Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk ...
Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk ...
Tech Risk Testing Director
Alpharetta, GA · On-site
Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk ...
Tech Risk Testing Director
Alpharetta, GA · On-site
Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk ...
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
Leads development of an information security risk management program that includes business, regulatory, industry practices and technical environment considerations * Establishes strategic vendor ...
Leads development of an information security risk management program that includes business, regulatory, industry practices and technical environment considerations * Establishes strategic vendor ...
Risk Management & Administrative Specialist
Ellabell, GA · On-site
$59K - $62K/yr
Information Security: Manage all departmental documentation in strict accordance with the corporate ... Bachelor's degree in Business Administration, Risk Management, Human Resources, or a closely ...
Quick apply
Risk Management & Administrative Specialist
Ellabell, GA · On-site
$59K - $62K/yr
Information Security: Manage all departmental documentation in strict accordance with the corporate ... Bachelor's degree in Business Administration, Risk Management, Human Resources, or a closely ...
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
Compliance and Risk Management : * Ensure compliance with all relevant laws, regulations, and industry standards. * Oversee security risk assessments and implement appropriate mitigation measures.
Compliance and Risk Management : * Ensure compliance with all relevant laws, regulations, and industry standards. * Oversee security risk assessments and implement appropriate mitigation measures.
This executive will define and execute Candescent's enterprise-wide security, compliance, and risk management strategy, ensuring regulatory alignment (FFIEC, SOC2, ISO 27001, PCI-DSS), securing the ...
This executive will define and execute Candescent's enterprise-wide security, compliance, and risk management strategy, ensuring regulatory alignment (FFIEC, SOC2, ISO 27001, PCI-DSS), securing the ...
Be Seen First
Bank Information Security Manager
Atlanta, GA · On-site
$70 - $80/hr
... IT management, cyber security, security risk assessment, protecting sensitive data, and maintaining integrity of systems within the banking industry. A CISSP, CISM, or CISA Certification is ...
Quick apply
Be Seen First
Bank Information Security Manager
Atlanta, GA · On-site
$70 - $80/hr
... IT management, cyber security, security risk assessment, protecting sensitive data, and maintaining integrity of systems within the banking industry. A CISSP, CISM, or CISA Certification is ...
Support security audits, compliance reviews, and risk-management activities, delivering required documentation and remediation follow-up. * Participate in or lead incident response activities and ...
Support security audits, compliance reviews, and risk-management activities, delivering required documentation and remediation follow-up. * Participate in or lead incident response activities and ...
Experience with using and configuring Oracle Risk Management Cloud GRC solution (RMC). Proficiency ... Experience with other ERP security would be nice to have. * Demonstrated knowledge of auditing ...
Experience with using and configuring Oracle Risk Management Cloud GRC solution (RMC). Proficiency ... Experience with other ERP security would be nice to have. * Demonstrated knowledge of auditing ...
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Quick apply
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Principal Product Security Engineer
Columbus, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Columbus, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Quick apply
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Principal Product Security Engineer
Atlanta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Atlanta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Macon, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Macon, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Quick apply
Be Seen First
Director of IT & Security
Atlanta, GA · On-site
Information Security & Risk Management * Lead the cybersecurity program, including policies ... controls, monitoring tools, security awareness, and incident response. * Identify and mitigate ...
Principal Product Security Engineer
Athens, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Athens, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Lawrenceville, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Lawrenceville, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Valdosta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Valdosta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Security Risk Management information
See Georgia salary details
$8.73 - $13.30
2% of jobs
$13.30 - $17.88
0% of jobs
$17.88 - $22.46
1% of jobs
$22.46 - $27.03
1% of jobs
$27.03 - $31.61
1% of jobs
$35.04 is the 25th percentile. Wages below this are outliers.
$31.61 - $36.18
26% of jobs
$36.18 - $40.76
11% of jobs
The median wage is $42.40 / hr.
$40.76 - $45.34
22% of jobs
$45.34 - $49.91
9% of jobs
$50.27 is the 75th percentile. Wages above this are outliers.
$49.91 - $54.49
17% of jobs
$54.49 - $59.07
9% of jobs
$8
$42
$59
How much do security risk management jobs pay per hour?
What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?
What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?
What is Security Risk Management?
What is the difference between Security Risk Management vs Security Analyst?
| Aspect | Security Risk Management | Security Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Strategic, policy-focused, risk assessment | Operational, monitoring, incident response |
| Employer & Industry Usage | Organizations managing enterprise security risks | Security teams, cybersecurity firms, IT departments |
Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.
- Security Analyst Part Time
- Senior Security Consultant
- Industrial Security
- Director Offensive Security Engineer
- Experienced Information Security Manager
- Information Technology Security Analyst
- Security Risk Compliance
- Protective Security Specialist
- Business Information Security Officer Biso
- Third Party Risk Analyst Remote
Morgan Stanley rating
8.3
Based on 147 frontline employees who took The Breakroom Quiz
37th of 138 rated financial services
Job description
Morgan Stanley is a leading global financial services firm providing a wide range of investment banking, securities, investment management and wealth management services. The Firm's employees serve clients worldwide including corporations, governments, and individuals from more than 1,200 offices in 43 countries.
As a market leader, the talent and passion of our people is critical to our success. Together, we share a common set of values rooted in integrity, excellence, and strong team ethic. Morgan Stanley can provide a superior foundation for building a professional career - a place for people to learn, to achieve and grow. A philosophy that balances personal lifestyles, perspectives and needs is an important part of our culture.
The cornerstone of Morgan Stanley's risk management philosophy is the execution of risk-adjusted returns through prudent risk-taking that protects Morgan Stanley's capital base, liquidity and franchise. Non-Financial Risk (NFR) refers to the risk of actual or potential economic, reputational, regulatory, financial reporting and client impact, resulting from inadequate or failed internal processes, people, and systems, or from external events impacting the full scope of its business activities, including revenue-generating activities and infrastructure groups. NFR is part of the Second Line of Defense providing independent oversight and challenge to management across compliance and operational risks. Given the nature and breadth of operational risk, operational risks are managed at multiple levels e.g. Firmwide, as well as Regional, Business Unit, Infrastructure Group, Control Function and Legal Entity.
The NFR Cyber, Technology and Information Security (CTIS) Department is focused specifically on managing cyber, technology and information security risks. NFR CTIS brings together rules management, standard setting, assessing risk, process and controls by technology domains, advising the business, and an oversight and testing function to provide a comprehensive risk management decision for cyber, technology and information security related risks. Cybersecurity, Information Security and Technology risk management is critical to ensure the confidentiality, integrity and availability of Firm Information, Systems and Assets. Cybersecurity risk refers to managing and protecting the Firm's information assets and operations from cyber threats, e.g., cyber events or attacks resulting from inadvertent or intentional acts involving deception, falsification, destruction, etc. Information Security risk refers to protecting the confidentiality, integrity and availability of Firm's information and systems, e.g., internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of confidential information and systems. Technology risk refers to ensuring and protecting the availability, stability, capacity and recovery capabilities of the Firm's key systems, e.g., loss, damage or business disruption resulting from inadequate or failed processes, people and systems or from external events.
Morgan Stanley is seeking a Risk professional to join the Non-Financial Risk Cyber, Technology and Information Security (NFR CTIS) Testing Team based in Alpharetta.
The successful candidate will plan and execute full scope and other tests on engagements assigned by Technology Risk Testing Manager. The Technology Risk Testing team is part of the broader Global 2LOD Non-Financial Risk Testing organization. The team plans and executes the Technology Risk annual testing plan.
Primary Responsibilities:
- Assist in the development and maintenance of the annual technology testing plan.
- Develop and deliver engagement announcements.
- Lead engagement kickoff meetings for stakeholders; lead periodic engagement progress updates.
- Execute and document test activities in test workpapers. Test activities may include process deep dives, control design reviews, control effectiveness tests, or outcome-based tests.
- Test execution fieldwork-Perform test activities in accordance with 2L NFR testing standards:
- Interview stakeholders, request and review pertinent policies, standards, procedures, KRI metrics, and other documents, and walk through relevant processes and control environments.
- Develop test scripts and recipe cards.
- Request and validate receipt of relevant data and samples for testing.
- Execute and document test activities in test workpapers.
- Identify and escalate potential test findings.
- Propose action plans and remediation requirements.
- Prepare test reports.
- Track and confirm completion of action plans and their remediation requirements.
- Remain current on industry rules, regulations and best practices to make recommendations to the testing program.
Skills Required:
- Bachelor of Science required with a concentration in Computer Science or Information Technology.
- 8+ years audit/risk/compliance experience in the financial services industry, a regulator, or a self-regulatory organization.
- Experience leading and conducting Technology reviews.
- Investigative skills - inquiry and analysis, interviewing, testing, risk assessment capabilities.
- Ability to research and resolve issues independently while working across teams to acquire information.
- Risk Management Knowledge - strong understanding of financial industry risk and control and the ability to critique relevant language.
- Self-motivated with strong analytical, organization, and problem-solving skills; ability to work independently, demonstrate resourcefulness, and develop well-structured proposals.
- Ability to work effectively in a cross-functional, global team.
- Excellent communication skills, both verbal and written; ability to tailor communication to technical vs non-technical, senior vs junior audiences.
- Proficiency with Microsoft Word, Excel, PowerPoint, Adobe, SharePoint and ability to quickly learn automated systems.
Skills Desired:
- Knowledge of global regulatory requirements like GLBA, GDPR, Part 30 Information Security, NYDFS etc. and technology control standards like NIST, FFIEC, CRI, COBIT, CIS etc.
- Certified Internal Auditor (CIA) or Certified Information Systems Auditor (CISA) or Certified in Risk and Information Systems Control (CRISC) designations are highly desirable.
- Prior experience in Big 4 or equivalent professional services environment, with hands-on responsibility for leading risk-based audits or testing engagements.
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
At Morgan Stanley, we raise, manage and allocate capital for our clients - helping them reach their goals. We do it in a way that's differentiated - and we've done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Morgan Stanley's goal is to build and maintain a workforce that is diverse in experience and background but uniform in reflecting our standards of integrity and excellence. Consequently, our recruiting efforts reflect our desire to attract and retain the best and brightest from all talent pools. We want to be the first choice for prospective employees.
It is the policy of the Firm to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, creed, age, sex, sex stereotype, gender, gender identity or expression, transgender, sexual orientation, national origin, citizenship, disability, marital and civil partnership/union status, pregnancy, veteran or military service status, genetic information, or any other characteristic protected by law.
Morgan Stanley is an equal opportunity employer committed to diversifying its workforce (M/F/Disability/Vet).
What Morgan Stanley employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom