Principal Cyber Security Engineer - Vice President
Morgan Stanley
- Location
- Baltimore, Maryland, United States of America
- Work model
- On-Site
- Level
- Principal
- H-1B history
- 39 approvals (FY2023)
- Posted
- Aug 12, 2026
Skills
About this role
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Principal Cyber Security Engineering position at Vice President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. What you'll do in the role: This position participates in a 24x7 on-call rotation as part of the Cloud Identity engineering organization. Serve as the Principal Engineer and technical authority for Cloud Identity and Access Management across Azure, AWS, and Google Cloud Platform (GCP). Work with the Product Owner and Technical Area Lead on defining and driving the strategic technical vision, architecture, and roadmap for enterprise cloud identity services, ensuring alignment with Firm standards, security requirements, regulatory obligations, and long-term technology objectives. Lead the design and evolution of scalable, resilient, and secure identity platforms supporting workforce, workload, service, and machine identities across multi-cloud environments. Establish architectural standards, reference patterns, and engineering best practices for authentication, authorization, federation, privileged access, and identity governance capabilities. Drive the adoption of cloud-native and automated solutions through infrastructure-as-code, policy-as-code, and platform engineering principles. Partner with senior technology leaders, product owners, security architects, and engineering teams to influence cloud identity strategy and guide critical technology decisions. Lead the technical design and implementation of enterprise-scale identity capabilities, including federation, role-based and attribute-based access control, workload identity management, provisioning, and lifecycle governance. Evaluate emerging cloud and identity technologies, providing recommendations that improve security, operational efficiency, resiliency, and developer experience. Champion automation initiatives by developing frameworks, tooling, and reusable services that improve consistency, observability, and operational excellence across cloud platforms. Act as the highest-level escalation point for complex technical challenges, performing deep root cause analysis and driving durable corrective actions. Mentor and develop engineers, fostering technical excellence and cultivating future technical leaders across the organization. What you'll bring to the role: Experience in executing IT strategy, delivery and complex initiatives. Ability to present information in a clear and concise manner to technology and business leadership. Advanced understanding of functional area and competent understanding of competitive environment. Extensive experience designing, implementing, and operating enterprise-scale Identity and Access Management (IAM) solutions across Azure, AWS, and Google Cloud Platform. Deep expertise in cloud identity architectures, including workforce identities, workload identities, service accounts, federated identities, and machine authentication models. > Proven experience defining technical strategy and architecture for large-scale cloud platforms operating under stringent security and regulatory requirements. Expert-level knowledge of authentication and authorization protocols, including OAuth 2.0, OpenID Connect (OIDC), SAML, Kerberos, SCIM, and emerging workload identity standards. Strong experience implementing identity federation and single sign-on solutions using platforms such as Microsoft Entra ID, PingFederate, Okta, or equivalent enterprise identity providers. Advanced knowledge of cloud-native authorization models, including Azure RBAC, AWS IAM, GCP IAM, ABAC, and policy-based access control frameworks. Significant experience