Detection Engineer, Associate/Director (Assistant VP)

morgan stanley

Singapore

On-site

SGD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Morgan Stanley in Singapore is seeking a detection engineer with a threat hunting mindset to join a global team. You will develop and maintain detection logic across endpoints, network, and telemetry sources, using Python to build automation and enrich security data.

You will translate threat intelligence into practical detection strategies, work with Sigma, YARA, ElasticSearch, Git, and related platforms, and collaborate with threat intel and incident response teams to improve coverage and

Qualifications

  • Min 3 years of hands‑on experience in cybersecurity, threat intelligence, threat hunting, detection engineering, security engineering, or related field.
  • Strong Python development skills with the ability to write maintainable code, work with APIs, process data, automate workflows, and troubleshoot issues.
  • Practical experience analyzing security data, logs, alerts, or telemetry to identify suspicious activity or understand adversary behavior.
  • Familiarity with detection engineering concepts, including detection logic, rule tuning, alert quality, false‑positive reduction, and detection validation.
  • Working knowledge of adversary tactics, techniques, and procedures, including converting behavior into detection opportunities.
  • Experience with ElasticSearch, Sigma, YARA, Git, SIEM platforms, EDR telemetry, or similar systems.
  • Ability to translate threat intelligence into hunting or detection opportunities and to communicate findings clearly.

Responsibilities

  • Develop, test, tune, and maintain detection logic across endpoints, networks, identities, and telemetry sources.
  • Translate adversary behaviors and threat intel into practical detection coverage.
  • Use Python to build automation, parse and enrich security data, and support tooling workflows.
  • Work with Sigma, YARA, ElasticSearch, Git, Python, and related platforms to create and maintain detection content.
  • Investigate signals to understand attacker behavior and improve detection coverage.
  • Collaborate with threat intel, incident response, purple team, and platform engineering stakeholders.
  • Research emerging adversary tradecraft and attack patterns relevant to the Firm’s threat landscape.
  • Map detection opportunities to MITRE ATT&CK and related frameworks.
  • Contribute to peer reviews of detection logic, Python code, and automation changes for quality and consistency.
  • Help improve detection-as-code practices, testing processes, and engineering standards.
  • Continue building depth in detection engineering, threat hunting, and financial-sector cyber threats.

Skills

Python
Threat hunting
Cybersecurity
Detection engineering
Threat intelligence
Analytics

Tools

ElasticSearch
Sigma
YARA
Git
SIEM
EDR

Job description

Threat Hunt and Cyber Detection (THCD) is looking for a detection engineer with a threat hunting mindset to join our global team in Singapore. The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets. As a Threat Hunt team member, you will focus on developing and maintaining detections, analyzing adversary behavior, improving security telemetry, and enhancing bespoke tools used to defend the Morgan Stanley network.

What You’ll Do In The Role
  • Develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources.
  • Translate adversary behaviors, threat intelligence, and hunt hypotheses into practical detection strategies and measurable detection coverage.
  • Use Python to build automation, parse and enrich security data, support detection engineering workflows, and improve bespoke threat hunting and detection tools.
  • Work with technologies such as Sigma, YARA, ElasticSearch, Git, Python, and related security analytics platforms to create and maintain detection content.
  • Investigate security signals and suspicious activity to understand attacker behavior, validate detection quality, and identify opportunities for improved coverage.
  • Collaborate with threat intelligence, incident response, purple team, and platform engineering stakeholders to improve detection fidelity and reduce false positives.
  • Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and campaigns relevant to the Firm’s threat landscape.
  • Map detection opportunities and hunting activity to adversary tactics, techniques, and procedures, including frameworks such as MITRE ATT&CK.
  • Contribute to peer reviews of detection logic, Python code, hunt hypotheses, investigation notes, and automation changes to improve quality, maintainability, and consistency.
  • Help improve the team’s detection-as-code practices, testing processes, documentation, and engineering standards.
  • Continue building technical depth in detection engineering, threat hunting, security analytics, adversary infrastructure, and financial-sector cyber threats.
What You’ll Bring To The Role
  • Min 3 years of hands‑on experience in cybersecurity, threat intelligence, threat hunting, detection engineering, security engineering, software engineering in a security context, incident response, blue teaming, or a related field.
  • Strong Python development skills, including the ability to write maintainable code, work with APIs, process structured and unstructured data, automate workflows, and troubleshoot issues independently.
  • Practical experience analyzing security data, logs, alerts, or telemetry to identify suspicious activity or understand adversary behavior.
  • Familiarity with detection engineering concepts, including detection logic, rule tuning, alert quality, false‑positive reduction, and detection validation.
  • Working knowledge of adversary tactics, techniques, and procedures, including how attacker behavior can be converted into detection opportunities.
  • Experience with tools or technologies such as ElasticSearch, Sigma, YARA, Git, SIEM platforms, EDR telemetry, threat intelligence platforms, or similar systems.
  • Ability to understand threat intelligence reporting and translate relevant behaviors, indicators, and infrastructure patterns into hunting or detection opportunities.
  • Strong analytical thinking, attention to detail, and the ability to explain technical findings clearly to both technical and non‑technical stakeholders.
  • Ability to gather requirements from stakeholders and turn operational or investigative needs into practical, maintainable technical solutions.
  • Curiosity about attacker behavior, security data, and how to build scalable tools and detections that improve cyber defense outcomes.
Skills That Would Be Useful But Are Not Required
  • Experience writing or maintaining detections as code.
  • Exposure to threat hunting, cyber threat intelligence, malware analysis, adversary emulation, purple‑team exercises, or threat‑informed defense.
  • Familiarity with adversary infrastructure hunting, including command‑and‑control infrastructure, domain and hosting patterns, phishing infrastructure, botnet infrastructure, or attacker use of legitimate services.
  • Exposure to cloud platforms such as AWS, GCP, or Azure, including cloud logs, security controls, or common cloud attack paths.
  • Relevant cybersecurity certifications.
What You Can Expect From Morgan Stanley

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values – putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back – aren’t just beliefs, they guide the decisions we make every day to do what’s best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work‑life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move around the business for those who show passion and grit in their work.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer, Director (Assistant VP)
Senior Detection Engineer, Director (Assistant VP)

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Senior Detection Engineer, Director (Assistant VP)
Senior Detection Engineer, Director (Assistant VP)

23 MS Mgmt Service (SGP) Pte Ltd • Singapore

On-site
SGD 120,000 - 200,000
Detection Engineer, Associate/Director (Assistant VP)
Detection Engineer, Associate/Director (Assistant VP)

PowerToFly • Singapore

On-site
SGD 70,000 - 90,000
Comprehensive benefits
Career growth opportunities
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

23 MS Mgmt Service (SGP) Pte Ltd • Singapore

On-site
SGD 120,000 - 200,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

Morgan Stanley • Singapore

On-site
SGD 120,000 - 180,000
Threat Detection Engineer: Hunt & Automate Detections
Threat Detection Engineer: Hunt & Automate Detections

morgan stanley • Singapore

On-site
SGD 90,000 - 130,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

PowerToFly • Singapore

On-site
SGD 90,000 - 150,000
Director Platform Engineer - Cyber Threat Hunt
Director Platform Engineer - Cyber Threat Hunt

Morgan Stanley • Singapore

On-site
SGD 70,000 - 90,000
Comprehensive benefits
Career growth opportunities
Vice President, Threat Detection Engineer
Vice President, Threat Detection Engineer

SGX Group • Singapore

On-site
SGD 180,000 - 280,000