Senior Detection Engineer, Director (Assistant VP)

Full time on site
Senior Detection Engineer, Director (Assistant VP)
Job Description

Threat Hunt and Cybersecurity Defense (THCD) is looking for an experienced detection engineer with strong cyber technical skills, Python development experience, and depth in either adversary infrastructure hunting or malware analysis and reverse engineering to join our global team in Singapore.

The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets. As a senior Threat Hunt team member, you will design, build, and maintain detections; hunt for adversary infrastructure, tools, and behaviors; translate technical findings into scalable detections, proactive surveillance capabilities, and security tooling that improve the Firm's ability to identify and respond to emerging threats; automate investigative workflows; and enhance bespoke tools used to defend the Morgan Stanley network.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cybersecurity Engineer position at Director level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Since 1935, Morgan Stanley is known as a global leader in financial services, always

evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role

> Design, develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources.

> Hunt for adversary infrastructure, tooling, command-and-control patterns, phishing infrastructure, staging infrastructure, and attacker abuse of legitimate services.

> Translate infrastructure, tooling, malware analysis and reverse engineering findings, hunt hypotheses, and investigative findings into practical detection strategies and measurable detection coverage.

> Use Python to automate analysis, enrich security data, build investigative workflows, integrate with internal and external APIs, and improve bespoke threat hunting and detection tools.

> Build and maintain tooling that helps analysts and engineers process large data sets, identify infrastructure and tooling patterns, validate detection ideas, reduce manual effort, and accelerate investigation outcomes.

> Analyze security telemetry and suspicious activity to understand attacker behavior, validate detection quality, identify coverage gaps, and recommend engineering improvements.

> Apply adversary infrastructure hunting or malware analysis and reverse engineering expertise to identify detection opportunities, improve investigative context, and strengthen proactive surveillance.

> Work with security analytics platforms, detection-as-code workflows, version control, peer review, and testing practices to improve the quality, maintainability, and reliability of detection content.

> Collaborate with threat intelligence, incident response, and purple team stakeholders to convert technical findings into high-fidelity detections and proactive surveillance opportunities.

> Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and tooling relevant to the Firm's threat landscape.

> Provide technical guidance to junior team members through code reviews, detection reviews, investigation support, documentation, and knowledge sharing.

> Contribute to engineering standards for detection development, Python tooling, testing, documentation, and operational handover.

> Help mature the team's approach to threat-informed defense, adversary infrastructure hunting, malware-informed detection, detection validation, and scalable security analytics.

What you'll bring to the role

> At least 7 years of related hands-on experience in detection engineering, threat hunting, security engineering, incident response, blue teaming, malware analysis and reverse engineering, security operations engineering, or a related cybersecurity field.

> Strong cyber technical knowledge, including adversary tactics, techniques, and procedures; enterprise attack paths; common post-exploitation behaviors; malware and command-and-control patterns; identity abuse; endpoint activity; network behavior; and security telemetry.

> Demonstrated experience in at least one of the following areas: adversary infrastructure hunting, malware analysis and reverse engineering, command-and-control infrastructure analysis, phishing infrastructure analysis, botnet infrastructure hunting, tooling fingerprinting, or attacker abuse of legitimate services.

> Strong Python development skills, including the ability to write maintainable code, work with APIs, process structured and unstructured data, automate complex workflows, troubleshoot issues, and build tools used by other security practitioners.

> Practical experience building automation or tooling for security analysis, detection engineering, threat hunting, incident investigation, data enrichment, infrastructure hunting, tooling fingerprinting, reverse engineering workflows, or operational efficiency.

> Experience analyzing large volumes of security data, logs, alerts, indicators, telemetry, infrastructure patterns, or tool behaviors to identify suspicious activity and understand adversary behavior.

> Strong understanding of detection engineering concepts, including detection design, rule tuning, alert quality, coverage analysis, false-positive reduction, detection validation, and lifecycle management.

> Ability to translate technical findings from infrastructure hunting, tooling analysis, malware analysis and reverse engineering, and investigations into hunting opportunities, detection logic, surveillance strategies, or automated analysis.

> Ability to gather requirements from stakeholders and turn investigative, operational, or technical hunting needs into practical technical solutions.

> Strong written and verbal communication skills, with the ability to explain technical findings, detection logic, and engineering tradeoffs to both technical and non-technical stakeholders.

> Curiosity, analytical rigor, attention to detail, and a desire to build scalable tools and detections that improve cyber defense outcomes.

Skills that would be useful but are not required

> Exposure to adversary emulation, purple-team exercises, red-team collaboration, or threat-informed defense.

> Experience designing dashboards, notebooks, data pipelines, enrichment services, or internal tools for security analysts and investigators.

> Relevant cybersecurity certifications.

What you can expect from Morgan Stanley

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are

supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to

move about the business for those who show passion and grit in their work To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences. For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo .

Share this job:
ES Assistant Online
Hello! I am your AI career assistant. How can I help you today?
130+ Free Online Tools
PDF, Image, SEO & AI Tools
Try Free →