Lead GCP Security Engineer_Vice President_Security Engineering
Morgan Stanley
- Location
- Bengaluru, India
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 39 approvals (FY2023)
- Posted
- 12h ago
Skills
About this role
Lead GCP Security Engineer We are looking for Lead GCP Security Engineer at VP Level to join our Cloud Security Platform & Development Engineering team in Bengaluru as part of CDRR Division The Cloud Security Engineering team is responsible for securely enabling the use of cloud technologies to support the firm's desire to leverage cloud-native services at enterprise scale. The Cloud Security Engineering team designs the security requirements that must be adhered to in cloud as well as builds the tooling and automation needed to provide enterprise capabilities to protect the firm and make securing workloads easier for application teams. The Cloud Security Engineering team works with multiple cloud providers and is currently looking for an experienced Lead GCP Security Engineer familiar with cloud computing concepts, Google cloud services, infrastructure as code, and programming languages. The team this engineer will join implements security controls into our cloud platforms (detective, preventative, and corrective) and owns platforms used to further secure our cloud footprint. This team also works to enable infrastructure and application development teams to extend their services to cloud environments. What you will do in the role : Developing, testing, and deploying GCP security controls across the firm’s GCP tenants Providing security recommendations and solutions for migrating legacy applications and for deploying new applications in the Morgan Stanley environment in GCP Working closely with vendors and partner squads to develop, deploy, and test Cloud security services Responding to GCP cloud configuration drifts in timely manner and working with the stakeholders to remediate drifts Integrating, configuring, documenting, and deploying compliant infrastructure and supporting services in AWS, Azure, and GCP Troubleshooting complex technical problems, analyzing root cause, and (where possible) fixing bugs introduced by owned or managed security solutions Collaborating with Risk Management, Security Architecture, and Cyber Incident Response teams to ensure necessary controls to Cloud services are deployed and tested Working in a globally distributed team to provide innovative and robust Cloud-centric solutions What you will bring to the role : Knowledge of the Shared Responsibility Model; keen understanding of the security risks inherent in hosting cloud-based applications and data Experience developing across the security assurance lifecycle (including prevent, detect, respond, and remediate controls) Experience configuring GCP native security policy and capabilities Experience solutioning and configuring event-driven serverless-based security controls in GCP Deep understanding of DevOps processes and workflows. Working knowledge of the Secure SDLC process. Experience with Infrastructure as Code (IaC) tooling such as Terraform Familiarity with standard GCP security tooling such as Security Command Center and VPC Service Controls Familiarity with Logging and data pipeline concepts and architectures in cloud. Strong in scripting languages such as PowerShell, Python and Bash. Experience creating technical architecture documentation. Excellent communication, written and interpersonal skills. Practical experience in designing and configuring CICD pipelines. Practical experience in GitHub Actions and Jenkins. Experience in ITSM. Ability to articulate complex technical concepts to non-technical stakeholders. Experience with risk control frameworks and engagements with risk and regulatory functions Experience in the financial industry would be a plus. GCP Certifications would be a plus. 6+ years of relevant experience WHAT YOU CAN EXPECT FROM MORGAN STANLEY: At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading