Technology/Role/Department at MorganStanley
Technology is the keydifferentiator that ensures that we manage our global businesses and serveclients on a market-leading platform that is resilient, safe, efficient, smart,fast and flexible. Technology redefines how we do business in global, complexand dynamic financial markets. We have a large number of award winningtechnology platforms that help to propel our Firm s businesses to be the top inthe market. Our India technology teams are based in Mumbai and Bengaluru. Wehave built strong techno-functional teams which partner with our officesglobally taking global ownership of systems and products. We have a vibrant anddiverse mix of technologists working on different technologies and functionaldomains. There is a large focus on innovation, inclusion, giving back to thecommunity and sharing knowledge.
The STAR Security Architecture(SecArch) team is part of the Technology & Operations Risk (TOR) division.The mission of the team is to protect the Firm by ensuring in-scopetechnologies built internally, products purchased and services used meetsecurity requirements that include the Firm s Policies, external guidelines,regulatory expectations, and appropriate controls in the areas of informationsecurity, secure design, and cyber security. We accomplish this mission viathree primary services: architecture consulting, solutions consulting, anddesign review. The Cloud Security Architect is an internal consultant who isworking on multiple cloud security engagements across the enterprise either asa single contributor or participating in a virtual team across businessunits. The security architect works withteam members (IT, Business, Suppliers, Stakeholders and Partners) globally toaddress SecArch s mission. The main focus of the Cloud Security Architect isthe responsibility of securely deploying systems, infrastructure and businesscapabilities on Cloud Service Providers (CSP). To be successful as a CloudSecurity Architect the candidate must have deep Azure cybersecurity experiencecoupled with strong communication, influencing and time management skills.
Job Responsibilities
Lead architecture consulting to construct SecurityArchitectures for a business unit or infrastructure Technology team in theMicrosoft Azure space
Conduct risk assessments and provide technologyrisk/requirements to address risks identified. Areas covered:
o Cloud cybersecurity using Microsoft Azure Active Directory,Azure Key Vault, Azure DNS / Firewall, Azure Kubernetes and Container Registry.
o Authentication, Authorization, Auditing
o Application Security - Session Security , Vulnerability / Penetration Testing items, Input Validation
o Secure data transport and storage
Periodically review security reference architecture(security blueprints) and conduct updates/enhancements to guidance, policies,or other applicable reference materials
Participate in various Operational and Technology Riskgovernance processes
Lead, where applicable, a role in architecture reviewcommittees representing Security Architecture
Skills
Excellentcommunication skills: written, oral, presentation, listening
Abilityto influence through factual reasoning
Timemanagement: ability to handle multiple concurrent assessments, plan baseddeliverable management, strong follow up and tracking
Strongfocus on delivery when presented with short timelines and increased involvementfrom senior management
Abilityto adjust communication of technology risks vs business risks based on theaudience
Abilityto operate in multiple virtual teams, directly manage teams, or ability tooperate as a sole contributor
Bachelor of Science in Computer Scienceor relevant technical degree.
7 years relevantwork experience in high-paced, enterprise environment
2 - 4 years of work experience in engineering and cybersecurity on the Azure platform.
Required Technical Skills:
o Architecture/ Design experience building secure applications and infrastructure using AzureIdentity, Network Security, DevOps, Database technologies.
o Workingsecurity architecture expertise of the following Azure services
Azure Key Vault
Azure Network Security Groups, DNS,Firewall
Azure Active Directory
Azure Kubernetes Service andContainer Registry
Azure API Gateway and APIM
Azure DevOps, Dev Tools, SQL
o Indepth knowledge of application, network and platform security vulnerabilities.Ability to explain vulnerabilities to developers
o Experiencein conducting Information Security, Security Architecture, Audit assessments.Presenting the outcomes of the assessment and obtaining buy in.
o Strongfocus on reviewing technical designs and functional requirements to identifyareas of Security weakness.
o Thecandidate must have working experience in the following application/networksecurity domains:
Authentication: SAML, SiteMinder,Kerberos, OpenId
Entitlements and identity management
Data protection, data leakageprevention and secure data transfer and storage
App Security - validation checking,software attack methodologies
Cryptography - encryption and hashing
o Eventhough the SecArch role is not a development role, the candidate must haveprevious background in programming, design and/or application architecture.
Desired Technical Skills:
o Securityfundamentals understanding. Experience implementing CSA Cloud Controls Matrix.
o Knowledgeof Cloud Servicer Provider (CSP) security fundamentals.
o Knowledgeof standard network model and the risks that present at each layer, thefunctions of network equipment such as switches, routers, firewalls, proxies,vpn, and load-balancers, and to understand network architecture.
o Thecandidate must have working knowledge of the primary operating systems (Unix,Windows, z/OS, Mac OS), the configuration and management of that platform at anenterprise scale, the security risks to that platform, and how to mitigatethose risks.
o Experience in testing tools, at leastone of Veracode, Fortify, OunceLabs, AppScan, WebInspect, Burp
o Inorder to be a practical SecArch the candidate must have experience implementingcomplex applications in an enterprise environment.
o workingknowledge of programming and scripting languages: Java, JavaScript, C#, C/C ,Perl, Python, Ruby
o In-depth knowledge of web technologies such as Web Browsers, Web Servers,Web Services
o Frameworks,protocols and subsystems: J2EE, .NET, Spring,RPC, SOAP, MQSeries, JMS, RMI, JMX, Hibernate.
o Knowledgeof JSP /Servlet/EJB or ASP.NET, HTTP/HTTPS, Cookies, AJAX, JavaScript, Flex /Silverlight.
o Databasedesign and programming experience
o Experienceof liaising with 3 rd Party Entities (exchanges, suppliers,regulators)
o Experiencein conducting and / or reviewing penetration tests, dynamic vulnerabilityassessments and static vulnerability assessments
o Understandingof geographic regulations and their impact on Security assessments
o Previousexperience in Financial Services is preferred
o CISSP,CCSP or other industry qualification
o Experience working with global organizations
Keyskills: Unix Hibernate JSP DNS Javascript J2Ee Perl Firewall SQL Ajax
Morgan Stanley Advantage Services Pvt. Ltd. Morgan Stanley has been operating in India for over 20 years , providing a range of services to domestic and international clients.The Firm has a premier institutional securities platform in India , providing a full range of investment banking , capita...