Web Security Engineer
Morgan Stanley
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Cybersecurity Engineering position at Vice President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.
Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.
We are seeking to add an experienced Web Security / Network Security subject matter expert to join our Web Security Operations. The team is responsible for the day-to-day operations, security, and health of Morgan Stanley's Web Proxy infrastructure on which thousands of web applications run.
The specialist will act as an SME for web security, handle operational escalations from our L2 teams, respond to incident management notifications, as well as in delivering robust, effective solutions covering our internet perimeter and external content delivery network providers.
What you'll do in the role:
Provide Level 3 Operations support for a global perimeter Web proxy and Web security enterprise infrastructure
Maintain Web security infrastructure, providing stability by developing tools, policies, processes and procedures for the operations teams
Lead projects, analyze and prioritize workload based on business risk and requirements.
Take ownership of incidents, problems, follow-up actions and manage to resolution
Plan, review production changes following firm Change Management process and procedure.
Provide Web Security consultancy services to other internal Technology teams.
Provides architecture assurance on Web Security initiatives.
Establish effective working relationships with Engineering counterparts and other stakeholders operating in the Web Security space
Provide a secure environment, by implementing controls to manage and mitigate risks.
Develop automated metrics reporting capabilities
Create, review, maintain and update documentation including Documenting & Publishing fixes in our central knowledge base
Work with global colleagues to provide globally consistent processes and solutions
Investigate & Troubleshoot root causes when escalated from operations
Escalate and liaise with additional internal/external groups when required
Input into Business Continuity Planning and Practices
Integration and testing, and deployment of Web Proxy technologies with leading network DLP or Malware scanning solutions
Collaborating with leads responsible for web and application servers, load-balancers and web authentication infrastructure
Working with colleague subject matter experts in the wider organization who administer networks, logging, application architecture and other complementary technologies
Drive determination and implementation of security best practice in our web platforms and infrastructure
Research into vendor and open-source solutions in the web security space, and determination of their place in our overall solution
Interfacing with technical contacts at external vendor providers and other internal teams to ensure a holistic solution is delivered and enhanced
Training operations L2 personnel, application support groups in tools, technologies and procedures
What you'll bring to the role:
Moderate-Advance direct experience with Proxy technologies
Netskope, Bluecoat, Fortinet, PaloAlto, ZScaler, ZPA, SSLi, Cloud DLP, Cloud Sandboxing
Moderate-Advanced proxy experience required including engineering of flows via proxy and client access for troubleshooting; Netskope, Bluecoat ProxySG Appliance, Netskope or Zscaler experience preferred.
Must know how to integrate external services with proxies via ICAP, proxy chaining, and service offloads.
Moderate cloud security experience across at least a couple of the more cloud providers (Azure, O365, AWS, etc.)
Excellent understanding and experience designing and implementing Web security solutions.
Good understanding on Web Proxy infrastructure serving various application layer protocols such as HTTP/HTTPs/SOCKS/FTP/ICAP
Scripting and Development Skills (Perl, Python or Shell).
Moderate Linux Sys admin experience.
Interpersonal Skills - Communication, flexibility, self-driven, team player
Strong general networking background (Firewalls, Routing, Load Balancing, OSI Model, Packet trace and analysis, etc.)
Good understanding of the protocols underpinning the web - TCP/IP, HTTP, SSL/TLS etc.
Ideal candidate would be able to intelligently dissect all 7 layers of the OSI stack
Experience working in DMZ environments with good understanding of hardware load-balancing, firewalls, multi-tiered architectures.
Experience implementing or maintaining monitoring for network security infrastructure
Skills Desired
Hands-on experience with Fortinet/Fortimanager appliances
Hands-on proxy knowledge: Netskope, Bluecoat, and/or Zscaler experience preferred
Hands-on CASB design, architecture and deployment (SkyHigh, Symantec, etc.)
Knowledge of Data Protection Practices (data at rest, in use, in motion, etc.) and their practical implementations
Practical knowledge of web malware, its propagation and mitigation strategies
CISSP or similar recognized cyber security qualifications
Experience operating in large, siloed enterprise environments
Project Management Skills with experience on enterprise projects
Web and database development skills (HTML, JavaScript, SQL, ETL)
Web Proxy Bluecoat/ZScaler or other major web proxy competitor
Experience within the financial services industry is preferred
We have a track record of innovation and passion for unlocking new opportunities, we help our clients raise, manage and allocate capital. We do this by offering a wide range of investment banking, securities, wealth management and asset management services.
All that we do at Morgan Stanley is driven by our five core values: do the right thing, put clients first, lead with exceptional ideas, commit to diversity and inclusion, and give back. These aren’t just beliefs, they guide the decisions we make every day, ensuring we do what's best for our clients, communities and more than 80,000 employees around the world. And at the core of our success are the people who drive it - relentless collaborators and creative thinkers who are fueled by diverse thinking and experiences.
Wherever you are in our 1,200 global offices, you’ll have the opportunity to work alongside the best and the brightest in an environment where you are empowered to achieve your full potential. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry.
At Morgan Stanley Alpharetta, we support the Firm’s global business and functions from Wealth Management and Institutional Securities to Technology and Operations, Finance and Human Resources. With the 2020 acquisition of E-TRADE, Morgan Stanley Alpharetta grew significantly and has grown its role in our Wealth Management business helping deliver a premiere experience for the digitally inclined investor and trader. Learn more about our work and culture in Morgan Stanley Alpharetta.
Morgan Stanley's goal is to build and maintain a workforce that is diverse in experience and background but uniform in reflecting our standards of integrity and excellence. Consequently, our recruiting efforts reflect our desire to attract and retain the best and brightest from all talent pools. We want to be the first choice for prospective employees.
It is the policy of the Firm to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, creed, age, sex, sex stereotype, gender, gender identity or expression, transgender, sexual orientation, national origin, citizenship, disability, marital and civil partnership/union status, pregnancy, veteran or military service status, genetic information, or any other characteristic protected by law.
Morgan Stanley is an equal opportunity employer committed to diversifying its workforce (M/F/Disability/Vet).
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Morgan Stanley's goal is to build and maintain a workforce that is diverse in experience and background but uniform in reflecting our standards of integrity and excellence. Consequently, our recruiting efforts reflect our desire to attract and retain the best and brightest from all talent pools. We want to be the first choice for prospective employees.
It is the policy of the Firm to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, creed, age, sex, sex stereotype, gender, gender identity or expression, transgender, sexual orientation, national origin, citizenship, disability, marital and civil partnership/union status, pregnancy, veteran or military service status, genetic information, or any other characteristic protected by law.
Morgan Stanley is an equal opportunity employer committed to diversifying its workforce (M/F/Disability/Vet).