Senior Detection Engineer, Director (Assistant VP) at Morgan Stanley

Morgan Stanley

Singapore

On-site

SGD 180,000 - 260,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Morgan Stanley is seeking a senior Threat Hunt Engineer in Singapore for the THCD team. On-site role focusing on designing and maintaining detections, hunting adversary infrastructure, and building security tooling to reduce risk across Morgan Stanley assets.

You will automate investigation workflows, collaborate with analytics and IR teams, and contribute to scalable detection content used across the firm.

Qualifications

  • At least 7 years of hands-on experience in detection engineering, threat hunting, security engineering, incident response, or related cybersecurity fields.
  • Strong cyber technical knowledge, including adversary TTPs, enterprise attack paths, and malware patterns.
  • Experience in adversary infrastructure hunting or malware analysis and reverse engineering.
  • Strong Python development skills for maintainable code and API integration.
  • Automation experience for security analysis and detection tooling.
  • Ability to analyze large volumes of security data to identify suspicious activity.
  • Knowledge of detection engineering concepts and lifecycle management.
  • Ability to translate findings into hunting opportunities and detection logic.
  • Strong written and verbal communication skills for technical stakeholder explanations.
  • Curiosity and attention to detail to build scalable tools.

Responsibilities

  • Design, develop, test, tune, and maintain detection logic across telemetry sources.
  • Hunt for adversary infrastructure, tooling, C2 patterns, phishing infrastructure, and abuse of services.
  • Translate findings into practical detection strategies and coverage.
  • Use Python to automate analysis, enrich data, and improve investigative workflows.
  • Build and maintain tooling to process large data sets and accelerate investigations.
  • Analyze telemetry to understand attacker behavior and detection quality.
  • Apply expertise to identify detection opportunities and strengthen surveillance.
  • Collaborate with threat intelligence, IR, and purple teams to create high-fidelity detections.
  • Research emerging threat tradecraft relevant to Morgan Stanley's threat landscape.
  • Provide technical guidance through code reviews, reviews, and knowledge sharing.

Skills

Threat hunting
Python development
Detection engineering
Security engineering
Incident response
Malware analysis
Reverse engineering
Security operations
Automation
Data analysis

Education

Bachelor's degree in CS or related field

Job description

This Full time on site position offers great opportunities for career growth.

Threat Hunt and Cybersecurity Defense (THCD) is looking for an experienced detection engineer with strong cyber technical skills, Python development experience, and depth in either adversary infrastructure hunting or malware analysis and reverse engineering to join our global team in Singapore.

The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets.

As a senior Threat Hunt team member, you will design, build, and maintain detections; hunt for adversary infrastructure, tools, and behaviors; translate technical findings into scalable detections, proactive surveillance capabilities, and security tooling that improve the Firm's ability to identify and respond to emerging threats; automate investigative workflows; and enhance bespoke tools used to defend the Morgan Stanley network.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.

This is a Cybersecurity Engineer position at Director level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you’ll do in the role
  • Design, develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources.
  • Hunt for adversary infrastructure, tooling, command-and-control patterns, phishing infrastructure, staging infrastructure, and attacker abuse of legitimate services.
  • Translate infrastructure, tooling, malware analysis and reverse engineering findings, hunt hypotheses, and investigative findings into practical detection strategies and measurable detection coverage.
  • Use Python to automate analysis, enrich security data, build investigative workflows, integrate with internal and external APIs, and improve bespoke threat hunting and detection tools.
  • Build and maintain tooling that helps analysts and engineers process large data sets, identify infrastructure and tooling patterns, validate detection ideas, reduce manual effort, and accelerate investigation outcomes.
  • Analyze security telemetry and suspicious activity to understand attacker behavior, validate detection quality, identify coverage gaps, and recommend engineering improvements.
  • Apply adversary infrastructure hunting or malware analysis and reverse engineering expertise to identify detection opportunities, improve investigative context, and strengthen proactive surveillance.
  • Work with security analytics platforms, detection-as-code workflows, version control, peer review, and testing practices to improve the quality, maintainability, and reliability of detection content.
  • Collaborate with threat intelligence, incident response, and purple team stakeholders to convert technical findings into high-fidelity detections and proactive surveillance opportunities.
  • Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and tooling relevant to the Firm's threat landscape.
  • Provide technical guidance to junior team members through code reviews, detection reviews, investigation support, documentation, and knowledge sharing.
  • Contribute to engineering standards for detection development, Python tooling, testing, documentation, and operational handover.
  • Help mature the team's approach to threat-informed defense, adversary infrastructure hunting, malware-informed detection, detection validation, and scalable security analytics.
What you’ll bring to the role
  • At least 7 years of related hands‑on experience in detection engineering, threat hunting, security engineering, incident response, blue teaming, malware analysis and reverse engineering, security operations engineering, or a related cybersecurity field.
  • Strong cyber technical knowledge, including adversary tactics, techniques, and procedures; enterprise attack paths; common post‑exploitation behaviors; malware and command‑and‑control patterns; identity abuse; endpoint activity; network behavior; and security telemetry.
  • Demonstrated experience in at least one of the following areas: adversary infrastructure hunting, malware analysis and reverse engineering, command‑and‑control infrastructure analysis, phishing infrastructure analysis, botnet infrastructure hunting, tooling fingerprinting, or attacker abuse of legitimate services.
  • Strong Python development skills, including the ability to write maintainable code, work with APIs, process structured and unstructured data, automate complex workflows, troubleshoot issues, and build tools used by other security practitioners.
  • Practical experience building automation or tooling for security analysis, detection engineering, threat hunting, incident investigation, data enrichment, infrastructure hunting, tooling fingerprinting, reverse engineering workflows, or operational efficiency.
  • Experience analyzing large volumes of security data, logs, alerts, indicators, telemetry, infrastructure patterns, or tool behaviors to identify suspicious activity and understand adversary behavior.
  • Strong understanding of detection engineering concepts, including detection design, rule tuning, alert quality, coverage analysis, false‑positive reduction, detection validation, and lifecycle management.
  • Ability to translate technical findings from infrastructure hunting, tooling analysis, malware analysis and reverse engineering, and investigations into hunting opportunities, detection logic, surveillance strategies, or automated analysis.
  • Ability to gather requirements from stakeholders and turn investigative, operational, or technical hunting needs into practical technical solutions.
  • Strong written and verbal communication skills, with the ability to explain technical findings, detection logic, and engineering tradeoffs to both technical and non‑technical stakeholders.
  • Curiosity, analytical rigor, attention to detail, and a desire to build scalable tools and detections that improve cyber defense outcomes.
Skills that would be useful but are not required
  • Exposure to adversary emulation, purple‑team exercises, red‑team collaboration, or threat‑informed defense.
  • Experience designing dashboards, notebooks, data pipelines, enrichment services, or internal tools for security analysts and investigators.
  • Relevant cybersecurity certifications.
What you can expect from Morgan Stanley

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals.

We do it in a way that’s differentiated – and we’ve done that for 90 years.

Our values – putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back – aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries.

At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered.

Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences.

We are proud to support our employees and their families at every point along their work‑life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry.

There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. Our workforce reflects a broad cross‑section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Detection Engineer, Director (Assistant VP)
Senior Detection Engineer, Director (Assistant VP)

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

PowerToFly • Singapore

On-site
SGD 90,000 - 150,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

Morgan Stanley • Singapore

On-site
SGD 120,000 - 180,000
Cyber Threat Intelligence Analyst, Associate
Cyber Threat Intelligence Analyst, Associate

23 MS Mgmt Service (SGP) Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Lead Python Software Engineer for AI Security, Vice President
Lead Python Software Engineer for AI Security, Vice President

23 MS Mgmt Service (SGP) Pte Ltd • Singapore

On-site
SGD 180,000 - 240,000
Director of Threat Hunt & Detection Engineering
Director of Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 260,000
Director, Threat Hunt & Detection Engineering
Director, Threat Hunt & Detection Engineering

Morgan Stanley • Singapore

On-site
SGD 180,000 - 240,000
AI Security Developer, Vice President, Cybersecurity Engineering
AI Security Developer, Vice President, Cybersecurity Engineering

Morgan Stanley • Singapore

On-site
SGD 260,000 - 380,000
Security Operations Vice President
Security Operations Vice President

Next Frontier Capital • Singapore

On-site
SGD 250,000 - 350,000
Research Associate - ASEAN (Energy, Power & Infrastructure)
Research Associate - ASEAN (Energy, Power & Infrastructure)

36 MS Asia Pte Singapore • Singapore

On-site
SGD 90,000 - 130,000