Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP

ms· 474 MS Services Group, Inc.
Apply Now ↗

About this role

We’re seeking someone to join our team as a Cyber Threat Intelligence - Technical Analysis and Investigations Lead in Technology to lead technical threat investigations, track sophisticated adversaries, and operationalize technical intelligence for detection and response.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities.

This is a Cyber Security Engineering position at VP which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Since 1935, Morgan Stanley is known as a global leader in financial services, continuously evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role:

  • Lead proactive threat hunts and advanced discovery to identify adversary campaigns, capabilities, infrastructure, and targets using internal collection, OSINT, and vendor intelligence.
    Research and track advanced threat actors and malware, maintaining deep technical understanding of adversary TTPs and tradecraft.

  • Author high-impact technical threat intelligence products and reports tailored to both operational teams and senior stakeholders. 

  • Develop and advance investigative tradecraft, analytic techniques, and automation to improve speed, repeatability, and fidelity of analytic workflows (including Python-based analytics). 
    Enrich, triage, and characterize threat insights and indicators by leveraging open-source and commercial tooling, and curate high-fidelity IOCs for operational use. 

  • Partner with threat hunting and security response teams to translate technical intelligence into detection opportunities, mitigations, and control validation activities.

  • Maintain and curate threat profiles aligned to areas of responsibility, producing actionable technical intelligence for proactive detection and discovery. {D Part 2: Scope of Role What you'll bring pre-set content based on tier framework + role-specific bullets

    What you'll bring to the role: 

  • Minimum 5 years of experience in cyber threat intelligence, cyber discovery, or cybersecurity investigations, with a track record leading both teams and technical investigations and producing actionable outcomes.

  • Expertise in tracking advanced threat actors and malware using frameworks such as MITRE ATT&CK and/or the Diamond Model to characterize campaigns, capabilities, and infrastructure.
    -Proficiency in Python and scripting to automate investigative workflows and develop analytics (e.g., Jupyter notebooks).

  • Experience with large-scale data analysis and security telemetry tooling to identify patterns, quantify trends, and support analytic judgments.

  • Experience with SIEM platforms and interpreting network/endpoint logs to progress investigations from hypothesis to evidence-based conclusions.

  • Ability to communicate clearly across technical and non-technical audiences, including writing technical reporting and briefing investigative judgments and mitigations.

Nice to have : GIAC GCTI, CISSP, CASP certifications

We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients,

communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work. To learn more about our offices across the globe, please copy and paste

https://www.morganstanley.com/about-us/global-offices into your browser.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years.  Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Salary range for the position: 135,000 and 190,000 per year. The successful candidate may be eligible for an annual discretionary incentive compensation award. The successful candidate may be eligible to participate in the relevant business unit’s incentive compensation plan, which also may include a discretionary bonus component. Morgan Stanley offers a full spectrum of benefits, including Medical, Prescription Drug, Dental, Vision, Health Savings Account, Dependent Day Care Savings Account, Life Insurance, Disability and Other Insurance Plans, Paid Time Off (including Sick Leave consistent with state and local law, Parental Leave and X Vacation Days annually), 10 Paid Holidays, 401(k), and Short/Long Term Disability, in addition to other special perks reserved for our employees. Please visit mybenefits.morganstanley.com to learn more about our benefit offerings.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background.  Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo.

Frequently Asked Questions

Is the salary disclosed for the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP position at ms?
The salary for this Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP role at ms is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP position at ms located?
This Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP role at ms is based in Baltimore, Maryland, United States of America. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP role at ms full-time or part-time?
This is listed as a Full time position. It is posted as a Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP role in the 474 MS Services Group, Inc. department at ms.
Which team or department does the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP at ms belong to?
This Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP position is part of the 474 MS Services Group, Inc. department at ms. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP position at ms?
Click the "Apply Now" button on this page. You will be redirected to ms's official application portal hosted on workday where you can submit your application directly.
When was the Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP job at ms posted?
This Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP position at ms was posted on Jul 20, 2026. Apply as soon as possible — early applications are often reviewed first.
Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP
ms
Apply for this role ↗

You'll be redirected to ms's official application page on Workday.