Jobs › Non-Financial Risk Manager - CTIS
Non-Financial Risk Manager - CTIS
Job at a glance
- Category
- GRC
- Work arrangement
- On-site
- Location
- Hong Kong, Hong Kong
- Posted
- Aug 31, 2026
Free. One click to unsubscribe. We never share your address.
Morgan Stanley is hiring a Non-Financial Risk Manager - CTIS in Hong Kong, Hong Kong. This is a GRC job in the governance, risk, and compliance field. Review the full details below and apply directly with Morgan Stanley.
The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks, globally. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm's information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm's information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm's key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events. Morgan Stanley is seeking a Risk professional to lead the Asia Cyber, Technology and Information Security (CTIS) Oversight Department within the Non-Financial Risk Organisation in Hong Kong at the Executive Director level. CTIS Risk Oversight is the practice of monitoring risks related to the confidentiality, availability and integrity of the Firm's systems and information including associated processes and controls. The successful candidate will be responsible for running a team focused on executing independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks. Primary Responsibilities The role includes the following primary responsibilities: Be a senior member of the global NFR CTIS team, providing regional and global views on CTIS risk management. As a senior member of the NFR CTIS team support and maintain the non-financial risk framework across the Asia entities to manage CTIS risks. Provide thought leadership to drive strategic and tactical evolution necessary to
Full responsibilities and requirements are on Morgan Stanley's application page.
Apply for this job →Location and market context
This job is based in Hong Kong, Hong Kong on-site. Local candidates benefit from being close to Morgan Stanley's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Morgan Stanley would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location