Technical Program Manager – Cyber / Data Security
Morgan Stanley
- Location
- New York, New York, United States of America
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 39 approvals (FY2023)
- Posted
- Sep 11, 2026
Skills
About this role
We're seeking someone to join our team as a Data Security Program Manager. Positioned to be the best in class of program execution across Technology at Morgan Stanley, the Strategic Programs Execution (SPE) is a Super Department in Cyber, Data, Risk and Resilience (CDRR). This function facilitates enhanced delivery capability to effectively manage the increasing pipeline of critical technology, regulatory, risk and control-based programs.
Job Summary
Responsible for leading complex data security programs that reduce firmwide risk, strengthen control execution, and advance the Firm's Data Security Strategy. This individual will manage cross-divisional delivery across Technology, Cyber, Business, Risk, and Control stakeholders, with accountability for planning, governance, milestone execution, risk and issue management, metrics reporting, and executive communication. The candidate should bring strong program management discipline, data security domain awareness, and the ability to translate technical control delivery into risk-reducing outcomes for senior leadership. Initial Assignment As Data Security Program Manager, responsible for driving execution of data security risk reduction initiatives across the Data Security Risk Execution (DSRE) portfolio, supporting governance through the Data Security Execution Governance Committee (DSEGC), and ensuring delivery aligns to the Firm's Data Security Strategy, applicable policy requirements, and risk appetite. The program scope includes oversight of data security capabilities including Data Leakage Prevention, Data Discovery, Data Masking, Secure Logging, Encryption at Rest, Encryption in Transit, Post-Quantum Cryptography readiness, API security, identity and access management, anomalous behavior detection, incident management, external website controls, network security, vendor risk management, and third-party data protection. This is a hands-on leadership role requiring close partnership with control owners, delivery leads, Business Unit sponsors, 1LOD/2LOD/3LOD stakeholders, and senior governance forums to drive transparent execution, timely escalation, and sustainable transition of mature capabilities to business-as-usual monitoring. The program is currently in its execution phase but detailed approach and plan for BAU transition yet to be agreed.
Responsibilities
Lead data security risk reduction execution: coordinate delivery across DSRE workstreams, ensuring milestones, action plans, dependencies, and risk-reducing outcomes are clearly defined, tracked, and achieved. Manage governance and executive reporting: prepare high-quality updates for DSEGC and related governance forums, including program status, risks, issues, decisions, metrics, and path-to-green plans. Drive milestone-based delivery plans and BAU transition: establish integrated plans that support control implementation, adoption, operational readiness, evidence capture, and sustainable metrics-based monitoring. Manage cross-program dependencies: partner with related technology, cyber, risk, policy, and business programs to align scope, delivery sequencing, control requirements Strengthen data security metrics and risk reporting: partner with metrics owners to define KPIs, KRIs, thresholds, trends, and executive narratives that demonstrate measurable control effectiveness and risk reduction. Support emerging technology and AI security integration: identify opportunities to improve data protection governance for AI-enabled use cases, external websites, APIs, SaaS platforms, and other evolving data movement channels. Develop program artifacts: maintain charters, roadmaps, stakeholder maps, RAID logs, action trackers, decision logs, program briefs, meeting materials, and executive-level communications. Translate data into actionable insights for senior audiences: analyze program status, delivery trends, control metrics, risks, dependencies Requirements At least 10 years demonstrable project management experience