Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP

474 MS Services Group, Inc.

United States

On-site

USD 135,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Morgan Stanley in the Technology division seeks a Cyber Threat Intelligence - Technical Analysis and Investigations Lead to head technical threat investigations, track sophisticated adversaries, and operationalize technical intelligence for detection and response.

The role requires at least 5 years in cyber threat intelligence, expertise with MITRE ATT&CK and the Diamond Model, proficiency in Python for analytics, and experience with SIEM platforms to drive detection improvements and proactive

Qualifications

  • Minimum 5 years of experience in cyber threat intelligence, cyber discovery, or cybersecurity investigations, with a track record leading both teams and technical investigations and producing actionable outcomes.
  • Expertise in tracking advanced threat actors and malware using frameworks such as MITRE ATT&CK and/or the Diamond Model to characterize campaigns, capabilities, and infrastructure.
  • Proficiency in Python and scripting to automate investigative workflows and develop analytics (e.g., Jupyter notebooks).
  • Experience with large-scale data analysis and security telemetry tooling to identify patterns, quantify trends, and support analytic judgments.
  • Experience with SIEM platforms and interpreting network/endpoint logs to progress investigations from hypothesis to evidence-based conclusions.
  • Ability to communicate clearly across technical and non-technical audiences, including writing technical reporting and briefing investigative judgments and mitigations.

Responsibilities

  • Lead proactive threat hunts and advanced discovery to identify adversary campaigns, capabilities, infrastructure, and targets using internal collection, OSINT, and vendor intelligence.
  • Research and track advanced threat actors and malware, maintaining deep technical understanding of adversary TTPs and tradecraft.
  • Author high-impact technical threat intelligence products and reports tailored to both operational teams and senior stakeholders.
  • Develop and advance investigative tradecraft, analytic techniques, and automation to improve speed, repeatability, and fidelity of analytic workflows (including Python-based analytics).
  • Enrich, triage, and characterize threat insights and indicators by leveraging open-source and commercial tooling, and curate high-fidelity IOCs for operational use.
  • Partner with threat hunting and security response teams to translate technical intelligence into detection opportunities, mitigations, and control validation activities.
  • Maintain and curate threat profiles aligned to areas of responsibility, producing actionable technical intelligence for proactive detection and discovery.

Skills

Threat hunting
Python scripting
Technical threat intel
MITRE ATT&CK
Diamond Model
OSINT
Stakeholder communication

Tools

SIEM
Jupyter notebooks
Threat intel tooling

Job description

We’re seeking someone to join our team as a Cyber Threat Intelligence - Technical Analysis and Investigations Lead in Technology to lead technical threat investigations, track sophisticated adversaries, and operationalize technical intelligence for detection and response. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. Since 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role:
  • Lead proactive threat hunts and advanced discovery to identify adversary campaigns, capabilities, infrastructure, and targets using internal collection, OSINT, and vendor intelligence.
  • Research and track advanced threat actors and malware, maintaining deep technical understanding of adversary TTPs and tradecraft.
  • Author high-impact technical threat intelligence products and reports tailored to both operational teams and senior stakeholders.
  • Develop and advance investigative tradecraft, analytic techniques, and automation to improve speed, repeatability, and fidelity of analytic workflows (including Python-based analytics).
  • Enrich, triage, and characterize threat insights and indicators by leveraging open-source and commercial tooling, and curate high-fidelity IOCs for operational use.
  • Partner with threat hunting and security response teams to translate technical intelligence into detection opportunities, mitigations, and control validation activities.
  • Maintain and curate threat profiles aligned to areas of responsibility, producing actionable technical intelligence for proactive detection and discovery.
What you'll bring to the role:
  • Minimum 5 years of experience in cyber threat intelligence, cyber discovery, or cybersecurity investigations, with a track record leading both teams and technical investigations and producing actionable outcomes.
  • Expertise in tracking advanced threat actors and malware using frameworks such as MITRE ATT&CK and/or the Diamond Model to characterize campaigns, capabilities, and infrastructure.
  • Proficiency in Python and scripting to automate investigative workflows and develop analytics (e.g., Jupyter notebooks).
  • Experience with large-scale data analysis and security telemetry tooling to identify patterns, quantify trends, and support analytic judgments.
  • Experience with SIEM platforms and interpreting network/endpoint logs to progress investigations from hypothesis to evidence-based conclusions.
  • Ability to communicate clearly across technical and non-technical audiences, including writing technical reporting and briefing investigative judgments and mitigations.

Nice to have : GIAC GCTI, CISSP, CASP certifications

We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work. To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

Salary range for the position: 135,000 and 190,000 per year. The successful candidate may be eligible for an annual discretionary incentive compensation award. The successful candidate may be eligible to participate in the relevant business unit’s incentive compensation plan, which also may include a discretionary bonus component. Morgan Stanley offers a full spectrum of benefits, including Medical, Prescription Drug, Dental, Vision, Health Savings Account, Dependent Day Care Savings Account, Life Insurance, Disability and Other Insurance Plans, Paid Time Off (including Sick Leave consistent with state and local law, Parental Leave and X Vacation Days annually), 10 Paid Holidays, 401(k), and Short/Long Term Disability, in addition to other special perks reserved for our employees. Please visit mybenefits.morganstanley.com to learn more about our benefit offerings.

  • Medical
  • Prescription Drug
  • Dental
  • Vision
  • Health Savings Account
  • Dependent Day Care Savings Account
  • Life Insurance
  • Disability and Other Insurance Plans
  • Paid Time Off (including Sick Leave consistent with state and local law, Parental Leave and X Vacation Days annually)
  • 10 Paid Holidays
  • 401(k)
  • Short/Long Term Disability
  • other special perks reserved for our employees

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

At Morgan Stanley, we advise, originate, trade, manage and distribute capital for people, governments and institutions, always with a standard of excellence and guided by our core values. Morgan Stanley is dedicated to providing first-class service to our clients, in a way that reflects our commitment to creating a more sustainable future and fostering stronger communities around the world. In each line of business, we strive to demonstrate our belief in the power of transformative thinking, innovative strategies and leading-edge solutions—and in the ability of capital to work for the benefit of all society.

What We Do

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP

PowerToFly • Baltimore (MD)

On-site
USD 135,000 - 190,000
Medical, Dental, and Vision insurance
401(k) with company match
Paid Time Off and Holidays
VP, CTIS Risk Oversight Lead
VP, CTIS Risk Oversight Lead

474 MS Services Group, Inc. • United States

On-site
USD 95,000 - 170,000
Comprehensive benefits package
Discretionary incentive compensation
VP, CTIS Risk Oversight Lead
VP, CTIS Risk Oversight Lead

Morgan Stanley • Baltimore (MD)

On-site
USD 102,000 - 170,000
Medical insurance
Retirement plan (401(k))
Paid time off
+1
VP Asset Servicing
VP Asset Servicing

PowerToFly • Baltimore (MD)

On-site
USD 125,000 - 185,000
Internal Audit Executive Director – Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience
Internal Audit Executive Director – Global Audit Lead, Cybersecurity, Information Security & Cyber Resilience

474 MS Services Group, Inc. • New York (NY)

On-site
USD 165,000 - 275,000
Principal AI Engineer - Vice President
Principal AI Engineer - Vice President

474 MS Services Group, Inc. • New York (NY)

On-site
USD 150,000 - 210,000
Competitive compensation
Inclusive benefits
Sr Software Developer
Sr Software Developer

474 MS Services Group, Inc. • New York (NY)

On-site
USD 150,000 - 210,000
VP - Cyber, Technology, and Information Risk Manager
VP - Cyber, Technology, and Information Risk Manager

474 MS Services Group, Inc. • Alpharetta (GA)

On-site
USD 95,000 - 165,000
Medical
Prescription Drug
Dental
+5
Technical Program Manager - Vice President
Technical Program Manager - Vice President

474 MS Services Group, Inc. • New York (NY)

On-site
USD 155,000 - 215,000
Assoc, Professional, P2, Client Services & Relationship Mgmt ISG, NEX : Job Level - Associate
Assoc, Professional, P2, Client Services & Relationship Mgmt ISG, NEX : Job Level - Associate

474 MS Services Group, Inc. • United States

On-site
USD 51,000 - 83,000
Medical benefits
Dental & Vision
401(k) plan
+1