At a Glance
- Tasks: Investigate cyber security incidents and enhance response methods.
- Company: Join Morgan Stanley, a leader in financial services with a commitment to excellence.
- Benefits: Enjoy flexible working options and comprehensive employee perks.
- Why this job: Be part of a dynamic team tackling real-world cyber threats and making an impact.
- Qualifications: 3+ years in Security Analysis; strong analytical skills and knowledge of cyber tactics required.
- Other info: Opportunity for growth within a diverse and inclusive workplace.
The predicted salary is between 36000 - 60000 £ per year.
Morgan Stanley are looking for a Security Analyst at AVP/Director level to join the Security Response team.
Department Profile
The mission of the Cyber Data Risk and Resilience division is to ensure the Firm manages its global businesses and serves clients on a market-leading technology platform that is resilient, safe, efficient, smart, fast, and flexible. The Security Response Team (SRT) is part of the Cyber Data Risk and Resilience division and manages the incident response capability to support day-to-day cross-enterprise event investigations and strategic input into security controls and countermeasures to proactively create better security for the Firm. The group’s vision is to deliver programs that protect and enable the business, ensure secure delivery of services to clients, adjust to address the risks presented by an evolving threat landscape, and meet regulatory expectations.
Team Profile
Morgan Stanley is seeking a Security Analyst (SA) to join the Firm's Cyber Incident Response Team (CIRT). The global CIRT is a 24/7 operation with members in key geographical locations performing incident response and remediation, campaign assessments, network and host-based forensics. SAs work core hours in their region with an on-call rotation for critical incidents.
Primary Responsibilities
- Investigate cyber security incidents and threats.
- Interact with stakeholders and leadership teams as part of the response and remediation efforts.
- Improve the detection, escalation, containment, and resolution of incidents.
- Enhance existing incident response methods, tools, and processes.
- Maintain knowledge of technologies and the threat landscape.
- During non-core business hours support emergency, critical, or large-scale incidents as required.
Qualifications
Candidates should have a genuine interest in cyber security and a good understanding of the tactics, techniques, and procedures of attackers. This role requires a detail oriented critical thinker who can anticipate issues and solve problems. Candidates should be able to analyze large datasets to detect underlying patterns and drive to a root cause analysis.
Required Skills
- 3+ years experiences (or equivalent) with Security Analysis and Incident Response (i.e., working in SOC/CIRT/CSIRT/CERT).
- Subject matter expert in two or more areas such as Windows, Unix, firewalls, intrusion detection, network- and host-based forensics.
- Understand the end-to-end workflow of a threat across multiple technologies.
- Think like an adversary.
- Ability to reduce large datasets to identify threats to the Firm.
- Sound understanding of TCP/IP and networking concepts, security alerts, and incidents.
- Excellent writing and presentation skills are required to communicate findings, recommendations, and status of investigations.
- Experience with investigating common types of attacks, network packet analysis, log analysis, and reviewing security events.
- Ability to build mitigations to defend against network-based threats.
- Knowledge of Windows processes and Active Directory.
- Able to work extended working hours during incidents.
- Experience with developing analytic and response workflow for security event.
Desired skills
- Scripting (Python, BASH, Perl, or PowerShell), coding, or other development experience.
- In-depth knowledge of security event management, network security monitoring, log collection, and correlation.
- Splunk usage or administration experience.
- Reverse engineering malware to understand attack vector and purpose.
- Security Orchestration and Automated Response (SOAR) experience.
- Industry certifications: GCIH, GNFA, GREM, or other related certifications.
- Financial industry experience.
- Foundational Cloud Security knowledge.
- OWASP Top 10 Knowledge.
- Security product assessments.
WHAT YOU CAN EXPECT FROM MORGAN STANLEY:
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what’s best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.
Certified Persons Regulatory Requirements:
If this role is deemed a Certified role and may require the role holder to hold mandatory regulatory qualifications or the minimum qualifications to meet internal company benchmarks.
Flexible work statement
Interested in flexible working opportunities? Morgan Stanley empowers employees to have greater freedom of choice through flexible working arrangements. Speak to our recruitment team to find out more.
Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.
Security Analyst employer: Morgan Stanley

Contact Detail:
Morgan Stanley Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Analyst
✨Tip Number 1
Familiarise yourself with the latest trends and technologies in cyber security. Being knowledgeable about current threats and defence mechanisms will not only help you in interviews but also demonstrate your genuine interest in the field.
✨Tip Number 2
Network with professionals in the industry, especially those who work at Morgan Stanley or similar firms. Attend cyber security conferences, webinars, or local meetups to make connections that could lead to referrals or insider information about the role.
✨Tip Number 3
Prepare for technical interviews by practising common security scenarios and incident response questions. Use platforms like Hack The Box or TryHackMe to sharpen your skills in a practical environment, which can set you apart from other candidates.
✨Tip Number 4
Showcase your problem-solving abilities by discussing past experiences where you successfully handled security incidents. Be ready to explain your thought process and the steps you took to resolve issues, as this will highlight your critical thinking skills.
We think you need these skills to ace Security Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security analysis and incident response. Focus on your skills related to the specific technologies mentioned in the job description, such as Windows, Unix, and network forensics.
Craft a Strong Cover Letter: In your cover letter, express your genuine interest in cyber security and detail how your background aligns with the responsibilities of the Security Analyst role. Mention specific experiences that demonstrate your problem-solving abilities and critical thinking skills.
Highlight Relevant Skills: Clearly list your technical skills, especially those related to security event management, log analysis, and any scripting or coding experience. Make sure to include any industry certifications you hold, as these can set you apart from other candidates.
Proofread Your Application: Before submitting your application, thoroughly proofread your CV and cover letter. Ensure there are no spelling or grammatical errors, and that your documents are formatted professionally. A polished application reflects your attention to detail, which is crucial for a Security Analyst.
How to prepare for a job interview at Morgan Stanley
✨Show Your Passion for Cyber Security
Make sure to express your genuine interest in cyber security during the interview. Discuss recent trends, threats, or incidents that have caught your attention and how they relate to the role. This will demonstrate your commitment and enthusiasm for the field.
✨Prepare for Technical Questions
Expect to be asked about specific technical skills related to security analysis and incident response. Brush up on your knowledge of TCP/IP, network security, and common attack vectors. Be ready to explain your thought process when analysing large datasets or responding to incidents.
✨Demonstrate Problem-Solving Skills
The role requires critical thinking and problem-solving abilities. Prepare examples from your past experiences where you successfully identified and mitigated security threats. Use the STAR method (Situation, Task, Action, Result) to structure your responses.
✨Communicate Clearly and Effectively
Since excellent writing and presentation skills are essential, practice explaining complex security concepts in simple terms. Be prepared to discuss how you would communicate findings and recommendations to both technical and non-technical stakeholders.