Jobs and Careers
MO

Assoc, P2, Cybersecurity Ops II : Job Level - Associate

Morgan Stanley
United Statesfull_timeVerifiedPosted 8 Apr 2025

About the role

Business Information Security & Risk Management (BISRM) Team Profile

BISRM team enables the Business and Technology to form a holistic view of identified risk and collaboratively make risk-based decisions in mitigating the risk to the firm while still enabling and ensuring velocity for the business. In addition to advising Technology Senior Managers on their risk posture, the team is also responsible in enabling Technology divisions to proactively embed and align security, governance and compliance through the implementation of solutions based on the firm’s security policies and controls.  The team advise on the firm’s Technology Policy & Standards, perform risk assessments and tests of controls, and deliver risk-reporting capabilities. The team handles responses to regulatory, audit, and client inquiries about the Firm's technology risk, control framework, and fulfil Technology Risk Governance Committee responsibilities.

The Security Architecture & Design Associate is responsible for assisting with improving the overall security posture of Morgan Stanley Investment Management.  The successful candidate will assist with Security and Identity Access Management (IAM) operational support.  The candidate will assist with the application Security Architecture process and the development of Security AWS/Azure Cloud Control tables.  The candidate will also evaluate, test and document security solutions and controls, and work closely with other department members within Business Information Security & Risk Management “BISRM” and Cyber Data Risk & Resiliency “CDRR” to remediate risk while ensuring the business is able to innovate and meet its business objectives through the implementation of technology initiatives.

The Information Security Architecture & Design Associate must continually adapt to stay a step ahead of potential risks.  This is not a passive career opportunity, but rather one that requires a passion for security and risk mitigation to protect the business. The candidate will collaborate with internal and external audit and exam teams, along with technology management and business stakeholders.

Essential Job Duties:

  • Partner with MSIM Technology and Business developers & engineers to understand business initiatives and assist in delivering secure on premise & in the cloud infrastructure through the alignment to the Morgan Stanley Security and IAM Control policies.
  • Assist MSIM Technology and Business developers & engineers through the Security Design tollgates of obtaining Permit to Build and Permit to Operate by engaging Security Design Analysts and quickly remediating issues with the goal of mitigating the risks to the firm but enabling the business on a timely basis.
  • Fully understand the Morgan Stanley AWS/Azure Security Cloud Control table and Security Design Processes and apply the knowledge to train developers in understanding the concepts and processes of secure development of on premise, in the cloud and SaaS solutions. 
  • Provide Certificate Management support
  • Participate in technical and non-technical projects to ensure policies, procedures and standards are met.
  • Interface with internal and external auditors for risk assessments.
  • Recommend new security solutions as well as effective improvements to existing security controls that do not negatively impact business innovation.

Skills and Experience

  • At least 5-10 years of information security experience with the focus on application and infrastructure focus
  • Knowledge in cloud security regarding infrastructure and application development within AWS and Azure platforms
  • Expertise in incident response and system monitoring and analysis.
  • Experience with compliance requirements and Audit engagements (GLBA, SOX, SOC, regulatory agencies, and Internal Audit etc.).
  • Ability to effectively communicate business risk as it relates to information security.
  • Experience in conducting risk assessments that protect the business and adhere with compliance and privacy laws.
  • Knowledge of multiple computing platforms, including Keyfactor, Sectigo, Security Design tools, Windows, OSX, Linux, Unix, networks, and endpoints.
  • Experience with vulnerability and penetration testing processes and tools including Nessus, Rapid 7 or Qualys.
  • Experience with configuration management, change management, project management methodologies and tools including Cherwell or ServiceNow.

Additional Qualifications

  • Possesses highly effective communications skills with the ability to influence business units.
  • Acts with integrity, takes pride in work and seeks to excel, be curious and adaptable.
  • Displays an analytical and problem-solving mind-set.
  • Is highly organized and efficient.
  • Leverages strate

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Morgan Stanley

View company profile →