Technical Program Manager – Cyber / Data Security
Morgan Stanley
Get more Cybersecurity openings
A short daily email when similar roles appear in New York. No account needed.
We're seeking someone to join our team as a Data Security Program Manager. Positioned to be the best in class of program execution across Technology at Morgan Stanley, the Strategic Programs Execution (SPE) is a Super Department in Cyber, Data, Risk and Resilience (CDRR). This function facilitates enhanced delivery capability to effectively manage the increasing pipeline of critical technology, regulatory, risk and control-based programs.
Job Summary
Responsible for leading complex data security programs that reduce firmwide risk, strengthen control execution, and advance the Firm's Data Security Strategy. This individual will manage cross-divisional delivery across Technology, Cyber, Business, Risk, and Control stakeholders, with accountability for planning, governance, milestone execution, risk and issue management, metrics reporting, and executive communication. The candidate should bring strong program management discipline, data security domain awareness, and the ability to translate technical control delivery into risk-reducing outcomes for senior leadership.
Initial Assignment
As Data Security Program Manager, responsible for driving execution of data security risk reduction initiatives across the Data Security Risk Execution (DSRE) portfolio, supporting governance through the Data Security Execution Governance Committee (DSEGC), and ensuring delivery aligns to the Firm's Data Security Strategy, applicable policy requirements, and risk appetite.
The program scope includes oversight of data security capabilities including Data Leakage Prevention, Data Discovery, Data Masking, Secure Logging, Encryption at Rest, Encryption in Transit, Post-Quantum Cryptography readiness, API security, identity and access management, anomalous behavior detection, incident management, external website controls, network security, vendor risk management, and third-party data protection.
This is a hands-on leadership role requiring close partnership with control owners, delivery leads, Business Unit sponsors, 1LOD/2LOD/3LOD stakeholders, and senior governance forums to drive transparent execution, timely escalation, and sustainable transition of mature capabilities to business-as-usual monitoring. The program is currently in its execution phase but detailed approach and plan for BAU transition yet to be agreed.
Responsibilities
Lead data security risk reduction execution: coordinate delivery across DSRE workstreams, ensuring milestones, action plans, dependencies, and risk-reducing outcomes are clearly defined, tracked, and achieved.
Manage governance and executive reporting: prepare high-quality updates for DSEGC and related governance forums, including program status, risks, issues, decisions, metrics, and path-to-green plans.
Drive milestone-based delivery plans and BAU transition: establish integrated plans that support control implementation, adoption, operational readiness, evidence capture, and sustainable metrics-based monitoring.
Manage cross-program dependencies: partner with related technology, cyber, risk, policy, and business programs to align scope, delivery sequencing, control requirements
Strengthen data security metrics and risk reporting: partner with metrics owners to define KPIs, KRIs, thresholds, trends, and executive narratives that demonstrate measurable control effectiveness and risk reduction.
Support emerging technology and AI security integration: identify opportunities to improve data protection governance for AI-enabled use cases, external websites, APIs, SaaS platforms, and other evolving data movement channels.
Develop program artifacts: maintain charters, roadmaps, stakeholder maps, RAID logs, action trackers, decision logs, program briefs, meeting materials, and executive-level communications.
Translate data into actionable insights for senior audiences: analyze program status, delivery trends, control metrics, risks, dependencies
Requirements
At least 10 years demonstrable project management experience
Demonstrable track record of operating and delivering at program manager level - 3 years minimum
Demonstrable experience leading change in a data security, cyber risk, technology controls, compliance, or regulatory environment.
Experience producing executive-ready program reporting, including milestone plans, RAID logs, KPI/KRI dashboards, OpenPages Issue and Action Plan status, and governance materials for senior committees.
Experienced of leading projects/programs using waterfall and agile methodologies
Skills
Strong knowledge of data security, cyber controls, risk management, and technology governance, with familiarity across DLP, data discovery, encryption, identity and access management, incident response, API security, vendor risk, and third-party data protection.
Previous experience on data security, cyber risk, control remediation, regulatory, or assessment programs strongly preferred.
Leading and driving delivery teams
Transitioning into BAU, including change management
Managing using a risk-based data security program approach, including alignment of milestones, evidence, metrics, issues, and action plans to measurable risk reduction.
Defining and tracking data security benefits, including improved control coverage, reduced residual risk, stronger governance, increased transparency, and sustainable BAU monitoring.
Effective interpersonal and communication skills
Ability to create a sense of community amongst the disparate members of the project teams
A strong knowledge of techniques for planning, monitoring, and controlling programs
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Expected base pay rates for the role will be between $195,000 and $275,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.
Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.
Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.
For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.
The average job posting receives 250 applications.
Stand out by tailoring your resume to this specific role. Our AI resume builder highlights the skills and experience that matter most to this employer.
More open roles at Morgan Stanley
Benefits Manager – Healthcare Strategy
New York
Associate - AI Governance & Reporting - Model Risk
New York
Registered Client Service Associate
Baltimore
Private Wealth Management Senior Registered Client Service Associate
Miami Beach
Registered Client Service Associate
Oxnard
Risk COO (Risk Management) : Job Level - Associate
New York
More cybersecurity roles in New York
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead
Morgan Stanley
Senior AI Product Manager, Cybersecurity
Scale AI
Digital Asset Cyber and Fraud Risk Specialist - Vice President
Morgan Stanley
Supervisor - Cyber M&A Diligence
RSM
Cyber Risk Director
Tradeweb
Cybersecurity Engineer - Cryptography - Director
Morgan Stanley