Hiring.Camp

Lead Cloud Security Controls Engineer - VP

Morgan Stanley

·

Yesterday

Location
Alpharetta, GA,US, US
Type
Full-time
Department
Engineering
Seniority
Lead
Education
Bachelor
Source
Eightfold

Description

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.

This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Morgan Stanley Since 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

Cyber, Data, Risk & Resilience:

Cyber, Data, Risk & Resilience delivers first-line defenses to manage technology, information, and cyber risk through risk identification, control management, and assurance. The organization helps the business operate and grow securely, comply with applicable obligations, and respond to an evolving threat landscape.

Role Profile:

The Cloud Security Engineering team enables secure adoption of cloud-native technologies at enterprise scale. We design, implement, test, and operate security controls that protect cloud platforms and make secure deployment easier for application and infrastructure teams.

We are seeking a Lead GCP Platform Cloud Security Controls Engineer, VP, to lead the hands-on implementation of cloud-native security checks for the GCP platform. The successful candidate will convert security requirements into preventive, detective, and corrective controls across organization-level guardrails, infrastructure-as-code and CI/CD workflows, and runtime/CSPM monitoring. This role requires deep technical control implementation experience, strong policy-writing skills, and the ability to connect deploy-time prevention with runtime assurance and remediation.

What you'll do in the role:

  • Lead the design, coding, testing, deployment, and operation of GCP-native security controls across enterprise GCP organizations, folders, projects, and workloads.
  • Translate configuration baseline, architecture, risk, and regulatory requirements into automated, testable, and enforceable cloud security policies.
  • Author and maintain GCP organization policies, IAM-related guardrails, network and data-perimeter controls, and other native GCP policy mechanisms.
  • Apply transferable policy-engineering patterns from AWS Service Control Policies, Azure Policy, or equivalent cloud-native governance frameworks.
  • Implement preventive controls in Terraform and CI/CD workflows to identify or block noncompliant infrastructure before deployment.
  • Implement detective and runtime controls using GCP-native security services, CSPM capabilities, logging, telemetry, event-driven automation, and drift detection.
  • Design corrective workflows and remediation automation for control violations, including clear ownership, prioritization, exception handling, and evidence capture.
  • Own the end-to-end control lifecycle: requirement interpretation, technical design, policy authoring, peer review, unit and integration testing, controlled rollout, monitoring, tuning, documentation, and retirement.
  • Determine the most effective enforcement point for each requirement and identify compensating controls when preventive enforcement is not technically feasible.
  • Build reusable policy libraries, common test patterns, modules, and implementation standards that improve consistency and delivery speed.
  • Partner with GCP platform engineering, application teams, security architecture, risk, incident response, and control-assurance stakeholders.
  • Troubleshoot complex control failures, false positives, pipeline issues, policy conflicts, and production security events; drive root-cause resolution.
  • Define implementation metrics and technical evidence that demonstrate control coverage, effectiveness, exceptions, and remediation status.
  • Provide technical direction, code and design review, and hands-on mentorship to engineers while maintaining direct involvement in critical implementations.

What you'll bring to the role:

  • Bachelors degree in computer science, Information Security, or a related field, or equivalent experience.
  • 7+ years of hands-on cloud security, platform security, security engineering, or cloud control engineering experience.
  • Demonstrated production experience implementing security controls in GCP, including direct policy authoring, testing, deployment, and operational support.
  • Hands-on experience with GCP organization policies and one or more relevant native security capabilities such as IAM, VPC Service Controls, Security Command Center, Cloud Logging, event-driven services, or organization-level governance.
  • Experience authoring cloud-native preventive policies, with GCP experience preferred; comparable experience with AWS Service Control Policies, Azure Policy, or similar guardrail frameworks is relevant.
  • Strong Terraform and infrastructure-as-code experience, including module usage, plan evaluation, policy validation, testing, and secure deployment patterns.
  • Practical experience integrating security checks and enforcement gates into CI/CD pipelines using Git-based engineering workflows.
  • Experience implementing runtime or CSPM controls, including posture evaluation, cloud configuration monitoring, drift detection, alert tuning, and remediation workflows.
  • Ability to translate written security requirements into clear technical control logic, test cases, acceptance criteria, and implementation evidence.
  • Proficiency in at least one scripting or programming language such as Python, Go, Bash, or PowerShell.
  • Strong understanding of GCP security architecture, including identity and access management, networking, service perimeters, encryption and key management, logging, workload security, and data protection.
  • Experience with software engineering practices for policy and automation code, including version control, peer review, unit testing, integration testing, release management, and troubleshooting.
  • Ability to communicate technical decisions, risks, dependencies, and implementation status to engineering teams and senior stakeholders.

Preferred Qualifications

  • Experience with policy-as-code technologies such as OPA/Rego, Conftest, Terraform policy frameworks, or comparable validation engines.
  • Experience designing event-driven corrective controls using GCP serverless services and cloud telemetry.
  • Experience integrating CSPM platforms with native GCP controls and deploy-time policy enforcement.
  • Experience building shared policy libraries or control frameworks for multiple teams, environments, or cloud services.
  • Experience working in a regulated enterprise and producing traceable control implementation evidence.
  • Relevant GCP security or professional cloud certification.
  • Experience leading or mentoring engineers while remaining hands-on with architecture, code, testing, and incident troubleshooting.
  • Leadership and Collaboration
  • Set technical direction and implementation standards for GCP platform security controls.
  • Mentor engineers in cloud-native policy design, Terraform, secure delivery pipelines, runtime assurance, testing, and operational support.
  • Create a high-accountability engineering culture with clear ownership, practical documentation, strong reviews, and measurable outcomes.
  • Influence platform and application designs through credible, hands-on engineering expertise and constructive cross-functional partnership.

What You Can Expect:

You will work with skilled engineers and security professionals in an environment that values technical depth, intellectual rigor, collaboration, and responsible innovation. The role offers the opportunity to shape cloud security controls at enterprise scale and improve how security requirements are implemented, measured, and sustained across the GCP platform.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Skills

PythonAWSAzureGCPTerraformCI/CDGitGo

Similar Jobs

30

Lead Cloud Security Controls Engineer - VP

Ms·Alpharetta GA 3, US

1d ago

Lead Cloud Security Engineer

JPMorgan Chase·Dublin, IE

2d ago

Lead Cloud Security Engineer

JP Morgan Chase·Dublin, IE

2d ago

Lead Cloud Security Engineer

Depository Trust Company·Tampa, FL

1w ago

Principal Security Lead- Cloud

Nokia·US·Onsite

1mo ago

Security Cloud Lead Enterprise Architect

Barclays·Chennai, DLF IT Park

2mo ago

Senior Lead Cloud Security Architect

Cox brings together the world·Atlanta, GA - 6305 Peachtree Dunwoody Rd Bldg A·Remote, Hybrid

2mo ago

Application & Cloud Security Lead

Spgi·IN - HYDERABAD SKYVIEW, India +2

2mo ago

Application & Cloud Security Lead

Spgi·IN - HYDERABAD SKYVIEW, India +2

2mo ago

Sr Lead, Cloud Security Engineering

NT Careers·Chicago, IL·Hybrid

3mo ago

Devoteam Cyber Trust | Lead Cloud Security Consultant — Microsoft Focus

Devoteam·Lisboa, Portugal·Hybrid

3mo ago

Lead Cloud Security/AppSec Engineer

Flagshippioneeringinc·Cambridge, MA USA +1

5mo ago

Oracle Cloud Security & Configuration Lead

Nffinc·Washington DC, US·Remote

3d ago

Cloud Security Capability Lead

Cummins·Columbus, IN·Onsite

1w ago

Lead Security Engineer- Cloud Devops Engineer

JPMorgan Chase·Plano, TX

1w ago

Lead Security Engineer- Cloud Devops Engineer

JP Morgan Chase·Plano, TX

1w ago

Lead Security Engineer - Cloud Threat Hunting

JPMorgan Chase·OH, US

1w ago

Lead Security Engineer - Cloud Threat Hunting

JP Morgan Chase·OH, US

1w ago

Cloud Security Automation Lead

Cummins·Columbus, IN·Onsite

1w ago

Lead Security Architect – Cloud Platform & Network Security

Logos Space·Mountain View or San Diego +2·Onsite

4w ago

Security Lead - Senior Cloud Security Engineer

Steampunk Inc.·McLean, VA

1mo ago

Lead Security Architect-Cloud Migration

Unisys·Canberra 6th floor, Australia·Onsite

1mo ago

Lead Security Architect – Cloud Data & AI Platforms

cartech·Philadelphia, PA·Hybrid

3mo ago

Lead ISSE / Cloud Security Engineer

Bowhead Uicalaska·Montgomery, AL·Hybrid

3mo ago

Cloud Security Architect Lead

Freddiemac·Headquarters 2, US +1

4mo ago

SAP Cloud Security Senior Lead

Mars·GSW-Mars Global Services, Poland·Hybrid

7mo ago

Senior Lead Security Engineer - Google Cloud.

JPMorgan Chase·Dublin, IE

1w ago

Senior Lead Security Engineer - Google Cloud.

JP Morgan Chase·Dublin, IE

1w ago

Sr. Lead Security Engineer - Google Cloud Platform

JPMorgan Chase·Dublin, IE

2mo ago

Sr. Lead Security Engineer - Google Cloud Platform

JP Morgan Chase·Dublin, IE

2mo ago