Application Security Engineer (Senior) ID71668 at Morgan Stanley
Tampa, FL
—
Jul 5, 2026
Tampa, FL
Jul 21, 2026
What this job asks for AI summary
A senior application security engineering role focused on building and automating security tooling within a large financial services program. Core work involves deploying and tuning SAST, DAST, and SCA tools into CI/CD pipelines, developing AI-enabled secure code scanning, and providing code-level remediation guidance to development teams in Java and Python. Suits an experienced engineer who can operate independently within a DevSecOps context.
Senior level · 6+ years · Remote
“or” means any one of them counts — you don't need all of them.
Posted 48 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 3,650 people nationally plausibly meet what this posting asks for (information security analysts). range 2,200–5,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The role is a genuine hybrid of Application Security (15-1212) and Software Engineering (15-1252) — it requires hands-on coding in Python/Java and building automated security tooling, not just operating security tools. 15-1212 was chosen as primary because the core mandate is AppSec/DevSecOps (SAST/DAST/SCA deployment, secure code review, security runbooks), but the runner-up 15-1252 is a close second given the heavy automation and engineering emphasis.
Python and Java are listed together under Must Haves with an 'and/or' qualifier — the JD requires proficiency in at least one; they are captured as a single skill with the other as an alternative.
No work location or metro is specified beyond 'remote and office options'; the role appears to be remote-eligible but no US city or CBSA is identifiable from the posting.
LLMs, AI agents, and threat modeling appear under the 'Nice to Haves' section.
No compensation figures are provided beyond a mention of 'USD-based pay'; no numeric range is given.
This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.