About the role
What will you do at JPMorganChase?
JPMorganChase is one of the world's leading financial services firms, with
assets exceeding $2 trillion and operations spanning more than 60 countries. We
are a global leader in investment banking, consumer and commercial banking,
financial transaction processing, and asset management. At JPMorganChase,
technology and security aren't just support functions — they are core to how we
serve clients, protect the firm, and drive innovation at scale.
As a Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity &
Technology Controls group, you will be at the forefront of securing the firm's
public cloud adoption — ensuring that cloud platforms, services, and
applications are designed, deployed, and operated in a secure and compliant
manner. You will partner across engineering, product, and risk teams to embed
security into the fabric of cloud architecture, translating complex threat
landscapes into actionable, scalable controls. This is a high-impact role where
your expertise will directly shape the firm's cloud security posture and
resilience.
The Cybersecurity & Technology Controls group proactively and strategically
partners with all lines of business to enable them to design, adopt, and
integrate appropriate controls — delivering processes and solutions that are
efficient, consistent, and automated. Our number one priority is to keep the
firm protected, stable, and resilient while enabling the business to move
forward with confidence.
--------------------------------------------------------------------------------
Job responsibilities
* Partner with stakeholders across product, engineering, and risk and controls
teams to understand firm control requirements, recommend implementations
across a broad range of cloud architectures, and ensure secure-by-design
principles are embedded throughout
* Develop, plan, and execute hypothesis-driven, cloud-focused threat hunts,
translating findings into actionable security outcomes including detection
rules, alert tuning, and compensating controls
* Apply specialized tooling to query, analyze, correlate, and interpret large
datasets to identify potential threats and emerging risk patterns
* Deliver threat models and risk-based assessments of cloud services, cloud
platforms, and cloud-based applications to inform architecture and
engineering decisions
* Perform security reviews of infrastructure-as-code for cloud platform
development, ensuring alignment with firm standards and industry best
practices
* Develop preventive and detective controls to enforce control requirements
across cloud environments at enterprise scale
* Interface with broader cybersecurity teams to ensure platform integration
with security operations, threat intelligence, and incident response —
operationalizing detections, improving triage playbooks, and supporting cloud
threat investigations
* Provide expert guidance on the cloud threat landscape, adversary tradecraft,
and emerging risks to inform strategic security decisions
* Contribute to documentation and agile processes in support of security
programs, driving consistency and repeatability across the team
--------------------------------------------------------------------------------
Required qualifications, capabilities, and skills
* Formal training or certification on cybersecurity concepts and 5+ years
applied experience (e.g., Security+, CEH, CCSP, CISSP, or equivalent)
* Hands-on cloud-native experience across one or more major cloud platforms
(AWS, Azure, or Google Cloud), including relevant cloud security
certification
* Demonstrated experience with threat modeling methodologies and delivering
risk-based security assessments
* Experience with cloud security posture management tooling (e.g., Wiz, Prisma
Cloud, CrowdStrike Falcon, or equivalent)
* Knowledge of infrastructure-as-code frameworks (e.g., Terraform,
CloudFormation, or equivalent) and their security implications
* Ability to lead cross-functional security initiatives and drive outcomes
without direct authority
* Strong prioritization skills with a risk-based approach to decision-making
across competing demands
* Ability to think beyond conventional approaches to build innovative solutions
and break down complex technical problems
--------------------------------------------------------------------------------
Preferred qualifications, capabilities, and skills
* Experience in offensive security disciplines including penetration testing,
red teaming, or purple teaming
* Proficiency with at least one query language used for threat detection and
hunting (e.g., KQL, Splunk SPL, or SQL), with comfort working across large
and complex datasets
* Experience working within agile delivery frameworks and contributing to
security program documentation at an enterprise level
#CTC
JPMorganChase, one of the oldest financial institutions, offers innovative
financial solutions to millions of consumers, small businesses and many of the
world’s most prominent corporate, institutional and government clients under the
J.P. Morgan and Chase brands. Our history spans over 200 years and today we are
a leader in investment banking, consumer and small business banking, commercial
banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined
based on the role, experience, skill set and location. Those in eligible roles
may receive commission-based pay and/or discretionary incentive compensation,
paid in the form of cash and/or forfeitable equity, awarded in recognition of
individual achievements and contributions. We also offer a range of benefits and
programs to meet employee needs, based on eligibility. These benefits include
comprehensive health care coverage, on-site health and wellness centers, a
retirement savings plan, backup childcare, tuition reimbursement, mental health
support, financial coaching and more. Additional details about total
compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring
to our global workforce are directly linked to our success. We are an equal
opportunity employer and place a high value on diversity and inclusion at our
company. We do not discriminate on the basis of any protected attribute,
including race, religion, color, national origin, gender, sexual orientation,
gender identity, gender expression, age, marital or veteran status, pregnancy or
disability, or any other basis protected under applicable law. We also make
reasonable accommodations for applicants’ and employees’ religious practices and
beliefs, as well as mental health or physical disability needs. Visit our FAQs
[https://careers.jpmorgan.com/us/en/how-we-hire/faqs] for more information about
requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including
Disability/Veterans
Our professionals in our Corporate Functions cover a diverse range of areas from
finance and risk to human resources and marketing. Our corporate teams are an
essential part of our company, ensuring that we’re setting our businesses,
clients, customers and employees up for success.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Lead Security Engineer
JPMorganChase · Columbus, Ohio, United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
Security Engineer - Directory Services
Truist · Atlanta, Georgia, United States
Product Systems Security Engineer
Lutron Electronics · Coopersburg, Pennsylvania, United States
Lead Security Engineer - Advanced Cryptography
JPMorganChase · Palo Alto, California, United States
Role information can change. Confirm current details on the original application page.
