Principal SIEM Engineer, VP, P5
Principal SIEM Engineer
Technology works as a strategic partner with Morgan Stanley business units and the world's leading technology companies to redefine how we do business in ever more global, complex, and dynamic financial markets. Morgan Stanley's sizeable investment in technology results in quantitative trading systems, cutting-edge modelling and simulation software, comprehensive risk and security systems, and robust client-relationship capabilities, plus the worldwide infrastructure that forms the backbone of these systems and tools. Our insights, our applications and infrastructure give a competitive edge to clients' businesses and to our own.
Position Overview
Cyber Response Platforms is looking for an experienced (10+ years) cyber-security professional to join their team as a SIEM lead. Our ideal candidate has hands-on experience in computer network defence working either in a Security Operations Center or Cyber Incident Response Team.
You will lead a team of technologists and cyber-security professionals that are dedicated to improving the coverage, quality and automation of cyber-security detection and response.
What you'll do in the role
- Supervise and govern the development of analytics in Splunk (SPL) or Elastic Search (EQL) to detect actionable security alerts
- Develop and fine-tune advanced detection rules, alerting mechanisms, and use cases to identify and respond to sophisticated security threats
- Create comprehensive security metrics, reports, dashboards, providing detailed insights into the organization's security posture
- Ensure that the SIEM solution complies with global regulatory standards and industry best practices
- Mentor and guide SIEM engineers, fostering a culture of continuous learning and development within the team
- Participate in the development of the organization's security strategy and contribute to its execution
- Monitor and support SIEM platforms to ensure security and stability of SOC infrastructure
Additional Leadership Responsibilities
- Provide day-to-day leadership and oversight for the SIEM engineering team, ensuring alignment with strategic goals and operational priorities
- Facilitate regular team standups, retrospectives, and planning sessions to promote transparency and accountability
- Coach team members on technical and professional growth, offering constructive feedback and career development support
- Champion a collaborative and inclusive team culture that encourages innovation, ownership, and continuous improvement
- Identify and address skill gaps through targeted training, mentoring, and knowledge-sharing initiatives
- Act as a point of escalation for technical challenges and team dynamics, resolving issues with empathy and decisiveness
- Collaborate with cross-functional teams to ensure seamless integration of SIEM capabilities into broader cyber response workflows Skills required (essential)
What you'll bring to the role
- Minimum of 10 years of experience in cyber detection engineering or incident response
- Strong understanding of network security, endpoint detection and computer forensics
- Experience in the creation and management of detection logic in SIEMs (e.g Elastic Search, Splunk, ArcSight, Microsoft Sentinel)
- Experience with SIEM rule tuning, correlation logic, alert de-duplication and false-positive reduction techniques
- Strong knowledge of exploitation techniques (e.g. MITRE ATT&CK) and use-case development
- Thorough TCP/IP and protocol experience (OSI L2-L7, DNS, HTTP, REST, SOAP)
- Highly experienced with Unix/Linux command-line tools and shell scripting
- Experience developing automations in SOAR (e.g. Palo Alto XSOAR, SumoLogic, Swimlane)
- Experience within the application of Indicators of Compromise (e.g. YARA rules, STIX and TAXII)
- Strong hands-on experience with a query language (e.g Splunk's SPL or Elastic's EQL, SQL)
- Experience with streaming data frameworks (e.g. Kafka, NiFi, Spark)
- Experience with CI/CD technology (e.g Jenkins, GitLab CI, GitHub Actions)
- Experience in the administration of systems (e.g. servers, desktops) or security controls (AV, Endpoint, IDS)
- Intermediate experience developing scripts in Python
- Strong communication, task management and organizational skills
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work.
Want more jobs like this?
Get jobs in Baltimore, MD delivered to your inbox every week.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.
Salary range for the position $135,000 to $190,000 per year. The successful candidate may be eligible for an annual discretionary incentive compensation award. The successful candidate may be eligible to participate in the relevant business unit's incentive compensation plan, which also may include a discretionary bonus component. Morgan Stanley offers a full spectrum of benefits, including Medical, Prescription Drug, Dental, Vision, Health Savings Account, Dependent Day Care Savings Account, Life Insurance, Disability and Other Insurance Plans, Paid Time Off (including Sick Leave consistent with state and local law, Parental Leave and X Vacation Days annually), 10 Paid Holidays, 401(k), and Short/Long Term Disability, in addition to other special perks reserved for our employees. Please visit mybenefits.morganstanley.com to learn more about our benefit offerings.
Morgan Stanley's goal is to build and maintain a workforce that is diverse in experience and background but uniform in reflecting our standards of integrity and excellence. Consequently, our recruiting efforts reflect our desire to attract and retain the best and brightest from all talent pools. We want to be the first choice for prospective employees.
It is the policy of the Firm to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, religion, creed, age, sex, sex stereotype, gender, gender identity or expression, transgender, sexual orientation, national origin, citizenship, disability, marital and civil partnership/union status, pregnancy, veteran or military service status, genetic information, or any other characteristic protected by law.
Morgan Stanley is an equal opportunity employer committed to diversifying its workforce (M/F/Disability/Vet).
Perks and Benefits
Health and Wellness
- Health Insurance
- Dental Insurance
- Vision Insurance
- Life Insurance
- Short-Term Disability
- Long-Term Disability
- Fitness Subsidies
- On-Site Gym
- Pet Insurance
- Mental Health Benefits
- FSA
- Virtual Fitness Classes
- HSA
Parental Benefits
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
- Return-to-Work Program
- Birth Parent or Maternity Leave
- Non-Birth Parent or Paternity Leave
- Adoption Leave
Work Flexibility
- Hybrid Work Opportunities
Office Life and Perks
- Commuter Benefits Program
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Paid Holidays
- Leave of Absence
- Volunteer Time Off
- Personal/Sick Days
Financial and Retirement
- 401(K) With Company Matching
- Stock Purchase Program
- Performance Bonus
- Relocation Assistance
- Financial Counseling
Professional Development
- Tuition Reimbursement
- Promote From Within
- Mentor Program
- Access to Online Courses
- Lunch and Learns
- Work Visa Sponsorship
- Leadership Training Program
- Associate or Rotational Training Program
- Internship Program
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program
- Employee Resource Groups (ERG)