Cloud Security Controls Engineering - VP

Morgan Stanley

Alpharetta (GA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Morgan Stanley is seeking a Cloud Security Engineer to lead the design and implementation of deploy-time security controls across various cloud services such as AWS, Azure, and GCP. This role involves managing the entire lifecycle from requirement interpretation to policy deployment and requires deep technical expertise in Terraform and infrastructure-as-code.

The ideal candidate will have over 7 years of experience in cloud security engineering, a strong grasp of modern threat models, and proven ability to lead and mentor a team of engineers.

Qualifications

  • 7+ years of hands-on experience in cloud security engineering.
  • Proven experience designing policy-as-code controls.
  • Strong expertise with Terraform and secure configuration patterns.

Responsibilities

  • Lead the design and implementation of deploy-time security controls.
  • Define and implement testing strategies for policy validation.
  • Contribute to cloud security strategy and standards.

Skills

Cloud security engineering
Infrastructure-as-code
Terraform
OPA (Rego)
CI/CD pipelines
Team leadership

Education

Bachelor's degree in computer science or Information Security

Tools

AWS
Azure
GCP

Job description

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.

What You Will Do
  • Lead the design and implementation of deploy‑time security controls for cloud services across Azure, AWS, and GCP, using OPA (Rego) and Regula.
  • Translate firm‑wide configuration baseline requirements into enforceable policy‑as‑code controls integrated directly into Terraform workflows and CI/CD pipelines.
  • Own end‑to‑end control implementation lifecycle: requirement interpretation, policy authoring, testing, optimization, and deployment within engineering pipelines.
  • Establish and maintain reusable policy libraries and modules to ensure consistency and scalability of controls across services and environments.
  • Provide deep technical expertise in Terraform, infrastructure‑as‑code patterns, and pipeline orchestration, ensuring secure and efficient deployments.
  • Define and implement testing strategies for policy validation, including unit and integration testing.
  • Identify gaps where requirements cannot be enforced at deploy‑time and propose compensating controls or alternative enforcement points.
  • Contribute to the evolution of a unified control framework, enabling consistent control logic across deploy‑time and runtime evaluation points.
  • Contribute to cloud security strategy and standards.
  • Lead and develop a team of engineers responsible for deploy‑time control implementation, setting technical direction and ensuring high‑quality delivery.
  • Provide hands‑on mentorship and coaching in OPA/Rego, Regula, Terraform, and secure pipeline design.
  • Manage performance, provide actionable feedback, and support career development for team members.
  • Foster a high‑accountability, low‑friction operating model, reducing handoffs and accelerating baseline delivery.
What You Will Bring
  • 7+ years of hands‑on experience in cloud security engineering, with a strong focus on infrastructure‑as‑code and deployment pipelines.
  • Bachelor's degree in computer science, Information Security, or a related field, or equivalent experience.
  • Proven experience designing and implementing policy‑as‑code controls using OPA (Rego) and/or Regulators in production environments.
  • Deep hands‑on expertise with Terraform, including module design, state management, and secure configuration patterns.
  • Strong experience integrating security controls into CI/CD pipelines, including gating and enforcement mechanisms.
  • Demonstrated ability to translate security requirements into automated, testable, and enforceable controls at deploy‑time.
  • Solid understanding of cloud security architectures across AWS, Azure, and/or GCP, including identity and access management, networking, and data protection controls.
  • Experience implementing control validation and testing strategies, including policy unit testing, pipeline validation, and drift detection.
  • Familiarity with CSPM platforms and the ability to align deploy‑time controls with runtime detection and compliance models.
  • Strong understanding of modern threat models, attack paths, and misconfiguration risks in cloud environments, and how to mitigate them through preventive controls.
  • Experience building and maintaining reusable policy libraries and shared control frameworks at enterprise scale.
  • Proven experience leading a team of engineers, including task prioritization, delivery oversight, and technical direction setting.
  • Demonstrated ability to mentor and develop engineers, particularly in policy‑as‑code, Terraform, and secure pipeline practices.
  • Experience establishing code quality standards, review processes, and engineering best practices for IaC and policy development.
  • Strong stakeholder management skills, with the ability to partner effectively with platform engineering, security architecture, and application teams.
  • Ability to communicate complex technical concepts clearly to both engineering audiences and senior leadership.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Cloud Security Controls & Secure IaC Pipelines
VP, Cloud Security Controls & Secure IaC Pipelines

Morgan Stanley • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Dir, P4, Lead Cybersecurity Eng : Job Level - Director
Dir, P4, Lead Cybersecurity Eng : Job Level - Director

Socket.dev • Alpharetta (GA)

On-site
USD 140,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

Morgan Stanley • Alpharetta (GA)

On-site
USD 95,000 - 135,000
Comprehensive employee benefits
Diversity and inclusion initiatives
Windows Infrastructure Engineer - Vice President
Windows Infrastructure Engineer - Vice President

Morgan Stanley • New York (NY)

On-site
USD 150,000 - 210,000
Principal Security Architect
Principal Security Architect

Francisco Partners • United States

On-site
USD 130,000 - 165,000
Senior Security Architecture Specialist
Senior Security Architecture Specialist

Morgan Stanley • Alpharetta (GA)

On-site
USD 180,000 - 240,000
Senior Vice President, Senior Cloud Security Engineer
Senior Vice President, Senior Cloud Security Engineer

BNY • New York (NY)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+3
AWS Solution architect
AWS Solution architect

Russell Tobin • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Comprehensive healthcare coverage
401(k)-retirement savings
Life & disability insurance
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • Malvern

On-site
USD 150,000 - 190,000
Security Controls Engineer
Security Controls Engineer

Tata Consultancy Services • Jersey City (NJ)

On-site
USD 80,000 - 90,000