hirly

Morgan Stanley

API Security Engineering Lead (Hybrid)

Montreal, Canada

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Morgan Stanley first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
CA
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

We’re seeking someone to join our team as an API Security Engineering Lead to lead the strategy, governance, discovery, and adoption of API security capabilities across the enterprise, partnering with technology and business stakeholders to strengthen visibility, resilience, and protection of the firm's API ecosystem.

In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Cyber Security Engineering position at Vice-President level, which is part of the job family responsible for providing specialist cyber expertise and creating solutions that protect the organization's systems and networks against actual and potential security threats and vulnerabilities.

Since 1935, Morgan Stanley is known as a global leader in financial services, always evolving and innovating to better serve our clients and our communities in more than 40 countries around the world.

What you'll do in the role:

Lead the engineering, deployment, and operational management of API Security and API Discovery solutions.

Drive onboarding and adoption of API Security capabilities across enterprise applications.

Define and execute API inventory, discovery, classification, and governance strategies.

Partner with application and infrastructure teams to improve API visibility, threat detection, and risk management.

Own and manage the API Security product roadmap and associated project portfolio, including business requirements, success metrics, and implementation plans.

Coordinate integration of API Security capabilities with Asset Inventory/CMDB, SDLC and DevSecOps pipelines, Web Application Firewall (WAF) platforms, and security monitoring and analytics solutions.

Lead workshops and requirements-gathering sessions with business, technology, and security stakeholders while acting as the primary liaison with external vendors.

Coordinate implementation efforts, issue resolution, risk management, and governance reviews and manage escalations and ensure timely delivery of commitments.

Develop and maintain standards, procedures, operating models, security reviews and audits, security architecture requirements, security metrics, KPIs, and governance processes to support compliance and data protection standards.

Provide leadership, mentorship, and guidance to analysts and project contributors, fostering collaboration and continuous improvement across technology, security, and business teams.

What you'll bring to the role:

Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline.

8+ years of experience in Cybersecurity, Application Security, Security Architecture, Product Management, or Security Program Delivery.

Strong understanding of API security, Web Application Firewalls (WAF), Cloud Security, Security Governance and Risk Management

Experience leading large-scale cross-functional initiatives and delivering complex technology programs.

Excellent stakeholder management and communication skills.

Experience working with third-party security vendors and enterprise security platforms.

Experience with API Security platforms such as Akamai/Noname or similar technologies is an asset.

Knowledge of DevSecOps and software development lifecycle integration is a nice to have.

All our positions are located in Montreal, Quebec. We offer a hybrid work environment, combining remote work and attendance in the office.

Knowledge of French and English is required.

WHAT YOU CAN EXPECT FROM MORGAN STANLEY:

At Morgan Stanley, we raise, manage and allocate capital for our clients – helping them reach their goals. We do it in a way that’s differentiated – and we’ve done that for 90 years. Our values - putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back - aren’t just beliefs, they guide the decisions we make every day to do what's best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. At Morgan Stanley, you’ll find an opportunity to work alongside the best and the brightest, in an environment where you are supported and empowered. Our teams are relentless collaborators and creative thinkers, fueled by their diverse backgrounds and experiences. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits and perks in the industry. There’s also ample opportunity to move about the business for those who show passion and grit in their work.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices​ into your browser.

Morgan Stanley is an equal opportunity employer committed to building and maintaining a workforce that is diverse in experience and background. Our recruiting efforts reflect our strong commitment to a culture of inclusion, where individuals are hired, developed, and advanced based on their skills and talents.

Our workforce reflects a broad cross-section of the global communities in which we operate, bringing a variety of backgrounds, talents, perspectives, and experiences.

For more information, please visit: https://www.morganstanley.com/people-opportunities/eeo .

Chef(fe) de l’ingénierie de la sécurité des API (hybride)Nous sommes à la recherche d’une personne pour se joindre à notre équipe à titre de chef(fe) de l’ingénierie de la sécurité des API afin de diriger la stratégie, la gouvernance, la découverte et l’adoption des capacités de sécurité des API à l’échelle de l’entreprise, en collaboration avec les parties prenantes des secteurs technologiques et d’affaires afin de renforcer la visibilité, la résilience et la protection de l’écosystème d’API de la société.

Au sein de la division Technologie, nous misons sur l’innovation pour développer les connexions et les capacités qui propulsent notre société et permettent à nos clients et à nos collègues de redéfinir les marchés et de façonner l’avenir de nos collectivités. Il s’agit d’un poste de responsable principal de l’ingénierie en cybersécurité au niveau de vice-président, faisant partie de la famille d’emplois responsable de fournir une expertise spécialisée en cybersécurité et de créer des solutions qui protègent les systèmes et les réseaux de l’organisation contre les menaces et vulnérabilités de sécurité actuelles et potentielles.

Depuis 1935, Morgan Stanley est reconnu comme un chef de file mondial des services financiers, évoluant et innovant constamment afin de mieux servir ses clients et les collectivités dans plus de 40 pays à travers le monde.

  • Ce que vous ferez dans ce rôle :
  • Diriger l’ingénierie, le déploiement et la gestion opérationnelle des solutions de sécurité et de découverte des API.
  • Favoriser l’intégration et l’adoption des capacités de sécurité des API dans l’ensemble des applications de l’entreprise.
  • Définir et exécuter les stratégies d’inventaire, de découverte, de classification et de gouvernance des API.
  • Collaborer avec les équipes responsables des applications et de l’infrastructure afin d’améliorer la visibilité des API, la détection des menaces et la gestion des risques.
  • Assumer la responsabilité et la gestion de la feuille de route du produit de sécurité des API ainsi que du portefeuille de projets associé, y compris les exigences d’affaires, les indicateurs de réussite et les plans de mise en œuvre.
  • Coordonner l’intégration des capacités de sécurité des API avec l’inventaire des actifs/la CMDB, les pipelines SDLC et DevSecOps, les plateformes de pare-feu d’applications Web (WAF), ainsi que les solutions de surveillance et d’analyse de la sécurité.
  • Animer des ateliers et des séances de collecte des exigences avec les parties prenantes des se
Original posting on Morgan Stanley's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job