Web Security Engineer
Listed on 2025-12-01
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, Network Security
Overview
Join to apply for the Web Security Engineer role at Morgan Stanley
. In the Technology division, we leverage innovation to power our Firm and support clients and colleagues to redefine markets. This is a Lead Cybersecurity Engineering position at Vice President level, part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.
Since 1935, Morgan Stanley is a global leader in financial services, evolving to better serve our clients and communities in more than 40 countries.
We are seeking an experienced Web Security / Network Security subject matter expert to join our Web Security Operations. The team is responsible for the day-to-day operations, security, and health of Morgan Stanley's Web Proxy infrastructure on which thousands of web applications run. The specialist will act as an SME for web security, handle operational escalations from our L2 teams, respond to incident management notifications, and deliver robust, effective solutions covering our internet perimeter and external content delivery network providers.
Responsibilities- Provide Level 3 Operations support for a global perimeter Web proxy and Web security enterprise infrastructure
- Maintain Web security infrastructure, providing stability by developing tools, policies, processes and procedures for the operations teams
- Lead projects, analyze and prioritize workload based on business risk and requirements
- Take ownership of incidents, problems, follow-up actions and manage to resolution
- Plan and review production changes following firm Change Management process and procedure
- Provide Web Security consultancy services to other internal Technology teams
- Provide architecture assurance on Web Security initiatives
- Establish effective working relationships with Engineering counterparts and other stakeholders in the Web Security space
- Provide a secure environment by implementing controls to manage and mitigate risks
- Develop automated metrics reporting capabilities
- Create, review, maintain and update documentation including documenting and publishing fixes in our central knowledge base
- Work with global colleagues to provide globally consistent processes and solutions
- Investigate and troubleshoot root causes when escalated from operations
- Escalate and liaise with additional internal/external groups when required
- Input into Business Continuity Planning and Practices
- Integration and testing, and deployment of Web Proxy technologies with leading network DLP or Malware scanning solutions
- Collaborate with leads responsible for web and application servers, load-balancers and web authentication infrastructure
- Work with colleague subject matter experts in the wider organization who administer networks, logging, application architecture and other complementary technologies
- Drive determination and implementation of security best practice in our web platforms and infrastructure
- Research into vendor and open-source solutions in the web security space, and determine their place in our overall solution
- Interface with technical contacts at external vendor providers and internal teams to ensure a holistic solution is delivered and enhanced
- Training operations L2 personnel, application support groups in tools, technologies and procedures
- Moderate-Advanced direct experience with Proxy technologies
- Netskope, Bluecoat, Fortinet, Palo Alto, ZScaler, ZPA, SSLi, Cloud DLP, Cloud Sandboxing
- Moderate-Advanced proxy experience including engineering of flows via proxy and client access for troubleshooting;
Netskope, Bluecoat Proxy
SG Appliance, Netskope or Zscaler experience preferred - Must know how to integrate external services with proxies via ICAP, proxy chaining, and service offloads
- Moderate cloud security experience across at least a couple of the major cloud providers (Azure, O365, AWS, etc.)
- Excellent understanding and experience designing and implementing Web security solutions
- Good understanding of Web Proxy infrastructure serving various application layer protocols (HTTP/HTTPS/SOCKS/FTP/ICAP)
- Scripting and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).