Web Security Specialist

6 hours ago


Bengaluru, Karnataka, India Morgan Stanley Full time US$ 90,000 - US$ 1,20,000 per year

Profile Description
We are seeking to add an experienced Web Security subject matter expert to join our Web Security Operations team in India. The team is responsible for the day-to-day operations, security, and health of Morgan Stanley's Proxy infrastructure on which thousands of web applications run. The specialist will act as a subject matter expert for web security, handle operational escalations from our L2 teams, respond to incident management notifications, as well as in delivering robust, effective solutions covering our internet perimeter and external content delivery network providers.

CDRR_Technology
The Cybersecurity organization's mission is to create an agile, adaptable organization with the skills and expertise needed to defend against increasingly sophisticated adversaries. This will be achieved by maintaining sound capabilities to identify and protect our assets, proactively assessing threats and vulnerabilities and detecting events, ensuring resiliency through our ability to respond to and recover from incidents and building awareness and increase vigilance while continually developing our cyber workforce.

Cyber
The Cybersecurity organization's mission is to create an agile, adaptable organization with the skills and expertise needed to defend against increasingly sophisticated adversaries. This will be achieved by maintaining sound capabilities to identify and protect our assets, proactively assessing threats and vulnerabilities and detecting events, ensuring resiliency through our ability to respond to and recover from incidents and building awareness and increase vigilance while continually developing our cyber workforce.

Morgan Stanley is an industry leader in financial services, known for mobilizing capital to help governments, corporations, institutions, and individuals around the world achieve their financial goals.

At Morgan Stanley India, we support the Firm's global businesses, with critical presence across Institutional Securities, Wealth Management, and Investment management, as well as in the Firm's infrastructure functions of Technology, Operations, Finance, Risk Management, Legal and Corporate & Enterprise Services. Morgan Stanley has been rooted in India since 1993, with campuses in both Mumbai and Bengaluru. We empower our multi-faceted and talented teams to advance their careers and make a global impact on the business. For those who show passion and grit in their work, there's ample opportunity to move across the businesses for those who show passion and grit in their work.

Interested in joining a team that's eager to create, innovate and make an impact on the world? Read on…

Responsibilities
What you'll do in the role:


Provide Level 3 Operations support for a global perimeter Web proxy and Web security enterprise infrastructure

Maintain Web security infrastructure, providing stability by developing tools, policies, processes and procedures for the operations teams

Lead projects, analyze and prioritize workload based on business risk and requirements.

Take ownership of incidents, problems, follow-up actions and manage to resolution

Plan, review production changes following firm Change Management process and procedure.

Provide Web Security consultancy services to other internal Technology teams.

Provides architecture assurance on Web Security initiatives.

Establish effective working relationships with Engineering counterparts and other stakeholders operating in the Web Security space

Provide a secure environment, by implementing controls to manage and mitigate risks.

Develop automated metrics reporting capabilities

Create, review, maintain and update documentation including Documenting & Publishing fixes in our central knowledge base

Work with global colleagues to provide globally consistent processes and solutions

Investigate & Troubleshoot root causes when escalated from operations

Escalate and liaise with additional internal/external groups when required

Input into Business Continuity Planning and Practices

Integration and testing, and deployment of Web Proxy technologies with leading network DLP or Malware scanning solutions

Collaborating with leads responsible for web and application servers, load-balancers and web authentication infrastructure

Working with colleague subject matter experts in the wider organization who administer networks, logging, application architecture and other complementary technologies

Drive determination and implementation of security best practice in our web platforms and infrastructure

Research into vendor and open source solutions in the web security space, and determination of their place in our overall solution

Interfacing with technical contacts at external vendor providers and other internal teams to ensure a holistic solution is delivered and enhanced

Followup the sun support model and able to pick up oncall roster and support over weekend

Training operations L2 personnel, application support groups in tools, technologies and procedure Skills Set

  • Moderate-Advance direct experience with ZScaler Cloud Proxy technologies (SASE, SSE)

Netskope, Fortinet, ZScaler, ZPA, SSLi, Cloud DLP, Cloud Sandboxing

  • Moderate-Advanced proxy experience required including engineering of flows via proxy and client access for troubleshooting; Bluecoat ProxySG Appliance experience preferred.
  • Must know how to integrate external services with proxies via ICAP, proxy chaining, and service offloads.
  • Moderate cloud security experience across at least a couple of the more cloud providers (Azure, O365, AWS, etc.)
  • Excellent understanding and experience designing and implementing Web security solutions.
  • Good understanding on Web Proxy infrastructure serving various application layer protocols such as HTTP/HTTPs/SOCKS/FTP/ICAP
  • Scripting and Development Skills (Perl, Python or Shell).
  • Moderate Linux Sys admin experience.
  • Interpersonal Skills - Communication, flexibility, self-driven, team player
  • Strong general networking background (Firewalls, Routing, Load Balancing, OSI Model, Packet trace and analysis, etc.)
  • Good understanding of the protocols underpinning the web - TCP/IP, HTTP, SSL/TLS etc. - - Ideal candidate would be able to intelligently dissect all 7 layers of the OSI stack
  • Experience working in DMZ environments with good understanding of hardware load-balancing, firewalls, multi-tiered architectures.
  • Experience and familiar with SASE solutions, know how to troubleshoot on cloud platforms

Required Skills
What you'll bring to the role:

  • Hands-on proxy knowledge; Netskope, Fortinet and Zscaler experience preferred
  • Understand Network topology and protocol well and know how to trouble shoot using packet capture, e.g. wireshark
  • Hands-on CASB design, architecture and deployment (SkyHigh, Symantec, etc.)
  • Programming/Scripting languages: Python, Perl, AngularJS
  • Knowledge of Data Protection Practices (data at rest, in use, in motion, etc.) and their practical implementations
  • Practical knowledge of web malware, its propagation and mitigation strategies
  • CISSP or similar recognized cyber security qualifications
  • Experience operating in large, siloed enterprise environments
  • Project Management Skills with experience on enterprise projects
  • Web and database development skills (HTML, JavaScript, SQL, ETL)
  • Web Proxy Netskope/ZScaler or other major web proxy competitor
  • Experience within the financial services industry is preferred
  • Experience in customer support and experience in interacting with business

What You Can Expect From Morgan Stanley
We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren't just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you'll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There's also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste into your browser.

Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.



  • Bengaluru, Karnataka, India beBeePenetration Full time ₹ 6,00,000 - ₹ 8,00,000

    Web Security Specialist">This role involves conducting penetration tests on web applications and APIs to identify vulnerabilities and business risk.">Key Responsibilities:">Plan, execute, and lead penetration tests on web applications & APIs.Simulate real-world attack scenarios to assess vulnerabilities and business risk.Document findings with clear and...


  • Bengaluru, Karnataka, India beBeeWebApplicationFirewall Full time € 95,000 - € 1,10,000

    Job DescriptionWe are seeking a skilled Web Application Firewall specialist to contribute to our digital security posture. The ideal candidate will have expertise in deploying and configuring WAF solutions, analyzing detection patterns, and automating rule management.This role requires collaboration with cross-functional teams and application owners to...


  • Bengaluru, Karnataka, India beBeeSecurity Full time ₹ 15,00,000 - ₹ 22,50,000

    About the RoleWe are seeking a seasoned Web Application Security Specialist to expand our Web Application Firewall (WAF), Bot Management, CVA protection and API Security Controls team. The ideal candidate will be a fungible, enthusiastic analyst/technologist with strong analytical and problem-solving skills, detail-oriented, and well-organized.Key...


  • Bengaluru, Karnataka, India beBeeSecurity Full time ₹ 8,00,000 - ₹ 12,00,000

    Job Overview">Protect Web Applications with Advanced Security Expertise.">As a seasoned security expert, you will play a critical role in safeguarding our high-critical web applications from potential threats. Your responsibilities will include conducting thorough security assessments, identifying vulnerabilities, and implementing effective remediations to...

  • Security Specialist

    2 weeks ago


    Bengaluru, Karnataka, India beBeeApplication Full time

    Senior Application Security SpecialistWe are seeking a highly skilled Senior Application Security Specialist to join our team.As a Senior Application Security Specialist, you will be responsible for performing comprehensive security assessments, recommending remediation strategies, and collaborating with development and operations teams to implement secure...


  • Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 1,80,00,000 - ₹ 2,40,00,000

    Job Title: Cyber Security SpecialistAbout This RoleWe are seeking a highly skilled Cyber Security Specialist to join our team. As a key member of our security team, you will be responsible for designing and implementing effective application security programs.Main ResponsibilitiesImplement and automate security controls, including SAST, DAST, SCA, and...


  • Bengaluru, Karnataka, India beBeeCyberSecurity Full time ₹ 45,000 - ₹ 55,000

    Job DescriptionWe are seeking a highly skilled Cyber Security Specialist to join our team. As a Cyber Security Specialist, you will be responsible for conducting in-depth penetration testing of web, API, and mobile platforms, performing secure code reviews using manual and automated techniques, developing security automation tools and integrating with CI/CD...


  • Bengaluru, Karnataka, India beBeeDeveloper Full time ₹ 20,00,000 - ₹ 25,00,000

    Job Title: Web Application SpecialistAbout the Role:We are seeking a highly skilled Web Application Specialist to develop and maintain custom web applications that integrate with e-commerce platforms.Create high-quality, scalable, and secure web applications that meet business requirements.Collaborate with product and design teams to understand project goals...


  • Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 1,00,00,000 - ₹ 1,50,00,000

    Key Cybersecurity Role:We are seeking a detail-oriented, enthusiastic security specialist with excellent analytical and communication skills to enhance our Web Application Firewall (WAF) and Bot Management team.The ideal candidate will play a critical role in ensuring that perimeter security for web properties keeps pace with the changing threat landscape....


  • Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 1,50,00,000 - ₹ 2,00,00,000

    Job TitleWe are seeking a highly skilled Cyber Security Specialist to join our ranks.Responsibilities include:Performing network, web, and application penetration testing using industry-leading tools and methodologies.Conducting vulnerability assessments and exploit testing with tools such as Nessus, Nmap, Metasploit, Burp Suite Pro.Preparing detailed...