Senior Detection Engineer, Director (Assistant VP)
Morgan Stanley
- Location
- Singapore, Singapore
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 39 approvals (FY2023)
- Posted
- Sep 1, 2026
Skills
About this role
Threat Hunt and Cybersecurity Defense (THCD) is looking for an experienced detection engineer with strong cyber technical skills, Python development experience, and depth in either adversary infrastructure hunting or malware analysis and reverse engineering to join our global team in Singapore. The THCD mission is to seek out attacks against the Morgan Stanley network, engineer high-quality detection strategies, and reduce risk to Morgan Stanley assets. As a senior Threat Hunt team member, you will design, build, and maintain detections; hunt for adversary infrastructure, tools, and behaviors; translate technical findings into scalable detections, proactive surveillance capabilities, and security tooling that improve the Firm's ability to identify and respond to emerging threats; automate investigative workflows; and enhance bespoke tools used to defend the Morgan Stanley network. In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Cybersecurity Engineer position at Director level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities. Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world. What you'll do in the role > Design, develop, test, tune, and maintain detection logic to identify suspicious activity across endpoint, network, identity, application, and other enterprise telemetry sources. > Hunt for adversary infrastructure, tooling, command-and-control patterns, phishing infrastructure, staging infrastructure, and attacker abuse of legitimate services. > Translate infrastructure, tooling, malware analysis and reverse engineering findings, hunt hypotheses, and investigative findings into practical detection strategies and measurable detection coverage. > Use Python to automate analysis, enrich security data, build investigative workflows, integrate with internal and external APIs, and improve bespoke threat hunting and detection tools. > Build and maintain tooling that helps analysts and engineers process large data sets, identify infrastructure and tooling patterns, validate detection ideas, reduce manual effort, and accelerate investigation outcomes. > Analyze security telemetry and suspicious activity to understand attacker behavior, validate detection quality, identify coverage gaps, and recommend engineering improvements. > Apply adversary infrastructure hunting or malware analysis and reverse engineering expertise to identify detection opportunities, improve investigative context, and strengthen proactive surveillance. > Work with security analytics platforms, detection-as-code workflows, version control, peer review, and testing practices to improve the quality, maintainability, and reliability of detection content. > Collaborate with threat intelligence, incident response, and purple team stakeholders to convert technical findings into high-fidelity detections and proactive surveillance opportunities. > Research emerging adversary tradecraft, malware behaviors, command-and-control patterns, infrastructure usage, and tooling relevant to the Firm's threat landscape. > Provide technical guidance to junior team members through code reviews, detection reviews, investigation support, documentation, and knowledge sharing. > Contribute to engineering standards for detection development, Python tooling, testing, documentation, and operational handover. > Help mature the team's approach to threat-informed defense, adversary infrastructure hunting, malware-informed detection, detection validation, and scalable security analytics. What you'll