GRC CareersAGJ, the AI governance job boardPost a Job

Jobs › Non-Financial Risk Manager - CTIS

Non-Financial Risk Manager - CTIS

Morgan Stanley

Job at a glance

Category
GRC
Work arrangement
On-site
Location
Hong Kong, Hong Kong
Posted
Aug 31, 2026
Apply for this jobApplications go directly to Morgan Stanley
Applying today? Most GRC roles fill fast. Get the next ones the day they post, in Hong Kong, Hong Kong.

Free. One click to unsubscribe. We never share your address.

ShareEmailLinkedInXFacebookPrint / Save PDF

Morgan Stanley is hiring a Non-Financial Risk Manager - CTIS in Hong Kong, Hong Kong. This is a GRC job in the governance, risk, and compliance field. Review the full details below and apply directly with Morgan Stanley.

The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks, globally. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm's information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm's information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm's key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events. Morgan Stanley is seeking a Risk professional to lead the Asia Cyber, Technology and Information Security (CTIS) Oversight Department within the Non-Financial Risk Organisation in Hong Kong at the Executive Director level. CTIS Risk Oversight is the practice of monitoring risks related to the confidentiality, availability and integrity of the Firm's systems and information including associated processes and controls. The successful candidate will be responsible for running a team focused on executing independent oversight and monitoring of risks and controls around the Firm's cyber, technology and information security risks. Primary Responsibilities The role includes the following primary responsibilities: Be a senior member of the global NFR CTIS team, providing regional and global views on CTIS risk management. As a senior member of the NFR CTIS team support and maintain the non-financial risk framework across the Asia entities to manage CTIS risks. Provide thought leadership to drive strategic and tactical evolution necessary to

Full responsibilities and requirements are on Morgan Stanley's application page.

Apply for this job →
About Morgan Stanley
Hiring for governance, risk, and compliance jobs on GRC Careers.
Search all Morgan Stanley jobs →

Location and market context

This job is based in Hong Kong, Hong Kong on-site. Local candidates benefit from being close to Morgan Stanley's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance jobs

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance job

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Morgan Stanley would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

IT Risk & Compliance Manager
SS&C Technologies
Melbourne, Australia
Contractor Special/Program Security Officer (CPSO)
KBR
Colorado Springs, CO$92k
Cybersecurity & AI Engineer Automation
Mirakl
Paris, France
Cybersecurity Risk Management and Compliance - Technical
DHS Headquarters
Multiple Locations$107k to $215k
Cyber Strategic Analyst
Joint Activities
Fort Meade, Maryland$177k to $197k
IT Cybersecurity Specialist (Customer Support/Information Security)
U.S. Coast Guard
Portsmouth, Virginia$91k to $118k
Get more jobs like this by email
We will email you new GRC jobs in Hong Kong, Hong Kong as they post. Free and confidential, one click to unsubscribe.

Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

More GRC jobs: All GRC jobs · Search by category & location