Your browser does not support javascript! Please enable it, otherwise web will not work for you.

SecArch Cloud Security Architect - Mumbai @ Morgan Stanley

Home > Senior Management

 SecArch Cloud Security Architect - Mumbai

Job Description

Technology/Role/Department at MorganStanley

Technology is the keydifferentiator that ensures that we manage our global businesses and serveclients on a market-leading platform that is resilient, safe, efficient, smart,fast and flexible. Technology redefines how we do business in global, complexand dynamic financial markets. We have a large number of award winningtechnology platforms that help to propel our Firm s businesses to be the top inthe market. Our India technology teams are based in Mumbai and Bengaluru. Wehave built strong techno-functional teams which partner with our officesglobally taking global ownership of systems and products. We have a vibrant anddiverse mix of technologists working on different technologies and functionaldomains. There is a large focus on innovation, inclusion, giving back to thecommunity and sharing knowledge.

The STAR Security Architecture(SecArch) team is part of the Technology & Operations Risk (TOR) division.The mission of the team is to protect the Firm by ensuring in-scopetechnologies built internally, products purchased and services used meetsecurity requirements that include the Firm s Policies, external guidelines,regulatory expectations, and appropriate controls in the areas of informationsecurity, secure design, and cyber security. We accomplish this mission viathree primary services: architecture consulting, solutions consulting, anddesign review. The Cloud Security Architect is an internal consultant who isworking on multiple cloud security engagements across the enterprise either asa single contributor or participating in a virtual team across businessunits. The security architect works withteam members (IT, Business, Suppliers, Stakeholders and Partners) globally toaddress SecArch s mission. The main focus of the Cloud Security Architect isthe responsibility of securely deploying systems, infrastructure and businesscapabilities on Cloud Service Providers (CSP). To be successful as a CloudSecurity Architect the candidate must have deep Azure cybersecurity experiencecoupled with strong communication, influencing and time management skills.

Job Responsibilities

Lead architecture consulting to construct SecurityArchitectures for a business unit or infrastructure Technology team in theMicrosoft Azure space

Conduct risk assessments and provide technologyrisk/requirements to address risks identified. Areas covered:

o Cloud cybersecurity using Microsoft Azure Active Directory,Azure Key Vault, Azure DNS / Firewall, Azure Kubernetes and Container Registry.

o Authentication, Authorization, Auditing

o Application Security - Session Security , Vulnerability / Penetration Testing items, Input Validation

o Secure data transport and storage

Periodically review security reference architecture(security blueprints) and conduct updates/enhancements to guidance, policies,or other applicable reference materials

Participate in various Operational and Technology Riskgovernance processes

Lead, where applicable, a role in architecture reviewcommittees representing Security Architecture




Skills

Excellentcommunication skills: written, oral, presentation, listening

Abilityto influence through factual reasoning

Timemanagement: ability to handle multiple concurrent assessments, plan baseddeliverable management, strong follow up and tracking

Strongfocus on delivery when presented with short timelines and increased involvementfrom senior management

Abilityto adjust communication of technology risks vs business risks based on theaudience

Abilityto operate in multiple virtual teams, directly manage teams, or ability tooperate as a sole contributor

Bachelor of Science in Computer Scienceor relevant technical degree.

7 years relevantwork experience in high-paced, enterprise environment

2 - 4 years of work experience in engineering and cybersecurity on the Azure platform.

Required Technical Skills:

o Architecture/ Design experience building secure applications and infrastructure using AzureIdentity, Network Security, DevOps, Database technologies.

o Workingsecurity architecture expertise of the following Azure services

Azure Key Vault

Azure Network Security Groups, DNS,Firewall

Azure Active Directory

Azure Kubernetes Service andContainer Registry

Azure API Gateway and APIM

Azure DevOps, Dev Tools, SQL

o Indepth knowledge of application, network and platform security vulnerabilities.Ability to explain vulnerabilities to developers

o Experiencein conducting Information Security, Security Architecture, Audit assessments.Presenting the outcomes of the assessment and obtaining buy in.

o Strongfocus on reviewing technical designs and functional requirements to identifyareas of Security weakness.

o Thecandidate must have working experience in the following application/networksecurity domains:

Authentication: SAML, SiteMinder,Kerberos, OpenId

Entitlements and identity management

Data protection, data leakageprevention and secure data transfer and storage

App Security - validation checking,software attack methodologies

Cryptography - encryption and hashing

o Eventhough the SecArch role is not a development role, the candidate must haveprevious background in programming, design and/or application architecture.

Desired Technical Skills:

o Securityfundamentals understanding. Experience implementing CSA Cloud Controls Matrix.

o Knowledgeof Cloud Servicer Provider (CSP) security fundamentals.

o Knowledgeof standard network model and the risks that present at each layer, thefunctions of network equipment such as switches, routers, firewalls, proxies,vpn, and load-balancers, and to understand network architecture.

o Thecandidate must have working knowledge of the primary operating systems (Unix,Windows, z/OS, Mac OS), the configuration and management of that platform at anenterprise scale, the security risks to that platform, and how to mitigatethose risks.

o Experience in testing tools, at leastone of Veracode, Fortify, OunceLabs, AppScan, WebInspect, Burp

o Inorder to be a practical SecArch the candidate must have experience implementingcomplex applications in an enterprise environment.

o workingknowledge of programming and scripting languages: Java, JavaScript, C#, C/C ,Perl, Python, Ruby

o In-depth knowledge of web technologies such as Web Browsers, Web Servers,Web Services

o Frameworks,protocols and subsystems: J2EE, .NET, Spring,RPC, SOAP, MQSeries, JMS, RMI, JMX, Hibernate.

o Knowledgeof JSP /Servlet/EJB or ASP.NET, HTTP/HTTPS, Cookies, AJAX, JavaScript, Flex /Silverlight.

o Databasedesign and programming experience

o Experienceof liaising with 3 rd Party Entities (exchanges, suppliers,regulators)

o Experiencein conducting and / or reviewing penetration tests, dynamic vulnerabilityassessments and static vulnerability assessments

o Understandingof geographic regulations and their impact on Security assessments

o Previousexperience in Financial Services is preferred

o CISSP,CCSP or other industry qualification

o Experience working with global organizations


Job Classification

Industry: Banking, Financial Services, Broking
Functional Area: IT Software - Application Programming, Maintenance,
Role Category: Senior Management
Role: Senior Management
Employement Type: Full time

Education

Under Graduation: B.Sc in Chemistry
Post Graduation: Post Graduation Not Required
Doctorate: Any Doctorate in Any Specialization, Doctorate Not Required

Contact Details:

Company: Morgan Stanley
Location(s): Mumbai

+ View Contactajax loader


Keyskills:   Unix Hibernate JSP DNS Javascript J2Ee Perl Firewall SQL Ajax

 Job seems aged, it may have been expired!
 Fraud Alert to job seekers!

₹ Not Disclosed

Morgan Stanley

Morgan Stanley Advantage Services Pvt. Ltd. Morgan Stanley has been operating in India for over 20 years , providing a range of services to domestic and international clients.The Firm has a premier institutional securities platform in India , providing a full range of investment banking , capita...