Technical Program Manager – Cyber / Data Security

Morgan-Stanley

Town of Islip (NY)

On-site

USD 195,000 - 275,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Morgan Stanley is seeking a Data Security Program Manager to lead complex data security initiatives across Technology, Cyber, Risk and Business units. The role focuses on governance, milestone execution, risk management, and executive communications to reduce firmwide risk.

The position requires strong program discipline, data security domain knowledge, and a track record of delivering measurable control improvements.

Qualifications

  • 10+ years demonstrable project management experience.
  • Experience delivering at program manager level in data security, cyber risk, technology controls, compliance, or regulatory environment.
  • Experience producing executive-ready program reporting and governance materials.

Responsibilities

  • Lead data security risk reduction execution across DSRE workstreams with defined milestones and risk-reducing outcomes.
  • Prepare updates for governance forums with program status, risks, issues, decisions, metrics, and green plans.
  • Drive milestone-based delivery and BAU transition with integrated plans for control implementation and evidence-based monitoring.
  • Coordinate cross-program dependencies with technology, cyber, risk, policy, and business programs.
  • Define and track KPIs, KRIs, thresholds, trends, and executive narratives showing measurable risk reduction.

Skills

Data security
Risk management
Program management
Leadership
Change management
Communication
Waterfall & Agile
Executive reporting

Tools

OpenPages

Job description

We're seeking someone to join our team as a Data Security Program Manager. Positioned to be the best in class of program execution across Technology at Morgan Stanley, the Strategic Programs Execution (SPE) is a Super Department in Cyber, Data, Risk and Resilience (CDRR). This function facilitates enhanced delivery capability to effectively manage the increasing pipeline of critical technology, regulatory, risk and control-based programs.Job SummaryResponsible for leading complex data security programs that reduce firmwide risk, strengthen control execution, and advance the Firm's Data Security Strategy. This individual will manage cross-divisional delivery across Technology, Cyber, Business, Risk, and Control stakeholders, with accountability for planning, governance, milestone execution, risk and issue management, metrics reporting, and executive communication. The candidate should bring strong program management discipline, data security domain awareness, and the ability to translate technical control delivery into risk-reducing outcomes for senior leadership.Initial AssignmentAs Data Security Program Manager, responsible for driving execution of data security risk reduction initiatives across the Data Security Risk Execution (DSRE) portfolio, supporting governance through the Data Security Execution Governance Committee (DSEGC), and ensuring delivery aligns to the Firm's Data Security Strategy, applicable policy requirements, and risk appetite.The program scope includes oversight of data security capabilities including Data Leakage Prevention, Data Discovery, Data Masking, Secure Logging, Encryption at Rest, Encryption in Transit, Post-Quantum Cryptography readiness, API security, identity and access management, anomalous behavior detection, incident management, external website controls, network security, vendor risk management, and third-party data protection.This is a hands-on leadership role requiring close partnership with control owners, delivery leads, Business Unit sponsors, 1LOD/2LOD/3LOD stakeholders, and senior governance forums to drive transparent execution, timely escalation, and sustainable transition of mature capabilities to business-as-usual monitoring. The program is currently in its execution phase but detailed approach and plan for BAU transition yet to be agreed.ResponsibilitiesLead data security risk reduction execution: coordinate delivery across DSRE workstreams, ensuring milestones, action plans, dependencies, and risk-reducing outcomes are clearly defined, tracked, and achieved.Manage governance and executive reporting: prepare high-quality updates for DSEGC and related governance forums, including program status, risks, issues, decisions, metrics, and path-to-green plans.Drive milestone-based delivery plans and BAU transition: establish integrated plans that support control implementation, adoption, operational readiness, evidence capture, and sustainable metrics-based monitoring.Manage cross-program dependencies: partner with related technology, cyber, risk, policy, and business programs to align scope, delivery sequencing, control requirementsStrengthen data security metrics and risk reporting: partner with metrics owners to define KPIs, KRIs, thresholds, trends, and executive narratives that demonstrate measurable control effectiveness and risk reduction.Support emerging technology and AI security integration: identify opportunities to improve data protection governance for AI-enabled use cases, external websites, APIs, SaaS platforms, and other evolving data movement channels.Develop program artifacts: maintain charters, roadmaps, stakeholder maps, RAID logs, action trackers, decision logs, program briefs, meeting materials, and executive-level communications.Translate data into actionable insights for senior audiences: analyze program status, delivery trends, control metrics, risks, dependenciesRequirementsAt least 10 years demonstrable project management experienceDemonstrable track record of operating and delivering at program manager level - 3 years minimumDemonstrable experience leading change in a data security, cyber risk, technology controls, compliance, or regulatory environment.Experience producing executive-ready program reporting, including milestone plans, RAID logs, KPI/KRI dashboards, OpenPages Issue and Action Plan status, and governance materials for senior committees.Experienced of leading projects/programs using waterfall and agile methodologiesSkillsStrong knowledge of data security, cyber controls, risk management, and technology governance, with familiarity across DLP, data discovery, encryption, identity and access management, incident response, API security, vendor risk, and third-party data protection.Previous experience on data security, cyber risk, control remediation, regulatory, or assessment programs strongly preferred.Leading and driving delivery teamsTransitioning into BAU, including change managementManaging using a risk-based data security program approach, including alignment of milestones, evidence, metrics, issues, and action plans to measurable risk reduction.Defining and tracking data security benefits, including improved control coverage, reduced residual risk, stronger governance, increased transparency, and sustainable BAU monitoring.Effective interpersonal and communication skillsAbility to create a sense of community amongst the disparate members of the project teamsA strong knowledge of techniques for planning, monitoring, and controlling programsWHAT YOU CAN EXPECT FROM MORGAN STANLEY:At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.Expected base pay rates for the role will be between $195,000 and $275,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.For more information, please visit : https://www.morganstanley.com/people-opportunities/eeo .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cyber Security Engineering
Manager, Cyber Security Engineering

Morgan-Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Competitive compensation package
Employee benefits
Senior Data Access Protection Engineer - Vice President
Senior Data Access Protection Engineer - Vice President

Morgan-Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Technical Program Manager - CISO Office
Technical Program Manager - CISO Office

Morgan-Stanley • Baltimore (MD)

On-site
USD 125,000 - 175,000
Senior Data Access Protection Engineer - Vice President
Senior Data Access Protection Engineer - Vice President

PowerToFly • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Morgan-Stanley • Town of Islip (NY)

On-site
USD 120,000 - 210,000
Program Manager - Applied AI Enablement
Program Manager - Applied AI Enablement

Morgan-Stanley • Town of Islip (NY)

On-site
USD 155,000 - 215,000
Senior Data Access Protection Engineer - Vice President
Senior Data Access Protection Engineer - Vice President

Morgan Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Windows Infrastructure Engineer - Vice President
Windows Infrastructure Engineer - Vice President

Koitecc Solutions • New York (NY)

On-site
USD 150,000 - 210,000
Windows Infrastructure Engineer - Vice President
Windows Infrastructure Engineer - Vice President

Quest Oracle Community • New York (NY)

On-site
USD 150,000 - 210,000
Lead Application Security Eng
Lead Application Security Eng

PowerToFly • Alpharetta (GA)

On-site
USD 125,000 - 175,000