strong knowledge of data security, cyber controls, risk management, and technology governance, with familiarity across DLP, data discovery, encryption, identity and access management, incident response, API security, vendor risk, and third-party data protection.

  • Previous experience on data security, cyber risk, control remediation, regulatory, or assessment programs strongly preferred.

  • Leading and driving delivery teams

  • Transitioning into BAU, including change management

  • Managing using a risk-based data security program approach, including alignment of milestones, evidence, metrics, issues, and action plans to measurable risk reduction.

  • Defining and tracking data security benefits, including improved control coverage, reduced residual risk, stronger governance, increased transparency, and sustainable BAU monitoring.

  • Effective interpersonal and communication skills

  • Ability to create a sense of community amongst the disparate members of the project teams

  • A strong knowledge of techniques for planning, monitoring, and controlling programs

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years.  Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Expected base pay rates for the role will be between $195,000 and $275,000 per year at the commencement of employment.  However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background.  Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

The average job posting receives 250 applications.

Stand out by tailoring your resume to this specific role. Our AI resume builder highlights the skills and experience that matter most to this employer.

Frequently asked questions

Who is hiring for Technical Program Manager – Cyber / Data Security at Morgan Stanley?+
Morgan Stanley is actively hiring for this Technical Program Manager – Cyber / Data Security role. Click "Apply Now" to submit your application directly on Morgan Stanley's careers page — Careeronaut doesn't charge employers or candidates for referrals.
When was this Technical Program Manager – Cyber / Data Security role posted?+
This listing was first posted on 2026-09-11. We pull the latest copy from the source feed daily, and any role that's taken down gets removed from Careeronaut within seven days so you don't waste time on stale listings.
How should I apply to this Technical Program Manager – Cyber / Data Security role?+
Start by tailoring your resume to the posting — most applicants send generic CVs and the first filter recruiters use is keyword relevance. Careeronaut's AI does this automatically: paste the job description, get a matched resume in under a minute, and download as PDF or DOCX.
Where can I find more Cybersecurity jobs in New York?+
Browse all open cybersecurity roles in New York on the listing pages linked below. You can filter by salary, remote-friendly, and posting date.