채용
Benefits & Perks
•Generous paid time off and holidays
•Team events and activities
•Flexible work arrangements
•401(k) matching
•Comprehensive health, dental, and vision insurance
•Professional development budget
•Flexible Hours
•Healthcare
•Learning
Required Skills
Node.js
Python
JavaScript
We're seeking someone to join our team as a Third-Party Security Assessment Specialist in Cyber to deliver security reviews of Third-Party service provides as part of the Security Design assurance process.
The Security Design (Sec Design) team is part of the Cyber Data Risk & Resilience (CDRR) organization. The mission of the Sec Design team is to provide security assessments of technology systems and processes to identify business risks and recommend remedial action based on established security standards or security best practices. The Sec Design Third-Party Security Assurance is an internal function that is working on multiple third-party security initiatives, handling risk assessments, control gap analysis of third-party services in order to remove risks from our environment.
It is an opportunity to get involved in multiple business units and technologies inherent to the mission of Sec Design. The ideal candidate works with the stakeholders and control groups (Technology, Business, risk management, Suppliers and other Stakeholders) globally to perform Sec Design Third-Party security risk posture analysis against firm security policies. The candidate will also be working with a global team of experts on modernizing the Firm's Third-Party security risk assessment processes.
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Third-Party Security Assessment Specialist position at Associate level, which is part of the job family responsible for developing and maintaining software solutions that support business needs.
Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.
What you'll do in the role:
-
Conduct risk assessments of third parties and provide technology requirements to address risks identified. Example areas covered:
Authentication, Authorization, Logging, Monitoring
Network security
Data protection, Cryptography, Secure Data Transport and Storage
SaaS, Cloud Security -
Identify technical control gaps and review security requirements set to remediate identified risks
-
Ensure that the quality of security assessments is consistent and meets expectations
-
Provide architectural and implementation guidance to ensure developers/technology owners follow security best practices.
-
Communicate to the IT System Owners technical details on technical control gaps and provide attack scenarios relevant to the risks identified.
-
Communicate to the IT System Owner detailed remediation guidance.
-
Articulate risks introduced by technical control gaps to the service's Business Owner.
-
Participate in the ongoing improvement of Sec Design Third Party security risk procedures and processes.
-
Build and maintain strong positive relationships with the existing cyber and information security risk community in the respective business and control groups.
What you'll bring to the role:
-
Actively seeking to understand how technology risks arise in different business contexts.
-
Basic knowledge and experience in at least one of the classic security topics such as:
Windows/Unix Operating System security
Risk management
Data protection, data leakage prevention and secure data transfer and storage
Network security -
WAN/LAN/Data Center
Application and Web Security - validation checking, software attack methodologies, OWASP
Cryptography, encryption and hashing -
Previous experience in Financial Services is preferred.
-
Experience working with global organizations is preferred.
-
Proactive approach to identifying issues and proposing solutions
-
Strong communication skills written, oral, presentation.
-
Ability to influence through factual reasoning.
-
Time management: ability to handle multiple concurrent requests, plan based deliverable management, strong follow up and tracking.
-
Strong focus on delivery when presented with short timelines and increased involvement from senior management.
-
Ability to adjust communication of technology risks vs business risks based on the audience.
-
Understanding of geographic regulations and their impact on Security assessments
-
Bachelor's Degree in relevant domain (technology, Cybersecurity)
#BPTECH
YOU CAN EXPECT FROM MORGAN STANLEY:
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work.
To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Certified Persons Regulatory Requirements:
If t his role is deemed a Certified role and may require the role holder to hold mandatory regulatory qualifications or the minimum qualifications to meet internal company benchmarks.
Flexible work statement
Interested in flexible working opportunities? Morgan Stanley empowers employees to have greater freedom of choice through flexible working arrangements. Speak to our recruitment team to find out more.
Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Citi Security Investigative Services Travel Security and People Safety Program - Senior Vice President
Citigroup · LONDON, United Kingdom

Senior Software Engineer, Security AI
Robinhood · Bellevue, WA

Analityk / Analityczka ds. Zarządzania Zabezpieczeniami (Sektor Bankowości Detalicznej)
Citigroup · warsaw

Technology Leadership Program - Risk & Security Analyst
Vanguard · Malvern, PA

Analityk / Analityczka ds. Zarządzania Zabezpieczeniami (Sektor Bankowości Detalicznej)
Citigroup · WARSAW, Poland; LODZ, Poland
About Morgan Stanley

Morgan Stanley
PublicA financial services company that offers securities, asset management, and credit services.
10,001+
Employees
New York
Headquarters
Reviews
3.5
4 reviews
Work Life Balance
3.0
Compensation
2.5
Culture
3.2
Career
3.0
Management
3.0
35%
Recommend to a Friend
Pros
Skills evaluation through business plans and projects
Direct access to senior leadership interviews
Conversational interview format
Cons
Automated resume screening system issues
Focus on formatting over qualifications
Compensation concerns and salary expectations
Salary Ranges
11,766 data points
Junior/L3
Mid/L4
Senior/L5
Junior/L3 · Analyst
1,682 reports
$114,371
total / year
Base
$96,366
Stock
-
Bonus
$18,005
$77,808
$170,800
Interview Experience
6 interviews
Difficulty
3.0
/ 5
Duration
21-35 weeks
Experience
Positive 16%
Neutral 84%
Negative 0%
Interview Process
1
Initial screening (HR/HireVue)
2
Technical rounds
3
Manager/Senior leadership interviews
4
Final round/Superday
Common Questions
Technical knowledge assessment
Behavioral questions
Role-specific scenarios
Leadership and teamwork examples
News & Buzz
Morgan Stanley Expands Crypto Offerings Across ETFs And E*TRADE Platform - simplywall.st
Source: simplywall.st
News
·
5w ago
This is Why Morgan Stanley Feels Atlassian Corporation (TEAM) is a Discount Play - Insider Monkey
Source: Insider Monkey
News
·
5w ago
Morgan Stanley Remains a Buy on Equifax Inc. (EFX) - Insider Monkey
Source: Insider Monkey
News
·
5w ago
KLA Corp. price target raised to $1,751 from $1,697 at Morgan Stanley - Yahoo Finance
Source: Yahoo Finance
News
·
5w ago