
Senior Cloud Security Engineer
Responsibilities
Qualifications & Requirements
Experience Level: Senior Level
Full Job Description
About the Role
Morgan Stanley is seeking a Senior Cloud Security Engineer with a Director level focus within the Cloud & Infrastructure Engineering team. This role is based in Bengaluru, Karnataka, India.
The successful candidate will be responsible for conducting in-depth security research and testing across major cloud platforms including Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). You will develop and publish firm-wide security requirements to ensure the secure adoption and operation of cloud services at scale.
Key responsibilities include providing essential security expertise to engineering and development teams, identifying and mitigating risks on projects where security requirements may be challenging to meet within project timelines, and proposing necessary compensating controls.
Key Responsibilities
- Conduct in-depth security research and testing of cloud services across Microsoft Azure, AWS, and GCP.
- Develop firm-wide security requirements enabling the secure use of cloud services at massive scale.
- Define and publish firm-wide security requirements for the secure, large-scale use of cloud services.
- Provide expert security guidance to engineering and development teams.
- Identify project risks related to security requirements and propose mitigating controls when full implementation is not feasible within project timelines.
Qualifications and Skills
- Demonstrated cloud security experience with at least one major Cloud Service Provider (GCP, AWS, Azure).
- Experience with modern authentication technologies such as OAuth2, OpenID Connect, and SAML 2.0.
- Familiarity with logging and data pipeline concepts and architectures in cloud environments.
- Experience in penetration testing, reverse engineering, incident response, or forensic analysis is considered an asset.
- Experience with cloud technologies for protecting data at rest and in transit, including key management practices.
- Proficiency with infrastructure as code tools, such as Terraform, and CI/CD pipelines.
- Experience with Kubernetes or similar workload orchestration platforms.
- Knowledge of traditional network technologies, including firewalls, NAT, load balancers, and web proxies.