Global Head of Governance | Threat Hunt | Executive Director
Top focus
This is a senior Executive Director role within Cybersecurity, responsible for leading governance, risk oversight, and stakeholder engagement for a highly specialized cyber defense environment. The role sits at the intersection of cyber operations, technology risk, regulatory engagement, and executive reporting, ensuring that critical cyber defense capabilities operate within a robust, controlled, and well-governed framework.
The successful candidate will provide strategic governance leadership across Threat Hunt and Cyber Defense, supporting the safe operation of cyber capabilities in an isolated and controlled environment designed to defend the Firm's networks, systems, and data.
The governance model is complex, independent, and continually evolving in response to regulatory expectations, internal risk requirements, emerging technologies, and the changing threat landscape. This role will be highly visible across Cyber, Technology, Risk, Legal, Compliance, Audit, and senior leadership forums.
It will be accountable for translating complex cyber operational activity into clear governance outcomes, strengthening control discipline, supporting regulatory and audit responses, and ensuring that cyber defense priorities remain aligned to the Firm's risk appetite, policy obligations, and strategic objectives.
As the cyber operating model continues to expand, the role will also support governance integration across Endpoint Security, Cyber Platforms, automation, and emerging capabilities such as artificial intelligence. This requires a leader who can combine strong governance judgement with sufficient technical fluency to engage credibly with engineers, cyber operators, risk partners, and executive stakeholders
Key Responsibilities
- Lead the design, execution, and continuous improvement of governance processes that enable cyber defense operations to operate safely, effectively, and in line with the Firm's policies, standards, and risk appetite.
- Serve as the primary governance lead for regulatory exams, risk assessments, audit reviews, and senior management requests relating to Threat Hunt and Cyber Defense capabilities.
- Partner with cyber operations, engineering, platform, endpoint security
- technology risk teams to identify governance requirements, assess control implications
- embed sustainable risk management practices into operational delivery.
- Translate complex cyber capabilities, operational risks
- technical control environments into clear, concise
- decision-ready materials for executive leadership, risk committees, regulators, auditors
- other non-technical stakeholders.
- Represent the department in cross-functional governance forums, contributing to the development of controls, procedures, risk treatment plans, issue management practices
- evidence standards across Cyber and Technology.
- Build strong partnerships across Cyber, Technology, first line, second line, Audit, Legal, Compliance
- business stakeholders to resolve governance gaps, strengthen accountability
- drive measurable cyber risk reduction.
- Oversee the development and maintenance of governance documentation, including process maps, control narratives, risk summaries, operating procedures, management updates
- supporting evidence for regulatory or audit review.
- Drive continuous improvement by simplifying governance processes, improving transparency of cyber risk posture, identifying opportunities for automation
- supporting the adoption of emerging technologies in a controlled and well-evidenced manner.
- Required Experience and Skills: Significant experience in cyber governance, technology risk, information security, audit, regulatory engagement
- a related control function within a complex, highly regulated organization.
- Strong understanding of cybersecurity operating environments, including threat detection, threat hunting, cyber defense, security platforms, endpoint security, incident response, or related technical domains.
- Proven ability to interpret policy, standards, controls, regulatory expectations, and audit requirements, and to convert them into practical governance processes that support operational teams.
- Excellent executive communication skills, with the ability to explain technical cyber risk, control effectiveness, and operational constraints clearly to senior, non-technical, and external audiences.
- Demonstrated experience managing complex stakeholder relationships across cyber operations, engineering, technology risk, second line risk, legal, compliance, audit, and senior management teams.
- Strong judgement, discretion, and attention to detail, with the ability to operate effectively in sensitive environments involving confidential information, regulatory scrutiny, and time-critical cyber risk matters
Preferred Qualifications
- Relevant professional certifications such as CISSP, CISM, CRISC, CISA, CGEIT, ISO 27001, or equivalent experience are desirable.
- Experience in financial services, critical infrastructure, or another highly regulated sector would be advantageous.
- Familiarity with industry frameworks and regulatory expectations such as NIST, ISO 27001, operational resilience requirements, cyber risk management frameworks, and technology control standards would be beneficial.
- WHAT YOU CAN EXPECT FROM MORGAN STANLEY: At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals.
- We do it in a way that’s differentiated – and we’ve done that for 90 years.
- Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion
- giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries.
- At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered.
- Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences.
- We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry.
- There’s also ample opportunity to move about the business for those who show passion and grit in their work.
- To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
- Expected base pay rates for the role will be between $160,000.00 and $250,000.00 per year at the commencement of employment.
- However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages
- other Morgan Stanley sponsored benefit programs.
- Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background.
- Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.
- Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.
- For more information, please visit : https://www.morganstanley.com/people-opportunities/eeo .