Senior Security Architecture Specialist

Morgan-Stanley

Alpharetta (GA)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Morgan Stanley’s Technology division is seeking a Senior Security Architecture Specialist to lead security design governance across the firm. You will steward architecture standards, ADRs, threat models, and control plane design while translating compliance obligations into operable patterns for developers.

The role involves building integrations between spec platforms and dev tooling, driving adoption through influence, and defining ADR lifecycles.

Qualifications

  • Bachelor’s degree with 7+ years of IT experience and security focus.
  • Experience designing governance artifacts like ADRs and threat models.
  • Hands-on with policy as code frameworks and compliance traceability.

Responsibilities

  • Architectural governance across the firm including ADRs and threat models.
  • Translate compliance obligations into operable security patterns for developers.
  • Build integrations between spec platforms and dev tooling for continuous traceability.

Skills

SAST
SCA
OSS governance
Threat models
ADR lifecycles
Policy as code
Python
PowerShell

Education

Bachelor’s degree in IT/Cybersecurity
CISSP/CSSLP certification

Tools

GitHub Advanced Security
Snyk
WhiteSource
Sonatype
X-Ray
Wiz

Job description

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Senior Security Architecture Specialist position at Vice President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.Morgan Stanley is an industry leader in financial services, known for mobilizing capital to help governments, corporations, institutions, and individuals around the world achieve their financial goals.Interested in joining a team that’s eager to create, innovate and make an impact on the world? Read on.We're seeking someone to join our team as a Senior Security Architecture Specialist in Cyber to be responsible for the security design tooling and security architecture standards across the firm – translating compliance obligations into operable, developer friendly architecture patterns, while directly operating the design governance toolchain that makes those standards real.What you'll do in the role:Architecture governanceSteward the security architecture standard across all verticals – ADRs, threat models, trust boundaries, and control plane designProduce compliance traceability artifacts mapping architecture decisions to compliance requirementsDrive cross team architecture through influence with principal engineers and engineering leadsSupport security standards, create templates and patterns to increase the efficiency and adoption of security programs.Living Spec & Design GovernanceOperate and evolve the design governance toolchainDefine the ADR lifecycles from creation to deprecation and ensure decision records remain the authoritative reference for architecture choicesBuild integrations between spec platform and dev tooling to make compliance traceability continuous, not periodicWhat you'll bring to the role:Bachelor’s degree with 7+ years of work experience in the IT field or equivalent.Demonstrated experience designing and governing SDLC security controls at scale – SAST, SCA, OSS governance, and container scanning.Hands-on experience with policy as code frameworks (OPA, Sentinel, or equivalent) and the ability to review and write policies, not just evaluate vendor tooling.Experience producing architecture decision records, threat models, or equivalent design governance artifacts that served as authoritative references for engineering teams.Strong written and verbal communication, ability to translate architecture decisions into compliance traceability artifacts and executive-facing recommendation documents.Track record of driving adoption through influence.Strong scripting background (Python, PowerShell).Desired Skills:A degree in Cybersecurity and/or CISSP/CSSLP certification and keen desire to move to security field.Business acumen to support the implementation of SAST, DAST, SCA, Container Security, API Security and IaC tools across the enterprise.Ability to perform code reviews with minimal assistance.A self-starter, with a strong desire for learning new technologies and applying them to solve problems.Expertise in monitoring, alerting, reporting, and data analysis.Experience with two or more of the application build environments like Jenkins, Gradle, Maven.Familiarity with public cloud services.Experience with two or more of the Secure SDLC tools like GitHub Advanced Security, Snyk, WhiteSource, Sonatype, X-Ray, Wiz.Experience with Threat Analysis.DevOps container/orchestration tools (Kubernetes, Docker, Puppet, etc.).Experience with evaluation, integration and onboard of application security tools.WHAT YOU CAN EXPECT FROM MORGAN STANLEY:At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.For more information, please visit : https://www.morganstanley.com/people-opportunities/eeo .
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Architecture Specialist
Senior Security Architecture Specialist

Morgan Stanley • Alpharetta (GA)

On-site
USD 180,000 - 240,000
Manager, Cyber Security Engineering
Manager, Cyber Security Engineering

Morgan-Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Competitive compensation package
Employee benefits
Senior Data Access Protection Engineer - Vice President
Senior Data Access Protection Engineer - Vice President

Morgan-Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Manager, Cyber Security Engineering
Manager, Cyber Security Engineering

PowerToFly • Alpharetta (GA)

On-site
USD 180,000 - 240,000
Manager, Cyber Security Engineering
Manager, Cyber Security Engineering

Morgan Stanley • Alpharetta (GA)

On-site
USD 180,000 - 240,000
VP, CTIS Risk Oversight Lead
VP, CTIS Risk Oversight Lead

Morgan-Stanley • Baltimore (MD)

On-site
USD 95,000 - 170,000
Medical insurance
Dental Insurance
Vision Insurance
+1
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Morgan-Stanley • Town of Islip (NY)

On-site
USD 120,000 - 210,000
Lead Application Security Eng
Lead Application Security Eng

PowerToFly • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Cyber Security AI Engineer - Director
Cyber Security AI Engineer - Director

Morgan-Stanley • Baltimore (MD)

On-site
USD 85,000 - 150,000
Discretionary bonus
Competitive benefits
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP

PowerToFly • Baltimore (MD)

On-site
USD 135,000 - 190,000
Medical, Dental, and Vision insurance
401(k) with company match
Paid Time Off and Holidays