Senior CyberSecurity Automation Engineer
Listed on 2026-03-12
-
IT/Tech
Cybersecurity
Company Profile
Morgan Stanley is a leading global financial services firm providing a wide range of investment banking, securities, investment management and wealth management services. The Firm's employees serve clients worldwide including corporations, governments, and individuals from more than 1,200 offices in 41 countries.
As a market leader, the talent and passion of our people is critical to our success. Together, we share a common set of values rooted in integrity, excellence, and dedicated team ethic. Morgan Stanley can provide a superior foundation for building a professional career – a place for people to learn, to achieve and grow. A philosophy that balances personal lifestyles, perspectives, and needs is an important part of our culture.
DepartmentProfile
The mission of the Cyber Data Risk and Resilience division is to ensure the Firm manages its global businesses and serves clients on a market-leading technology platform that is resilient, safe, efficient, smart, fast, and flexible.
The Cyber Incident Response Team (CIRT) is part of the Cyber Data Risk and Resilience division and manages the incident response capability to support day-to-day cross-enterprise event investigations and strategic input into security controls and countermeasures to proactively create better security for the Firm. The group's vision is to deliver programs that protect and enable the business, ensure secure delivery of services to clients, adjust to address the risks presented by an evolving threat landscape, and meet regulatory expectations.
TeamProfile
Morgan Stanley is seeking a Senior Cyber Automation Engineer to join the Firm's Cyber Incident Response Team (CIRT). Global CIRT is a 24/7 operation with members in key geographical locations performing incident response and remediation, campaign assessments, network and host-based forensics.
What You Will Do InThe Role
- Develop, implement, and maintain automated playbooks and workflows in the SOAR platform to streamline SOC operations.
- Integrate the SOAR with various security tools (SIEM, EDR, Email, etc.) using APIs and custom connectors.
- Automate incident triage, investigation, and response processes to reduce manual effort and improve response times.
- Collaborate with analysts and leadership to identify automation opportunities and optimize security operations.
- Maintain up-to-date knowledge of the threat landscape, security technologies and best practices.
- Build, tune, and maintain SOC detections within the SIEM, leveraging scripting and automation to ensure accurate and efficient threat detection.
- Document automation processes, playbooks, and integrations for knowledge sharing and compliance.
The Role
Candidates should have a genuine interest in cyber security and a good understanding of the tactics, techniques, and procedures of attackers. This role requires a detail-oriented critical thinker who can anticipate issues and solve problems.
- 3+ years of experience in developing, implementing, and maintaining automated workflows, and playbooks with SOAR platforms.
- Advanced proficiency in scripting languages such as Python, Power Shell, and Bash for security automation and integration.
- Experience integrating SOAR platforms with various security tools (SIEM, EDR, etc.) using APIs and custom connectors.
- Ability to design, document and optimize automated processes and playbooks for SOC workflow.
- Strong understanding of security operations concepts, triage and investigation, including event management, log collection, and workflow orchestration.
- Excellent written and verbal communication skills for documenting automation processes and collaborating with SOC team members.
- Experience working in a collaborative environment to identify automation opportunities and implement solutions.
- Hands-on experience building, tuning, and maintaining SOC detections within SIEM platforms.
- Hands-on experience with SOAR platform administration and customization (e.g., developing custom integrations, connectors, and modules)
- Familiarity with SIEM technologies, especially in relation to automation and orchestration.
- Possesses knowledge or experience as a member…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).