Senior Detection Engineer, Director (Assistant VP)

23 MS Mgmt Service (SGP) Pte Ltd

Singapore

On-site

SGD 120,000 - 200,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Morgan Stanley is seeking an experienced Threat Hunt and Cybersecurity Defense senior engineer in Singapore. You will design, build, and maintain detections; hunt for adversary infrastructure, and translate findings into scalable security tooling and surveillance capabilities.

You will automate workflows with Python, enrich security data, and collaborate with incident response, threat intelligence, and purple teams to strengthen proactive defense.

Qualifications

  • 7+ years of hands-on experience in detection engineering, threat hunting, or related cybersecurity fields.
  • Strong cyber technical knowledge of adversary tactics, techniques, and procedures and malware behavior.
  • Experience in at least one focus area: adversary infrastructure hunting or malware analysis/reverse engineering.

Responsibilities

  • Design, develop, test, and maintain detection logic across endpoints, network, identity, and telemetry sources.
  • Hunt for adversary infrastructure, tooling, C2 patterns, phishing infrastructure, and attacker abuse of legitimate services.
  • Translate findings into practical detection strategies and high-coverage detections; automate workflows and tooling.
  • Use Python to automate analysis, enrich security data, and build investigative workflows leveraging internal/external APIs.
  • Collaborate with threat intelligence, incident response, and purple team stakeholders to convert findings into detections.
  • Provide technical guidance through code reviews, documentation, and knowledge sharing.

Skills

Python
Threat hunting
Malware analysis
Reverse engineering
Security engineering
Incident response
Detection engineering
Adversary infrastructure hunting

Tools

APIs

Job description

The Threat Hunt and Cybersecurity Defense (THCD) is looking for an experienced detection engineer with strong cyber technical skills, Python development experience, and depth in either adversary infrastructure hunting or malware analysis and reverse engineering to join our global team in Singapore. The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets. As a senior Threat Hunt team member, you will design, build, and maintain detections; hunt for adversary infrastructure, tools, and behaviors; translate technical findings into scalable detections, proactive surveillance capabilities, and security tooling that improve the Firm's ability to identify and respond to emerging threats; automate investigative workflows; and enhance bespoke tools used to defend the Morgan Stanley network. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cybersecurity Engineer position at Director level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role
  • Design, develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources.
  • Hunt for adversary infrastructure, tooling, command-and-control patterns, phishing infrastructure, staging infrastructure, and attacker abuse of legitimate services.
  • Translate infrastructure, tooling, malware analysis and reverse engineering findings, hunt hypotheses, and investigative findings into practical detection strategies and measurable detection coverage.
  • Use Python to automate analysis, enrich security data, build investigative workflows, integrate with internal and external APIs, and improve bespoke threat hunting and detection tools.
  • Build and maintain tooling that helps analysts and engineers process large data sets, identify infrastructure and tooling patterns, validate detection ideas, reduce manual effort, and accelerate investigation outcomes.
  • Analyze security telemetry and suspicious activity to understand attacker behavior, validate detection quality, identify coverage gaps, and recommend engineering improvements.
  • Apply adversary infrastructure hunting or malware analysis and reverse engineering expertise to identify detection opportunities, improve investigative context, and strengthen proactive surveillance.
  • Work with security analytics platforms, detection-as-code workflows, version control, peer review, and testing practices to improve the quality, maintainability, and reliability of detection content.
  • Collaborate with threat intelligence, incident response, and purple team stakeholders to convert technical findings into high-fidelity detections and proactive surveillance opportunities.
  • Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and tooling relevant to the Firm's threat landscape.
  • Provide technical guidance to junior team members through code reviews, detection reviews, investigation support, documentation, and knowledge sharing.
  • Contribute to engineering standards for detection development, Python tooling, testing, documentation, and operational handover.
  • Help mature the team's approach to threat-informed defense, adversary infrastructure hunting, malware-informed detection, detection validation, and scalable security analytics.
What you'll bring to the role
  • At least 7 years of related hands‑on experience in detection engineering, threat hunting, security engineering, incident response, blue teaming, malware analysis and reverse engineering, security operations engineering, or a related cybersecurity field.
  • Strong cyber technical knowledge, including adversary tactics, techniques, and procedures; enterprise attack paths; common post‑exploitation behaviors; malware and command‑and‑control patterns; identity abuse; endpoint activity; network behavior; and security telemetry.
  • Demonstrated experience in at least one of the following areas: adversary infrastructure hunting, malware analysis and reverse engineering, command-and‑control infrastructure analysis, phishing infrastructure analysis, botnet infrastructure hunting, tooling fingerprinting, or attacker abuse of legitimate services.
  • Strong Python development skills, including the ability to write maintainable code, work with APIs, process structured and unstructured data, automate complex workflows, troubleshoot issues, and build tools used by other security practitioners.
  • Practical experience building automation or tooling for security analysis, detection engineering, threat hunting, incident investigation, data enrichment, infrastructure hunting, tooling fingerprinting, reverse engineering workflows, or operational efficiency.
  • Experience analyzing large volumes of security data, logs, alerts, indicators, telemetry, infrastructure patterns, or tool behaviors to identify suspicious activity and understand adversary behavior.
  • Strong understanding of detection engineering concepts, including detection design, rule tuning, alert quality, coverage analysis, false‑positive reduction, detection validation, and lifecycle management.
  • Ability to translate technical findings from infrastructure hunting, tooling analysis, malware analysis and reverse engineering, and investigations into hunting opportunities, detection logic, surveillance strategies, or automated analysis.
  • Ability to gather requirements from stakeholders and turn investigative, operational, or technical hunting needs into practical technical solutions.
  • Strong written and verbal communication skills, with the ability to explain technical findings, detection logic, and engineering trade‑offs to both technical and non‑technical stakeholders.
  • Curiosity, analytical rigor, attention to detail, and a desire to build scalable tools and detections that improve cyber defense outcomes.
Skills that would be useful but are not required
  • Exposure to adversary emulation, purple‑team exercises, red‑team collaboration, or threat‑informed defense.
  • Experience designing dashboards, notebooks, data pipelines, enrichment services, or internal tools for security analysts and investigators.
  • Relevant cybersecurity certifications.
What you can expect from Morgan Stanley

At Morgan Stanley, we raise, manage and allocate capital for our clients - helping them reach their goals. We do it in a way that is differentiated - and we've done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work. To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

Morgan Stanley is an equal opportunity employer

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

At Morgan Stanley, we advise, originate, trade, manage and distribute capital for people, governments and institutions, always with a standard of excellence and guided by our core values. Morgan Stanley is dedicated to providing first-class service to our clients, in a way that reflects our commitment to creating a more sustainable future and fostering stronger communities around the world. In each line of business, we strive to demonstrate our belief in the power of transformative thinking, innovative strategies and leading-edge solutions-and in the ability of capital to work for the benefit of all society.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer, Director (Assistant VP)
Senior Detection Engineer, Director (Assistant VP)

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Detection Engineer, Associate/Director (Assistant VP)
Detection Engineer, Associate/Director (Assistant VP)

morgan stanley • Singapore

On-site
SGD 90,000 - 130,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

Morgan Stanley • Singapore

On-site
SGD 120,000 - 180,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

PowerToFly • Singapore

On-site
SGD 90,000 - 150,000
Detection Engineer, Associate/Director (Assistant VP)
Detection Engineer, Associate/Director (Assistant VP)

PowerToFly • Singapore

On-site
SGD 70,000 - 90,000
Comprehensive benefits
Career growth opportunities
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

23 MS Mgmt Service (SGP) Pte Ltd • Singapore

On-site
SGD 120,000 - 200,000
Threat Detection Engineer: Hunt & Automate Detections
Threat Detection Engineer: Hunt & Automate Detections

morgan stanley • Singapore

On-site
SGD 90,000 - 130,000
Trade support Group Operations, Director(Assistant VP)
Trade support Group Operations, Director(Assistant VP)

Morgan Stanley • Singapore

On-site
SGD 180,000 - 300,000
Cyber Intelligence Vice President, Malware Reverse Engineer
Cyber Intelligence Vice President, Malware Reverse Engineer

Fairygodboss • Singapore

On-site
SGD 250,000 - 350,000