Lead Application Security Eng
Role details
Job location
Tech stack
Job description
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Application Security Engineering position at the Vice President level, which is part of the job family responsible for providing specialist data analysis and expertise that drive decision-making and business insights as well as crafting data pipelines, implementing data models, and optimizing data processes for improved data accuracy and accessibility, including applying machine learning and AI-based techniques., * This role will provide hands-on leadership for a team of 4+ engineers responsible for designing secure systems, performing technical analysis, and delivering scalable solutions that support secure software delivery.
- The Team Lead will partner closely with stakeholders across Technology and Cybersecurity to define standards, guide implementation, and maintain integrated application security capabilities.
- The role requires strong communication skills and the ability to translate security risks, strategy, and technical solutions for both engineering teams and senior stakeholders.
Requirements
- 10+ years of IT experience, including 7+ years in Application Security.
- Strong knowledge of SDLC standards, SAST, SCA/OSS, DAST, container scanning, security vulnerabilities, cyber incidents, penetration testing tools, and security frameworks.
- Experience designing and integrating application security capabilities into CI/CD pipelines.
- Ability to define, track, and report key security metrics to stakeholders.
- Hands-on experience developing event-driven applications using Python, PostgreSQL, MongoDB, and Kafka.
- Experience conducting security reviews and validating architecture and engineering designs for security.
- Proven leadership, stakeholder management, analytical, and problem-solving skills.
- Strong understanding of cyber technologies and their integration in large-scale enterprise environments.
- Ability to present, discuss, and challenge design and architecture decisions with confidence.
- Strong communication and partnership skills, including the ability to collaborate with cross-functional teams and engage senior stakeholders on risks, strategy, and solutions., * Experience using AI tools effectively to accelerate delivery.
- Knowledge of cyber domains including Data Protection, Cryptography, Network Security, Web Application Firewalls, and Identity and Access Management.
- Understanding of web protocols including TCP/IP, HTTP, and SSL/TLS.
Benefits & conditions
Expected base pay rates for the role will be between $125,000 and $175,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs.
Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.
Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.