Vulnerability Management Operations Analyst

474 MS Services Group, Inc.

Alpharetta (GA)

On-site

USD 95,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Morgan Stanley is seeking a VM Ops Analyst to support Vulnerability Management in Cloud Platform Security and Developer Enablement. You will triage findings, manage cases, and track remediation SLAs while guiding system owners and expanding platform automation.

Ideal candidates have 3–5 years in vulnerability/security operations, with knowledge of CVSS/EPSS, cloud/on-prem environments, and scripting to automate tasks. On-call coverage may be required.

Qualifications

  • 3–5 years in vulnerability, security ops, or SRE functions.
  • Ability to interpret CVSS/EPSS ratings and threats.
  • Understanding of on-prem and cloud infra basics.

Responsibilities

  • Triaging vulnerabilities, case management, and remediation SLA tracking.
  • Communicate status and guidance to system owners.
  • Develop VM platform expertise and assist with automation needs.
  • Support on-call incidents and after-hours needs.

Skills

Vulnerability mgmt
Cybersecurity ops
CI/CD basics
Python/PowerShell
Communication skills

Tools

Splunk
Grafana

Job description

We're seeking someone to join our Vulnerability Management (VM) Operations team as a VM Ops Analyst in Cloud Platform Security and Developer Enablement to assist with Vulnerability findings identification, assignment, notification, prioritization, escalation and reporting. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role:

Join a dynamic team accountable for Vulnerability Management findings triaging, case management, and remediation SLA tracking. The VM Analyst will need to familiarize themselves with the firm's scanning tools and processes, triaging vulnerabilities, communicating status, guiding system owners in remediation, updating cases, reviewing system owner comments and requests. The VM Analyst will also be required to develop deep operational expertise of the VM platform/s to mature and improve the platform determine possible future automation needs and work with the dev team to fix bugs, test fixes in QA, and streamline the processes via the platform. VM Analysts must also be able to explain and present the VM process and tool usage to system owners and provide basic guidance around VM Reporting and metrics. VM Analysts must be for zero-day response and bypass of normal patch SLAs - the response window compresses to mere hours inclusive of Weekend and Holiday times. - VM Analysts are expected to be part of the on-call may occasionally be called upon to support an active incident after hours.

What you bring to the role:

3 -5 years of experience in vulnerability, technology security operations, or related SRE functions. Vulnerability management / Cybersecurity knowledge such as the ability to interpret vulnerability CVSS / EPSS / exploitability ratings and threats Ability to learn and understand the firm's OS/app patching ecosystems Basic understanding of on prem and cloud infrastructure technologies (e.g., systems, servers, virtualization, containers, images) Ability to adapt to inputs from cyber threat intelligence and/or escalations from Management. Ability to process information, translate into plans and present summaries to stakeholders. Strong analytical and problem‑solving mindset Basic understanding of SDLC, CI/CD, IT Asset Management, and third‑party software supply chains Ability to communicate effectively across technical and non‑technical audiences Experience managing competing priorities in fast‑paced environments Self‑starter with ability to drive initiatives independently Additional Skills: Basic understanding of emerging LLM/AI cyber threats Ability to document user‑stories and/or bugs Prior experience with commercial Vulnerability Management scanning tooling (or adjacent Observability Management or Endpoint Security tools) Experience with Spunk and/or Grafana Ability to write scripts in Python or PowerShell and/or leveraging Agentic coding capabilities

What You Can Expect From Morgan Stanley:

At Morgan Stanley, we raise, manage and allocate capital for our clients - helping them reach their goals. We do it in a way that’s differentiated - and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work. To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser. Expected base pay rates for the role will be between $95,0000 and $130,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs. Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents. Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo. At Morgan Stanley, we advise, originate, trade, manage and distribute capital for people, governments and institutions, always with a standard of excellence and guided by our core values. Morgan Stanley is dedicated to providing first-class service to our clients, in a way that reflects our commitment to creating a more sustainable future and fostering stronger communities around the world. In each line of business, we strive to demonstrate our belief in the power of transformative thinking, innovative strategies and leading-edge solutions—and in the ability of capital to work for the benefit of all society.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Management Operations Analyst
Vulnerability Management Operations Analyst

Morgan-Stanley • Alpharetta (GA)

On-site
USD 95,000 - 130,000
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP

474 MS Services Group, Inc. • United States

On-site
USD 135,000 - 190,000
Lead Application Security Eng
Lead Application Security Eng

474 MS Services Group, Inc. • Alpharetta (GA)

On-site
USD 125,000 - 175,000
Windows Infrastructure Engineer - Vice President
Windows Infrastructure Engineer - Vice President

474 MS Services Group, Inc. • New York (NY)

On-site
USD 150,000 - 210,000
VP, CTIS Risk Oversight Lead
VP, CTIS Risk Oversight Lead

474 MS Services Group, Inc. • United States

On-site
USD 95,000 - 170,000
Comprehensive benefits package
Discretionary incentive compensation
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Morgan Stanley • New York (NY)

On-site
USD 120,000 - 210,000
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead
Vice President, Cyber, Technology and Information Security (CTIS) Risk Oversight Lead

Morgan-Stanley • Town of Islip (NY)

On-site
USD 120,000 - 210,000
Senior Security Architecture Specialist
Senior Security Architecture Specialist

474 MS Services Group, Inc. • Alpharetta (GA)

On-site
USD 140,000 - 200,000
Sr Software Developer
Sr Software Developer

474 MS Services Group, Inc. • New York (NY)

On-site
USD 150,000 - 210,000
SRE/Production Support Lead
SRE/Production Support Lead

Morgan Stanley • Alpharetta (GA)

On-site
USD 125,000 - 175,000