Morgan Stanley

API Security Engineering Lead (Hybrid)

Morgan Stanley$125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline.
  • 8+ years of experience in Cybersecurity, Application Security, Security Architecture, Product Management, or Security Program Delivery.
  • Strong understanding of API security, Web Application Firewalls (WAF), Cloud Security, Security Governance and Risk Management.
  • Experience leading large-scale cross-functional initiatives and delivering complex technology programs.
  • Excellent stakeholder management and communication skills.
  • Experience working with third-party security vendors and enterprise security platforms.
  • Experience with API Security platforms such as Akamai/Noname or similar technologies is an asset.
  • Knowledge of DevSecOps and software development lifecycle integration is a nice to have.

Responsibilities

  • Lead the engineering, deployment, and operational management of API Security and API Discovery solutions.
  • Drive onboarding and adoption of API Security capabilities across enterprise applications.
  • Define and execute API inventory, discovery, classification, and governance strategies.
  • Partner with application and infrastructure teams to improve API visibility, threat detection, and risk management.
  • Own and manage the API Security product roadmap and associated project portfolio, including business requirements, success metrics, and implementation plans.
  • Coordinate integration of API Security capabilities with Asset Inventory/CMDB, SDLC and DevSecOps pipelines, Web Application Firewall (WAF) platforms, and security monitoring and analytics solutions.
  • Lead workshops and requirements-gathering sessions with business, technology, and security stakeholders while acting as the primary liaison with external vendors.

Benefits

  • Hybrid work environment combining remote work and office attendance.
  • Opportunity to provide leadership and mentorship to project contributors.
  • Engagement with cutting-edge API security technologies and practices.
Full Job Description

We’re seeking someone to join our team as an API Security Engineering Lead to lead the strategy, governance, discovery, and adoption of API security capabilities across the enterprise, partnering with technology and business stakeholders to strengthen visibility, resilience, and protection of the firm's API ecosystem.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Cyber Security Engineering position at Vice-President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

What you'll do in the role:

  • Lead the engineering, deployment, and operational management of API Security and API Discovery solutions.

  • Drive onboarding and adoption of API Security capabilities across enterprise applications.

  • Define and execute API inventory, discovery, classification, and governance strategies.

  • Partner with application and infrastructure teams to improve API visibility, threat detection, and risk management.

  • Own and manage the API Security product roadmap and associated project portfolio, including business requirements, success metrics, and implementation plans.

  • Coordinate integration of API Security capabilities with Asset Inventory/CMDB, SDLC and DevSecOps pipelines, Web Application Firewall (WAF) platforms, and security monitoring and analytics solutions.

  • Lead workshops and requirements-gathering sessions with business, technology, and security stakeholders while acting as the primary liaison with external vendors.

  • Coordinate implementation efforts, issue resolution, risk management, and governance reviews and manage escalations and ensure timely delivery of commitments.

  • Develop and maintain standards, procedures, operating models, security reviews and audits, security architecture requirements, security metrics, KPIs, and governance processes to support compliance and data protection standards.

  • Provide leadership, mentorship, and guidance to analysts and project contributors, fostering collaboration and continuous improvement across technology, security, and business teams.

What you'll bring to the role:

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline.

  • 8+ years of experience in Cybersecurity, Application Security, Security Architecture, Product Management, or Security Program Delivery.

  • Strong understanding of API security, Web Application Firewalls (WAF), Cloud Security, Security Governance and Risk Management

  • Experience leading large-scale cross-functional initiatives and delivering complex technology programs.

  • Excellent stakeholder management and communication skills.

  • Experience working with third-party security vendors and enterprise security platforms.

  • Experience with API Security platforms such as Akamai/Noname or similar technologies is an asset.

  • Knowledge of DevSecOps and software development lifecycle integration is a nice to have.

All our positions are located in Montreal, Quebec. We offer a hybrid work environment, combining remote work and attendance in the office.

Knowledge of French and English is required.

Chef(fe) de l’ingénierie de la sécurité des API (hybride)

Nous sommes à la recherche d’une personne pour se joindre à notre équipe à titre de chef(fe) de l’ingénierie de la sécurité des API afin de diriger la stratégie, la gouvernance, la découverte et l’adoption des capacités de sécurité des API à l’échelle de l’entreprise, en collaboration avec les parties prenantes des secteurs technologiques et d’affaires afin de renforcer la visibilité, la résilience et la protection de l’écosystème d’API de la société.

Au sein de la division Technologie, nous misons sur l’innovation pour développer les connexions et les capacités qui propulsent notre société et permettent à nos clients et à nos collègues de redéfinir les marchés et de façonner l’avenir de nos collectivités. Il s’agit d’un poste de responsable principal de l’ingénierie en cybersécurité au niveau de vice-président, faisant partie de la famille d’emplois responsable de fournir une expertise spécialisée en cybersécurité et de créer des solutions qui protègent les systèmes et les réseaux de l’organisation contre les menaces et vulnérabilités de sécurité actuelles et potentielles.

Ce que vous ferez dans ce rôle :

  • Diriger l’ingénierie, le déploiement et la gestion opérationnelle des solutions de sécurité et de découverte des API.

  • Favoriser l’intégration et l’adoption des capacités de sécurité des API dans l’ensemble des applications de l’entreprise.

  • Définir et exécuter les stratégies d’inventaire, de découverte, de classification et de gouvernance des API.

  • Collaborer avec les équipes responsables des applications et de l’infrastructure afin d’améliorer la visibilité des API, la détection des menaces et la gestion des risques.

  • Assumer la responsabilité et la gestion de la feuille de route du produit de sécurité des API ainsi que du portefeuille de projets associé, y compris les exigences d’affaires, les indicateurs de réussite et les plans de mise en œuvre.

  • Coordonner l’intégration des capacités de sécurité des API avec l’inventaire des actifs/la CMDB, les pipelines SDLC et DevSecOps, les plateformes de pare-feu d’applications Web (WAF), ainsi que les solutions de surveillance et d’analyse de la sécurité.

  • Animer des ateliers et des séances de collecte des exigences avec les parties prenantes des secteurs d’affaires, de la technologie et de la sécurité, tout en agissant à titre de principal point de contact auprès des fournisseurs externes.

  • Coordonner les activités de mise en œuvre, la résolution des problèmes, la gestion des risques et les examens de gouvernance, gérer les escalades et assurer la livraison des engagements dans les délais prévus.

  • Élaborer et maintenir des normes, procédures, modèles opérationnels, examens et audits de sécurité, exigences d’architecture de sécurité, mesures de sécurité, indicateurs clés de performance (KPI) et processus de gouvernance afin de soutenir les exigences de conformité et les normes de protection des données.

  • Fournir du leadership, du mentorat et de l’encadrement aux analystes et aux contributeurs de projets, en favorisant la collaboration et l’amélioration continue entre les équipes des technologies, de la sécurité et des affaires.

Ce que vous apporterez à ce rôle :

  • Baccalauréat en informatique, en sécurité de l’information, en génie ou dans une discipline connexe.

  • Plus de huit années d’expérience en cybersécurité, en sécurité des applications, en architecture de sécurité, en gestion de produits ou en livraison de programmes de sécurité.

  • Excellente compréhension de la sécurité des API, des pare-feu d’applications Web (WAF), de la sécurité infonuagique, de la gouvernance de la sécurité et de la gestion des risques.

  • Expérience dans la direction d’initiatives de grande envergure impliquant plusieurs fonctions ainsi que dans la livraison de programmes technologiques complexes.

  • Excellentes compétences en gestion des parties prenantes et en communication.

  • Expérience de travail avec des fournisseurs tiers en sécurité et des plateformes de sécurité d’entreprise.

  • L’expérience avec des plateformes de sécurité des API telles qu’Akamai/Noname ou des technologies similaires constitue un atout.

  • Une connaissance de DevSecOps et de l’intégration au cycle de vie du développement logiciel constitue un atout.

Tous nos postes sont situés à Montréal, au Québec. Nous offrons un environnement de travail hybride combinant le télétravail et la présence au bureau.

La connaissance du français et de l’anglais est requise.

About Morgan Stanley

Morgan Stanley Investment Management are active managers of capital, working to outperform the market and deliver results for their clients. Morgan Stanley Investment Management's long-tenured professionals apply their experience and expertise across public and private markets, in single-sector, multi-asset and custom solutions.

Morgan Stanley Careers

Joining Morgan Stanley today means becoming part of a global team dedicated to strengthening communities, pioneering innovation, and fostering diversity. As a leading global financial services firm, Morgan Stanley offers unparalleled job opportunities, career growth, and a culture of leadership that together create an exceptional employment experience. Work You’ll Do At Morgan Stanley, you will collaborate with knowledgeable professionals to drive innovation and deliver solutions in financial services. Our team is composed of diverse, talented individuals who bring their unique skills and perspectives to work every day, setting the standard for leadership in the global market. Morgan Stanley is not just a company; it's a place where ambitious, creative, and skilled individuals can build a rewarding career. Here, you can experience the benefits of a vibrant culture dedicated to professional growth and diversity training. Internship Programs Kickstart your career with Morgan Stanley’s internship programs. These positions offer invaluable industry insights and professional experience to students and recent graduates. Interns at Morgan Stanley gain hands-on experience, working alongside seasoned experts in a dynamic, supportive environment. Innovation and Professional Growth We believe in the power of innovation to solve complex problems and encourage our team to think differently and act boldly. Morgan Stanley supports your career development through comprehensive training, development programs, and leadership workshops, ensuring that every employee has the tools they need to succeed. Join Our Team Explore the various job opportunities at Morgan Stanley, from entry-level positions to executive roles. We are hiring individuals who are passionate about finance and eager to contribute to a team that values integrity, excellence, and a forward-thinking mindset. Enhance your skills through our networking events, mentorship opportunities, and ongoing professional development. Stay Connected Keep up to date with the latest from Morgan Stanley Careers by subscribing to our job alert emails. Tailor your preferences to receive updates about new postings, career tips, and exclusive insights from our team leaders. Apply Now Ready to take the next step in your career? Search open positions that match your skills and interests on the Morgan Stanley Jobs portal. Prepare your resume, refine your interview techniques, and join a company that values innovation and leadership. At Morgan Stanley, we’re not just building careers—we’re developing leaders. Discover how far your talents can take you by joining our team today.
Learn more about Morgan Stanley
Size
77,000 employees
Market Cap
$144.1 billion
Industry
Net Income
$10.9 billion
Founded
1935
5 Year Trend
+10%
Revenue
$52 billion
NASDAQ

Similar Jobs

More Jobs at Morgan Stanley

More Information Technology Jobs

Find similar API Security Engineering Lead (Hybrid) jobs: