Lead Cloud Security Controls Engineer - VP
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.
This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.
Morgan StanleySince 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.
Cyber, Data, Risk & ResilienceCyber, Data, Risk & Resilience delivers first-line defenses to manage technology, information, and cyber risk through risk identification, control management, and assurance. The organization helps the business operate and grow securely, comply with applicable obligations, and respond to an evolving threat landscape.
Role ProfileThe Cloud Security Engineering team enables secure adoption of cloud-native technologies at enterprise scale. We design, implement, test, and operate security controls that protect cloud platforms and make secure deployment easier for application and infrastructure teams.
We are seeking a Lead GCP Platform Cloud Security Controls Engineer, VP, to lead the hands‑on implementation of cloud-native security checks for the GCP platform. The successful candidate will convert security requirements into preventive, detective, and corrective controls across organization‑level guardrails, infrastructure-as-code and CI/CD workflows, and runtime/CSPM monitoring. This role requires deep technical control implementation experience, strong policy‑writing skills, and the ability to connect deploy‑time prevention with runtime assurance and remediation.
Whatyou’ll do in the role:
- Lead the design, coding, testing, deployment, and operation of GCP-native security controls across enterprise GCP organizations, folders, projects, and workloads.
- Translate configuration baseline, architecture, risk, and regulatory requirements into automated, testable, and enforceable cloud security policies.
- Author and maintain GCP organization policies, IAM‑related guardrails, network and data‑perimeter controls, and other native GCP policy mechanisms.
- Apply transferable policy‑engineering patterns from AWS Service Control Policies, Azure Policy, or equivalent cloud‑native governance frameworks.
- Implement preventive controls in Terraform and CI/CD workflows to identify or block noncompliant infrastructure before deployment.
- Implement detective and runtime controls using GCP-native security services, CSPM capabilities, logging, telemetry, event‑driven automation, and drift detection.
- Design corrective workflows and remediation automation for control violations, including clear ownership, prioritization, exception handling, and evidence capture.
- Own the end‑to‑end control lifecycle: requirement interpretation, technical design, policy authoring, peer review, unit and integration testing, controlled rollout, monitoring, tuning, documentation, and retirement.
- Determine the most effective enforcement point for each requirement and identify compensating controls when preventive enforcement is not technically feasible.
- Build reusable policy libraries, common test patterns, modules, and implementation standards that improve consistency and delivery speed.
- Partner with GCP platform engineering, application teams, security architecture, risk, incident response, and control‑assurance stakeholders.
- Troubleshoot complex control failures, false positives, pipeline issues, policy conflicts, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).