Non-Financial Risk Manager – CTIS - Associate
We’re seeking someone to join our team as a Non-Financial Risk Manager – CTIS - Associate
The cornerstone of Morgan Stanley's risk management philosophy is the execution of risk-adjusted returns through prudent risk-taking that protects Morgan Stanley's capital base, liquidity and franchise. Non-Financial Risk (NFR) refers to the risk of actual or potential economic, reputational, regulatory, financial reporting and client impact, resulting from inadequate or failed internal processes, people, and systems, or from external events impacting the full scope of its business activities, including revenue-generating activities and infrastructure groups. NFR is part of the Second Line of Defence providing independent oversight and challenge to management across compliance and operational risks. Given the nature and breadth of operational risk, operational risks are managed at multiple levels e.g. Firmwide, as well as Regional, Business Unit, Infrastructure Group, Control Function and Legal Entity.
The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm’s information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm’s information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm’s key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events.
Morgan Stanley is seeking a Risk professional to join the Cyber, Technology and Information Security (CTIS) Oversight Department within the Non-Financial Risk Organisation in Budapest at the Associate level. CTIS Risk Oversight is the practice of monitoring risks related to the confidentiality, availability and integrity of the Firm’s systems and information including associated processes and controls. The successful candidate will be responsible for the monitoring of risks and controls around the Firm’s CTIS.
Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.
What you'll do in the role:
Review & Challenge: Review risk management activities performed by first line of defense (1L), and challenge the effectiveness of existing controls and mitigation strategies.
Metrics, Risk Reporting & Monitoring: Regularly monitor and assess the effectiveness of risk management activities. Highlight key risks and the status of risk mitigation efforts. Review metrics and escalation reports to monitor risk and control-related developments, issues and trends.
Emerging Threat Oversight: Keep a close eye on emerging security threats and vulnerabilities and advise 1L on adjustments or enhancements to risk management practices to address new challenges.
Incident Response Oversight: Provide oversight of incident response activities, ensuring that risk management considerations are incorporated into the response process, and assist with post-incident risk assessments.
Security Awareness & Culture: Promote a culture of cybersecurity awareness and risk management across the organization, monitoring that employees at all levels understand their role in managing security risks.
Cross-Functional Collaboration: Work closely with other departments to ensure the alignment of security risk management activities with broader organizational risk management frameworks. Build and maintain strong positive relationships with the broader risk community and the security engineering, operational and development teams.
What you'll bring to the role:
Degree (Computer Science or Information Security, preferable but not essential)
3+ years’ worth of cybersecurity or security risk related work experience.
Basic understanding of cybersecurity frameworks, risk management principles, and security controls. Familiarity with risk management best practices (e.g., CRI, NIST CSF, ISO 27001, CIS Controls).
Excellent communication skills, both verbal and written; ability to tailor communication to technical and non-technical audiences.
Strong analytical skills.
#LI-HYBRID #BPGC #LI-VR1
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Certified Persons Regulatory Requirements:
If this role is deemed a Certified role and may require the role holder to hold mandatory regulatory qualifications or the minimum qualifications to meet internal company benchmarks.
Flexible work statement
Interested in flexible working opportunities? Morgan Stanley empowers employees to have greater freedom of choice through flexible working arrangements. Speak to our recruitment team to find out more.
Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.