- Company Name
- Morgan Stanley
- Job Title
- Application Security Team Lead
- Job Description
-
**Job Title**
Application Security Team Lead
**Role Summary**
Lead a team of 4+ application security engineers to design, implement, and maintain secure software development practices across the organization. Drive application security excellence, integrating security tools into CI/CD pipelines, conducting design reviews, and reporting on security posture to executive stakeholders.
**Expectations**
- Steer security strategy for application development life‑cycle.
- Maintain compliance with industry standards and regulatory requirements.
- Foster a culture of developer enablement and security-awareness.
- Deliver measurable improvements to security metrics and risk reduction.
**Key Responsibilities**
- Manage and mentor the application security engineering team.
- Design security architecture for new and existing applications.
- Integrate SAST, SCA, DAST, container scanning, and other security tools into CI/CD pipelines.
- Conduct threat modeling, security design reviews, and vulnerability assessments.
- Compile and present key security metrics to business leaders and executive stakeholders.
- Document architecture decisions, security policies, and incident response procedures.
- Coordinate cross‑functional initiatives with DevOps, product, and risk teams.
- Keep up to date with emerging threats, industry frameworks (e.g., NIST, ISO 27001), and regulatory changes.
**Required Skills**
- 10+ years in application security, 5+ years in general IT roles.
- Deep knowledge of SDLC, vulnerability management, penetration testing, and security frameworks.
- Hands‑on experience with SAST, SCA, DAST, container scanning, and CI/CD integration.
- Strong understanding of cybersecurity domains: data protection, cryptography, network security, WAF, IAM.
- Proficiency with web protocols (TCP/IP, HTTP, SSL/TLS).
- Familiarity with Python, PostgreSQL, MongoDB.
- Leadership, stakeholder management, and cross‑functional collaboration skills.
- Analytical problem‑solving, design‑thinking, and risk communication abilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Relevant security certifications preferred (e.g., CISSP, CISM, CEH, or equivalent).
- Knowledge of regulatory compliance (e.g., PCI DSS, GDPR, SOX) is advantageous.