Lead Cybersecurity Engineer
Role details
Job location
Tech stack
Job description
We're seeking someone to join our Crypto Squad team as a Lead Cybersecurity Engineer in Technology to design, implement, and manage cryptographic infrastructure that secures the Firm's most sensitive data and transactions.
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cybersecurity Engineering position at Director level, which is part of the job family responsible for developing and maintaining secure systems, cryptographic services, and key management solutions to protect Firm assets and ensure compliance with regulatory standards.
Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.
What you'll do in the role:
- Communicate regularly with product leads across the technology organization and discuss opportunities for improvement to existing and future technology solutions.
- Design and maintain cryptographic infrastructure, including Hardware Security Modules (HSMs) and key management platforms.
- Implement and manage encryption key lifecycle processes (generation, rotation, archival, destruction) aligned with Firm security standards.
- Integrate cryptographic services with enterprise applications using protocols such as KMIP and PKCS#11.
- Collaborate with cybersecurity, risk, and compliance teams to ensure adherence to regulatory and internal control requirements.
- Troubleshoot and resolve complex issues related to cryptographic systems and secure credential vaults.
- Maintain documentation, assist customers through FAQ entries and similar
- Drive automation and process improvements for certificate and key management workflows.
- Provide technical leadership and mentorship to team members on cryptographic best practices and emerging technologies.
Requirements
Do you have experience in UNIX?, * Ability to effectively manage multiple functions or guide junior staff and initiatives.
- Advanced understanding of business line and discipline with some knowledge of competitive environment and other disciplines.
- Ability to design and implement cryptographic solutions that meet enterprise security and compliance standards.
- Understanding of encryption key lifecycle management, including generation, rotation, archival, and destruction.
- Experience in managing Hardware Security Modules (HSMs) and key management platforms such as CipherTrust Manager and Luna HSM.
- Ability to integrate cryptographic services with enterprise applications using protocols like KMIP and PKCS#11.
- Understanding of regulatory requirements and risk controls related to cryptographic infrastructure.
- Experience in automation and scripting (e.g., PowerShell, Python) for operational efficiency.
- Proficiency in Linux or other Unix variant.
- Experience/Knowledge with Observability tools such as Prometheus and Grafana.
- At least 6 years' relevant experience would generally be expected to find the skills required for this role.