API Security Engineering Lead (Hybrid)
Morgan Stanley
- Location
- Montreal, Canada
- Work model
- Hybrid
- Level
- Senior
- H-1B history
- 39 approvals (FY2023)
- Posted
- Sep 16, 2026
Skills
About this role
We’re seeking someone to join our team as an API Security Engineering Lead to lead the strategy, governance, discovery, and adoption of API security capabilities across the enterprise, partnering with technology and business stakeholders to strengthen visibility, resilience, and protection of the firm's API ecosystem. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Cyber Security Engineering position at Vice-President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. What you'll do in the role: Lead the engineering, deployment, and operational management of API Security and API Discovery solutions. Drive onboarding and adoption of API Security capabilities across enterprise applications. Define and execute API inventory, discovery, classification, and governance strategies. Partner with application and infrastructure teams to improve API visibility, threat detection, and risk management. Own and manage the API Security product roadmap and associated project portfolio, including business requirements, success metrics, and implementation plans. Coordinate integration of API Security capabilities with Asset Inventory/CMDB, SDLC and DevSecOps pipelines, Web Application Firewall (WAF) platforms, and security monitoring and analytics solutions. Lead workshops and requirements-gathering sessions with business, technology, and security stakeholders while acting as the primary liaison with external vendors. Coordinate implementation efforts, issue resolution, risk management, and governance reviews and manage escalations and ensure timely delivery of commitments. Develop and maintain standards, procedures, operating models, security reviews and audits, security architecture requirements, security metrics, KPIs, and governance processes to support compliance and data protection standards. Provide leadership, mentorship, and guidance to analysts and project contributors, fostering collaboration and continuous improvement across technology, security, and business teams. What you'll bring to the role: Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline. 8+ years of experience in Cybersecurity, Application Security, Security Architecture, Product Management, or Security Program Delivery. Strong understanding of API security, Web Application Firewalls (WAF), Cloud Security, Security Governance and Risk Management Experience leading large-scale cross-functional initiatives and delivering complex technology programs. Excellent stakeholder management and communication skills. Experience working with third-party security vendors and enterprise security platforms. Experience with API Security platforms such as Akamai/Noname or similar technologies is an asset. Knowledge of DevSecOps and software development lifecycle integration is a nice to have. All our positions are located in Montreal, Quebec. We offer a hybrid work environment, combining remote work and attendance in the office. Knowledge of French and English is required. WHAT YOU CAN EXPECT FROM MORGAN STANLEY: At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the