Assistant VP (Engineering) - Morgan Stanley

Morgan Stanley

Singapore

On-site

SGD 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Training and development opportunities

Job summary

Morgan Stanley is seeking a Detection Engineer for its Threat Hunt and Cyber Detection (THCD) team in Singapore. You will develop and maintain detections across endpoints, network, and telemetry, translating adversary behavior into practical detection strategies.

You will leverage Python for automation and collaborate with threat intelligence, incident response, and platform engineering teams. The role emphasizes building scalable detections, improving telemetry, and reducing false positives

Qualifications

  • 3+ years hands-on cybersecurity experience in threat hunting/detection engineering or related field.

Responsibilities

  • Develop, test, tune, and maintain detection logic across endpoints, network, identity, and telemetry sources.
  • Translate adversary behaviors and threat intel into practical detection strategies and coverage.
  • Use Python to build automation, parse and enrich security data, and support detection workflows.
  • Work with ElasticSearch, Sigma, YARA, Git and related platforms to create and maintain detection content.
  • Investigate signals to understand attacker behavior and improve coverage and reduce false positives.
  • Collaborate with threat intel, incident response, and platform engineering to improve detection fidelity.
  • Research adversary tradecraft, malware behavior, command-and-control patterns relevant to the Firm.
  • Map detection opportunities to MITRE ATT&CK techniques and update detection against evolving threats.
  • Contribute to peer reviews of detection logic, code, and documentation to improve quality.
  • Help improve detection-as-code practices, testing, and engineering standards.
  • Continue building depth in detection engineering, threat hunting, and financial-sector threats.

Skills

Python development
Threat hunting
Data analysis
Communication
Problem solving
Independent工作

Tools

ElasticSearch
Sigma
YARA
Git
SIEM
EDR telemetry
Threat intel platforms

Job description

Threat Hunt and Cyber Detection (THCD) is looking for a detection engineer with a threat hunting mindset to join our global team in Singapore. The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets. As a Threat Hunt team member, you will focus on developing and maintaining detections, analyzing adversary behavior, improving security telemetry, and enhancing bespoke tools used to defend the Morgan Stanley network.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.

Since 1935, Morgan Stanley has been known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

At Morgan Stanley Singapore, we serve as the Firm's Southeast Asia headquarters and regional hub, supporting Morgan Stanley's businesses across the region. Morgan Stanley has had a presence in Singapore since 1990, and our Singapore office provides capabilities across investment banking, equity and fixed income research, securities trading, derivatives, commodities, private wealth management, and investment management. Located at IOI Central Boulevard Towers in downtown Singapore, our Southeast Asia headquarters provides a world-class work environment, advanced technology infrastructure, and collaborative facilities that help our teams deliver best-in-class services and solutions for clients. Everyone is encouraged to chart their own meaningful career and achieve goals with the support of our training, development, and global collaboration opportunities.

What you'll do in the role:
  • Develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources.
  • Translate adversary behaviors, threat intelligence, and hunt hypotheses into practical detection strategies and measurable detection coverage.
  • Use Python to build automation, parse and enrich security data, support detection engineering workflows, and improve bespoke threat hunting and detection tools.
  • Work with technologies such as Sigma, YARA, ElasticSearch, Git, Python, and related security analytics platforms to create and maintain detection content.
  • Investigate security signals and suspicious activity to understand attacker behavior, validate detection quality, and identify opportunities for improved coverage.
  • Collaborate with threat intelligence, incident response, purple team, and platform engineering stakeholders to improve detection fidelity and reduce false positives.
  • Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and campaigns relevant to the Firm's threat landscape.
  • Map detection opportunities and hunting activity to adversary tactics, techniques, and procedures, including frameworks such as MITRE ATT&CK.
  • Contribute to peer reviews of detection logic, Python code, hunt hypotheses, investigation notes, and automation changes to improve quality, maintainability, and consistency.
  • Help improve the team's detection-as-code practices, testing processes, documentation, and engineering standards.
  • Continue building technical depth in detection engineering, threat hunting, security analytics, adversary infrastructure, and financial-sector cyber threats.
What you'll bring to the role:
  • Min 3 years of hands-on experience in cybersecurity, threat intelligence, threat hunting, detection engineering, security engineering, software engineering in a security context, incident response, blue teaming, or a related field.
  • Strong Python development skills, including the ability to write maintainable code, work with APIs, process structured and unstructured data, automate workflows, and troubleshoot issues independently.
  • Practical experience analyzing security data, logs, alerts, or telemetry to identify suspicious activity or understand adversary behavior.
  • Familiarity with detection engineering concepts, including detection logic, rule tuning, alert quality, false-positive reduction, and detection validation.
  • Working knowledge of adversary tactics, techniques, and procedures, including how attacker behavior can be converted into detection opportunities.
  • Experience with tools or technologies such as ElasticSearch, Sigma, YARA, Git, SIEM platforms, EDR telemetry, threat intelligence platforms, or similar systems.
  • Ability to understand threat intelligence reporting and translate relevant behaviors, indicators, and infrastructure patterns into hunting or detection opportunities.
  • Strong analytical thinking, attention to detail, and the ability to explain technical findings clearly to both technical and non-technical stakeholders.
  • Ability to gather requirements from stakeholders and turn operational or investigative needs into practical, maintainable technical solutions.
  • Curiosity about attacker behavior, security data, and how to build scalable tools and detections that improve cyber defense outcomes.

Skills that would be useful but are not required:

  • Experience writing or maintaining detections as code.
  • Exposure to threat hunting, cyber threat intelligence, malware analysis, adversary emulation, purple-team exercises, or threat-informed defense.
  • Familiarity with adversary infrastructure hunting, including command-and-control infrastructure, domain and hosting patterns, phishing infrastructure, botnet infrastructure, or attacker use of legitimate services.
  • Exposure to cloud platforms such as AWS, GCP, or Azure, including cloud logs, security controls, or common cloud attack paths.
  • Relevant cybersecurity certifications.
What you can expect from Morgan Stanley

At Morgan Stanley, we raise, manage and allocate capital for our clients - helping them reach their goals. We do it in a way that's differentiated - and we've done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients - helping them reach their goals. We do it in a way that's differentiated - and we've done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer, Director (Assistant VP) at Morgan Stanley
Senior Detection Engineer, Director (Assistant VP) at Morgan Stanley

Morgan Stanley • Singapore

On-site
SGD 180,000 - 260,000
Senior Detection Engineer, Director (Assistant VP)
Senior Detection Engineer, Director (Assistant VP)

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Detection Engineer, Associate/Director (Assistant VP)
Detection Engineer, Associate/Director (Assistant VP)

morgan stanley • Singapore

On-site
SGD 90,000 - 130,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

PowerToFly • Singapore

On-site
SGD 90,000 - 150,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

Morgan Stanley • Singapore

On-site
SGD 120,000 - 180,000
Detection Engineer, Associate/Director (Assistant VP)
Detection Engineer, Associate/Director (Assistant VP)

PowerToFly • Singapore

On-site
SGD 70,000 - 90,000
Comprehensive benefits
Career growth opportunities
Assistant VP, Threat Detection Engineering
Assistant VP, Threat Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 90,000 - 130,000
Training and development opportunities
Director of Threat Hunt & Detection Engineering
Director of Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 260,000
AI Security Developer, Vice President, Cybersecurity Engineering
AI Security Developer, Vice President, Cybersecurity Engineering

Morgan Stanley • Singapore

On-site
SGD 260,000 - 380,000
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000