Morgan Stanley

Lead Cloud Security Controls Engineer - VP

Morgan Stanley • $150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, Information Security, or related field, or equivalent experience.
  • 7+ years of hands-on experience in cloud security and platform security.
  • Expertise in implementing security controls in GCP, including policy authoring and operational support.
  • Proficient in Terraform and infrastructure-as-code methodologies.
  • Strong understanding of GCP security architecture and native security capabilities.
  • Experience integrating security checks into CI/CD pipelines using Git-based workflows.
  • Ability to translate security requirements into technical control logic and test cases.

Responsibilities

  • Lead design and implementation of GCP-native security controls for enterprise level.
  • Translate risk and regulatory requirements into automated cloud security policies.
  • Author and maintain policies and guardrails related to GCP organization security.
  • Implement preventive controls in Terraform and CI/CD workflows to ensure compliance.
  • Utilize GCP-native services for detective and runtime controls including monitoring and remediation.
  • Manage the full control lifecycle from design to retirement, including peer review and testing.
  • Troubleshoot control failures and policy conflicts to maintain security integrity.

Benefits

  • Collaborative environment with skilled engineers and security professionals.
  • Opportunity to influence and improve security practices at enterprise scale.
  • Engagement in responsible innovation within cloud security architecture.
Full Job Description
This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Role Profile:
The Cloud Security Engineering team enables secure adoption of cloud-native technologies at enterprise scale. We design, implement, test, and operate security controls that protect cloud platforms and make secure deployment easier for application and infrastructure teams.

We are seeking a Lead GCP Platform Cloud Security Controls Engineer, VP, to lead the hands-on implementation of cloud-native security checks for the GCP platform. The successful candidate will convert security requirements into preventive, detective, and corrective controls across organization-level guardrails, infrastructure-as-code and CI/CD workflows, and runtime/CSPM monitoring. This role requires deep technical control implementation experience, strong policy-writing skills, and the ability to connect deploy-time prevention with runtime assurance and remediation.

What you'll do in the role:
  • Lead the design, coding, testing, deployment, and operation of GCP-native security controls across enterprise GCP organizations, folders, projects, and workloads.
  • Translate configuration baseline, architecture, risk, and regulatory requirements into automated, testable, and enforceable cloud security policies.
  • Author and maintain GCP organization policies, IAM-related guardrails, network and data-perimeter controls, and other native GCP policy mechanisms.
  • Apply transferable policy-engineering patterns from AWS Service Control Policies, Azure Policy, or equivalent cloud-native governance frameworks.
  • Implement preventive controls in Terraform and CI/CD workflows to identify or block noncompliant infrastructure before deployment.
  • Implement detective and runtime controls using GCP-native security services, CSPM capabilities, logging, telemetry, event-driven automation, and drift detection.
  • Design corrective workflows and remediation automation for control violations, including clear ownership, prioritization, exception handling, and evidence capture.
  • Own the end-to-end control lifecycle: requirement interpretation, technical design, policy authoring, peer review, unit and integration testing, controlled rollout, monitoring, tuning, documentation, and retirement.
  • Determine the most effective enforcement point for each requirement and identify compensating controls when preventive enforcement is not technically feasible.
  • Build reusable policy libraries, common test patterns, modules, and implementation standards that improve consistency and delivery speed.
  • Partner with GCP platform engineering, application teams, security architecture, risk, incident response, and control-assurance stakeholders.
  • Troubleshoot complex control failures, false positives, pipeline issues, policy conflicts, and production security events; drive root-cause resolution.
  • Define implementation metrics and technical evidence that demonstrate control coverage, effectiveness, exceptions, and remediation status.
  • Provide technical direction, code and design review, and hands-on mentorship to engineers while maintaining direct involvement in critical implementations.


What you'll bring to the role:
  • Bachelors degree in computer science, Information Security, or a related field, or equivalent experience.
  • 7+ years of hands-on cloud security, platform security, security engineering, or cloud control engineering experience.
  • Demonstrated production experience implementing security controls in GCP, including direct policy authoring, testing, deployment, and operational support.
  • Hands-on experience with GCP organization policies and one or more relevant native security capabilities such as IAM, VPC Service Controls, Security Command Center, Cloud Logging, event-driven services, or organization-level governance.
  • Experience authoring cloud-native preventive policies, with GCP experience preferred; comparable experience with AWS Service Control Policies, Azure Policy, or similar guardrail frameworks is relevant.
  • Strong Terraform and infrastructure-as-code experience, including module usage, plan evaluation, policy validation, testing, and secure deployment patterns.
  • Practical experience integrating security checks and enforcement gates into CI/CD pipelines using Git-based engineering workflows.
  • Experience implementing runtime or CSPM controls, including posture evaluation, cloud configuration monitoring, drift detection, alert tuning, and remediation workflows.
  • Ability to translate written security requirements into clear technical control logic, test cases, acceptance criteria, and implementation evidence.
  • Proficiency in at least one scripting or programming language such as Python, Go, Bash, or PowerShell.
  • Strong understanding of GCP security architecture, including identity and access management, networking, service perimeters, encryption and key management, logging, workload security, and data protection.
  • Experience with software engineering practices for policy and automation code, including version control, peer review, unit testing, integration testing, release management, and troubleshooting.
  • Ability to communicate technical decisions, risks, dependencies, and implementation status to engineering teams and senior stakeholders.


Preferred Qualifications
  • Experience with policy-as-code technologies such as OPA/Rego, Conftest, Terraform policy frameworks, or comparable validation engines.
  • Experience designing event-driven corrective controls using GCP serverless services and cloud telemetry.
  • Experience integrating CSPM platforms with native GCP controls and deploy-time policy enforcement.
  • Experience building shared policy libraries or control frameworks for multiple teams, environments, or cloud services.
  • Experience working in a regulated enterprise and producing traceable control implementation evidence.
  • Relevant GCP security or professional cloud certification.
  • Experience leading or mentoring engineers while remaining hands-on with architecture, code, testing, and incident troubleshooting.
  • Leadership and Collaboration
  • Set technical direction and implementation standards for GCP platform security controls.
  • Mentor engineers in cloud-native policy design, Terraform, secure delivery pipelines, runtime assurance, testing, and operational support.
  • Create a high-accountability engineering culture with clear ownership, practical documentation, strong reviews, and measurable outcomes.
  • Influence platform and application designs through credible, hands-on engineering expertise and constructive cross-functional partnership.


What You Can Expect:
You will work with skilled engineers and security professionals in an environment that values technical depth, intellectual rigor, collaboration, and responsible innovation. The role offers the opportunity to shape cloud security controls at enterprise scale and improve how security requirements are implemented, measured, and sustained across the GCP platform.

About Morgan Stanley

Morgan Stanley Investment Management are active managers of capital, working to outperform the market and deliver results for their clients. Morgan Stanley Investment Management's long-tenured professionals apply their experience and expertise across public and private markets, in single-sector, multi-asset and custom solutions.

Morgan Stanley Careers

Joining Morgan Stanley today means becoming part of a global team dedicated to strengthening communities, pioneering innovation, and fostering diversity. As a leading global financial services firm, Morgan Stanley offers unparalleled job opportunities, career growth, and a culture of leadership that together create an exceptional employment experience. Work You’ll Do At Morgan Stanley, you will collaborate with knowledgeable professionals to drive innovation and deliver solutions in financial services. Our team is composed of diverse, talented individuals who bring their unique skills and perspectives to work every day, setting the standard for leadership in the global market. Morgan Stanley is not just a company; it's a place where ambitious, creative, and skilled individuals can build a rewarding career. Here, you can experience the benefits of a vibrant culture dedicated to professional growth and diversity training. Internship Programs Kickstart your career with Morgan Stanley’s internship programs. These positions offer invaluable industry insights and professional experience to students and recent graduates. Interns at Morgan Stanley gain hands-on experience, working alongside seasoned experts in a dynamic, supportive environment. Innovation and Professional Growth We believe in the power of innovation to solve complex problems and encourage our team to think differently and act boldly. Morgan Stanley supports your career development through comprehensive training, development programs, and leadership workshops, ensuring that every employee has the tools they need to succeed. Join Our Team Explore the various job opportunities at Morgan Stanley, from entry-level positions to executive roles. We are hiring individuals who are passionate about finance and eager to contribute to a team that values integrity, excellence, and a forward-thinking mindset. Enhance your skills through our networking events, mentorship opportunities, and ongoing professional development. Stay Connected Keep up to date with the latest from Morgan Stanley Careers by subscribing to our job alert emails. Tailor your preferences to receive updates about new postings, career tips, and exclusive insights from our team leaders. Apply Now Ready to take the next step in your career? Search open positions that match your skills and interests on the Morgan Stanley Jobs portal. Prepare your resume, refine your interview techniques, and join a company that values innovation and leadership. At Morgan Stanley, we’re not just building careers—we’re developing leaders. Discover how far your talents can take you by joining our team today.
Learn more about Morgan Stanley
Size
77,000 employees
Market Cap
$144.1 billion
Industry
Net Income
$10.9 billion
Founded
1935
5 Year Trend
+10%
Revenue
$52 billion
NASDAQ

Similar Jobs

More Jobs at Morgan Stanley

More Information Technology Jobs

Find similar Lead Cloud Security Controls Engineer - VP jobs: