> Markdown version of [/jobs/ext/1504792-senior-security-architecture-specialist](https://www.wearedevelopers.com/jobs/ext/1504792-senior-security-architecture-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Architecture Specialist - **Company:** Morgan Stanley - **Location:** Alpharetta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Data Analysis, Code Review, Cyber Security, DevOps, Github, Gradle, Python (Programming Language), Apache Maven, Windows PowerShell, Systems Development Life Cycle, Cloud Services, Policy as Code, Sonatype, Software Security, Build Management, Kubernetes, Infrastructure Automation Frameworks, Puppet, Docker, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=79ae9ae8d65f4f99 ## About the Role * Bachelor's degree with 7+ years of work experience in the IT field or equivalent. * Demonstrated experience designing and governing SDLC security controls at scale - SAST, SCA, OSS governance, and container scanning. * Hands-on experience with policy as code frameworks (OPA, Sentinel, or equivalent) and the ability to review and write policies, not just evaluate vendor tooling. * Experience producing architecture decision records, threat models, or equivalent design governance artifacts that served as authoritative references for engineering teams. * Strong written and verbal communication, ability to translate architecture decisions into compliance traceability artifacts and executive-facing recommendation documents. * Track record of driving adoption through influence. * Strong scripting background (Python, PowerShell). Desired Skills: * A degree in Cybersecurity and/or CISSP/CSSLP certification and keen desire to move to security field. * Business acumen to support the implementation of SAST, DAST, SCA, Container Security, API Security and IaC tools across the enterprise. * Ability to perform code reviews with minimal assistance. * A self-starter, with a strong desire for learning new technologies and applying them to solve problems. * Expertise in monitoring, alerting, reporting, and data analysis. * Experience with two or more of the application build environments like Jenkins, Gradle, Maven. * Familiarity with public cloud services. * Experience with two or more of the Secure SDLC tools like GitHub Advanced Security, Snyk, WhiteSource, Sonatype, X-Ray, Wiz. * Experience with Threat Analysis. * DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc.). * Experience with evaluation, integration and onboard of application security tools. ## Description In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Senior Security Architecture Specialist position at Vice President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities., We're seeking someone to join our team as a Senior Security Architecture Specialist in Cyber to be responsible for the security design tooling and security architecture standards across the firm - translating compliance obligations into operable, developer friendly architecture patterns, while directly operating the design governance toolchain that makes those standards real. What you'll do in the role: Architecture governance * Steward the security architecture standard across all verticals - ADRs, threat models, trust boundaries, and control plane design * Produce compliance traceability artifacts mapping architecture decisions to compliance requirements * Drive cross team architecture through influence with principal engineers and engineering leads * Support security standards, create templates and patterns to increase the efficiency and adoption of security programs. Living Spec & Design Governance * Operate and evolve the design governance toolchain * Define the ADR lifecycles from creation to deprecation and ensure decision records remain the authoritative reference for architecture choices * Build integrations between spec platform and dev tooling to make compliance traceability continuous, not periodic ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)