> Markdown version of [/jobs/ext/2695774-cyber-threat-intelligence-technical-analysis-and-investigations-lead-vp](https://www.wearedevelopers.com/jobs/ext/2695774-cyber-threat-intelligence-technical-analysis-and-investigations-lead-vp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Intelligence - Technical Analysis and Investigations Lead - VP - **Company:** Morgan Stanley - **Location:** Baltimore, MD, United States - **Experience:** Expert - **Salary:** $190,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Big Data, Cyber Security, Python (Programming Language), Open Source Technology, Open Source Intelligence, Security Information and Event Management, Jupyter Notebook, Mitre Att&ck, Cyber Threat Analysis, Cybercrime - **Published:** September 3, 2026 - **Apply:** https://www.themuse.com/jobs/morganstanley/cyber-threat-intelligence-technical-analysis-and-investigations-lead-vp ## About the Role * Minimum 5 years of experience in cyber threat intelligence, cyber discovery, or cybersecurity investigations, with a track record leading both teams and technical investigations and producing actionable outcomes. * Expertise in tracking advanced threat actors and malware using frameworks such as MITRE ATT&CK and/or the Diamond Model to characterize campaigns, capabilities, and infrastructure. -Proficiency in Python and scripting to automate investigative workflows and develop analytics (e.g., Jupyter notebooks). * Experience with large-scale data analysis and security telemetry tooling to identify patterns, quantify trends, and support analytic judgments. * Experience with SIEM platforms and interpreting network/endpoint logs to progress investigations from hypothesis to evidence-based conclusions. * Ability to communicate clearly across technical and non-technical audiences, including writing technical reporting and briefing investigative judgments and mitigations. Nice to have : GIAC GCTI, CISSP, CASP certifications ## Description We're seeking someone to join our team as a Cyber Threat Intelligence - Technical Analysis and Investigations Lead in Technology to lead technical threat investigations, track sophisticated adversaries, and operationalize technical intelligence for detection and response. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. Since 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. What you'll do in the role: * Lead proactive threat hunts and advanced discovery to identify adversary campaigns, capabilities, infrastructure, and targets using internal collection, OSINT, and vendor intelligence. Research and track advanced threat actors and malware, maintaining deep technical understanding of adversary TTPs and tradecraft. * Author high-impact technical threat intelligence products and reports tailored to both operational teams and senior stakeholders. * Develop and advance investigative tradecraft, analytic techniques, and automation to improve speed, repeatability, and fidelity of analytic workflows (including Python-based analytics). Enrich, triage, and characterize threat insights and indicators by leveraging open-source and commercial tooling, and curate high-fidelity IOCs for operational use. * Partner with threat hunting and security response teams to translate technical intelligence into detection opportunities, mitigations, and control validation activities. * Maintain and curate threat profiles aligned to areas of responsibility, producing actionable technical intelligence for proactive detection and discovery. {D Part 2: Scope of Role What you'll bring pre-set content based on tier framework + role-specific bullets ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)