Morgan Stanley

Azure Endpoint Security Engineer

New York, NY
USD 150k - 210k
Azure PowerShell Python Perl Ansible API Splunk Microsoft Sentinel BitLocker Intune SCCM Linux MacOS AWS CISSP GSEC
Description

Azure Endpoint Security Engineer- Vice President

Location: New York, New York, United States of America

Time Type: Full time

Job Description

Position Profile:

As a key component of the firm's Technology organisation, the Cyber Data Risk and Resiliency (CDRR) department's mandate is to enable the Firm to manage technology risk through modern, cloud-aligned and AI-informed security practices. CDRR executes first line of defence technology risk management capabilities and implements proactive, comprehensive, and consistent risk management across on-premises and Azure-hosted services.

CDRR protects the Firm's information, endpoints, and infrastructure from cyber and insider threats by delivering operational capabilities and a suite of advanced detection, monitoring, analytics, and automation. The department is driving the implementation and operationalization of AI-assisted investigation and response capabilities (including Microsoft Security Copilot)-covering onboarding, integration with the Microsoft security stack, governance/controls, and measurable improvements to triage speed and response quality. CDRR provides expert advice on secure design, development, and control effectiveness across enterprise endpoints and the Azure platform.

The Team:

The Endpoint Security Team mandate is to implement the Firm's Cybersecurity Strategy by architecting, engineering, deploying, and operating technical security controls and capabilities for the Enterprise across on-premises and the Azure platform. The team designs, develops, and operates solutions that protect desktops, laptops, servers, and cloud resources from malicious internal and external threats by implementing preventative and hardening controls, enabling real-time endpoint detection and response, and leading the implementation of AI-enabled security operations capabilities (including Microsoft Security Copilot)-from solution design and integration through governance, rollout, and ongoing optimization.

Role Profile & Expectations:

  • You will be part of a Global (North America, Europe, Asia) cross-disciplined Agile team working with DevOps practices within the firm's Endpoint Security team, partnering closely with Azure platform and security operations stakeholders.
  • You will have strong Windows Desktop/Infrastructure/Security knowledge and experience operating at very-large enterprise scale across on-premises and Azure environments, including identity, endpoint, and cloud security controls.
  • You will have strong analytical and problem-solving abilities, with experience using security telemetry and analytics to drive decisions, and the communication skills to translate findings into clear actions-including helping implement Microsoft Security Copilot by defining high-value use cases, creating prompt/runbook patterns, validating outputs, and partnering with security operations to drive adoption.
  • You will be responsible for continuously improving the quality of our technology solutions through peer review, retrospectives, refactoring and automation, and by building, operationalizing, and maintaining repeatable AI-assisted runbooks and workflows (including Microsoft Security Copilot) to increase consistency, improve auditability, and reduce mean time to detect/respond.

Required Skills:

  • 10+ years hands-on Enterprise-class Information Technology experience, including security engineering for Windows and cloud platforms (Azure).
  • Strong knowledge of Windows operating system and endpoint internals at 50,000+ endpoint scale, including modern security telemetry and endpoint protection capabilities.
  • Ability to troubleshoot complex Windows OS environments across hybrid architectures (on-premises and Azure), including identity, networking, and security control interactions.
  • Advanced Infrastructure as Code and automation (e.g. Ansible) with Generative AI to streamline playbook creation and infrastructure workflows for efficient operations.
  • Competency with scripting/automation languages such as PowerShell, Python, Perl etc., and the ability to codify operational runbooks (including integrating AI-assisted workflows where appropriate).
  • Experience in designing/engineering/architecting new security solutions from proof of concept to production, including Azure-aligned architectures and operational readiness.
  • Dedication and passion for cybersecurity technologies, with an AI-first and continuous-learning mindset, including a drive to evaluate, implement, and mature emerging capabilities like Microsoft Security Copilot in an enterprise environment.


Desired Skills:

  • Experience with Enterprise-class endpoint and cloud security technologies, especially within the Microsoft security stack (e.g., Microsoft Defender for Endpoint, Microsoft Defender for Cloud, BitLocker, and related capabilities), including experience implementing and operationalizing Microsoft Security Copilot (e.g., integrations, governance/controls, use-case development, rollout, and continuous tuning).
  • Experience with Disk Encryption (e.g. BitLocker) and hardening operating systems.
  • Experience with Microsoft Defender for Cloud Apps (and broader Microsoft security ecosystem integrations). Experience with SCCM/Intune for software deployment and endpoint management, and security logging/analytics platforms such as Splunk and/or Microsoft Sentinel/Azure Monitor for dashboards, reporting, and investigation.
  • Experience working in a DevOps/SRE aligned team.
  • Effective troubleshooting skills across hardware, OS, network, and storage.
  • Experience of platform design, build and deployment, with a focus on continual service improvement (CI/CD).
  • Experience of working in an Agile environment.
  • Experience with Unix/Linux, and MacOS sysadmin a benefit.
  • Experience with API implementations and key management, including HSM-backed designs and/or Azure Key Vault.
  • Enterprise security industry certifications (CISSP, SANS, GSEC etc).
  • Solutions Architect Certifications in either AWS and Azure.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years.  Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Expected base pay rates for the role will be between $150,000 and $210,000 per year at the commencement of employment. However, base pay if hired will be determined on an individualized basis and is only part of the total compensation package, which, depending on the position, may also include commission earnings, incentive compensation, discretionary bonuses, other short and long-term incentive packages, and other Morgan Stanley sponsored benefit programs

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background.  Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Morgan Stanley
Morgan Stanley

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say