Prepin
Log in
JPMorganChase

engineering opportunity

Lead Security Engineer - Cloud Threat Hunting

The Lead Security Engineer will design and implement secure cloud architectures while proactively conducting threat hunts to identify and mitigate emerging risks. They will collaborate with engineering and risk teams to embed security controls and operationalize detection capabilities across the firm's cloud environments.

Columbus, Ohio, United StatesonsiteFULL_TIME

Posted

About the role

What will you do at JPMorganChase?

JPMorganChase is one of the world's leading financial services firms, with

assets exceeding $2 trillion and operations spanning more than 60 countries. We

are a global leader in investment banking, consumer and commercial banking,

financial transaction processing, and asset management. At JPMorganChase,

technology and security aren't just support functions — they are core to how we

serve clients, protect the firm, and drive innovation at scale.

As a Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity &

Technology Controls group, you will be at the forefront of securing the firm's

public cloud adoption — ensuring that cloud platforms, services, and

applications are designed, deployed, and operated in a secure and compliant

manner. You will partner across engineering, product, and risk teams to embed

security into the fabric of cloud architecture, translating complex threat

landscapes into actionable, scalable controls. This is a high-impact role where

your expertise will directly shape the firm's cloud security posture and

resilience.

The Cybersecurity & Technology Controls group proactively and strategically

partners with all lines of business to enable them to design, adopt, and

integrate appropriate controls — delivering processes and solutions that are

efficient, consistent, and automated. Our number one priority is to keep the

firm protected, stable, and resilient while enabling the business to move

forward with confidence.

--------------------------------------------------------------------------------

Job responsibilities

* Partner with stakeholders across product, engineering, and risk and controls

teams to understand firm control requirements, recommend implementations

across a broad range of cloud architectures, and ensure secure-by-design

principles are embedded throughout

* Develop, plan, and execute hypothesis-driven, cloud-focused threat hunts,

translating findings into actionable security outcomes including detection

rules, alert tuning, and compensating controls

* Apply specialized tooling to query, analyze, correlate, and interpret large

datasets to identify potential threats and emerging risk patterns

* Deliver threat models and risk-based assessments of cloud services, cloud

platforms, and cloud-based applications to inform architecture and

engineering decisions

* Perform security reviews of infrastructure-as-code for cloud platform

development, ensuring alignment with firm standards and industry best

practices

* Develop preventive and detective controls to enforce control requirements

across cloud environments at enterprise scale

* Interface with broader cybersecurity teams to ensure platform integration

with security operations, threat intelligence, and incident response —

operationalizing detections, improving triage playbooks, and supporting cloud

threat investigations

* Provide expert guidance on the cloud threat landscape, adversary tradecraft,

and emerging risks to inform strategic security decisions

* Contribute to documentation and agile processes in support of security

programs, driving consistency and repeatability across the team

--------------------------------------------------------------------------------

Required qualifications, capabilities, and skills

* Formal training or certification on cybersecurity concepts and 5+ years

applied experience (e.g., Security+, CEH, CCSP, CISSP, or equivalent)

* Hands-on cloud-native experience across one or more major cloud platforms

(AWS, Azure, or Google Cloud), including relevant cloud security

certification

* Demonstrated experience with threat modeling methodologies and delivering

risk-based security assessments

* Experience with cloud security posture management tooling (e.g., Wiz, Prisma

Cloud, CrowdStrike Falcon, or equivalent)

* Knowledge of infrastructure-as-code frameworks (e.g., Terraform,

CloudFormation, or equivalent) and their security implications

* Ability to lead cross-functional security initiatives and drive outcomes

without direct authority

* Strong prioritization skills with a risk-based approach to decision-making

across competing demands

* Ability to think beyond conventional approaches to build innovative solutions

and break down complex technical problems

--------------------------------------------------------------------------------

Preferred qualifications, capabilities, and skills

* Experience in offensive security disciplines including penetration testing,

red teaming, or purple teaming

* Proficiency with at least one query language used for threat detection and

hunting (e.g., KQL, Splunk SPL, or SQL), with comfort working across large

and complex datasets

* Experience working within agile delivery frameworks and contributing to

security program documentation at an enterprise level

#CTC

JPMorganChase, one of the oldest financial institutions, offers innovative

financial solutions to millions of consumers, small businesses and many of the

world’s most prominent corporate, institutional and government clients under the

J.P. Morgan and Chase brands. Our history spans over 200 years and today we are

a leader in investment banking, consumer and small business banking, commercial

banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined

based on the role, experience, skill set and location. Those in eligible roles

may receive commission-based pay and/or discretionary incentive compensation,

paid in the form of cash and/or forfeitable equity, awarded in recognition of

individual achievements and contributions. We also offer a range of benefits and

programs to meet employee needs, based on eligibility. These benefits include

comprehensive health care coverage, on-site health and wellness centers, a

retirement savings plan, backup childcare, tuition reimbursement, mental health

support, financial coaching and more. Additional details about total

compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring

to our global workforce are directly linked to our success. We are an equal

opportunity employer and place a high value on diversity and inclusion at our

company. We do not discriminate on the basis of any protected attribute,

including race, religion, color, national origin, gender, sexual orientation,

gender identity, gender expression, age, marital or veteran status, pregnancy or

disability, or any other basis protected under applicable law. We also make

reasonable accommodations for applicants’ and employees’ religious practices and

beliefs, as well as mental health or physical disability needs. Visit our FAQs

[https://careers.jpmorgan.com/us/en/how-we-hire/faqs] for more information about

requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including

Disability/Veterans

Our professionals in our Corporate Functions cover a diverse range of areas from

finance and risk to human resources and marketing. Our corporate teams are an

essential part of our company, ensuring that we’re setting our businesses,

clients, customers and employees up for success.

Which skills does this role require?

Cloud securityThreat huntingCybersecurity architectureThreat modelingInfrastructure-as-codeRisk assessmentAWSAzureGoogle CloudWizPrisma CloudCrowdStrike FalconTerraformCloudFormationSecurity operationsIncident responseCloud SecurityThreat HuntingCybersecurityThreat ModelingCISSPCCSPSecurity+CEHRisk AssessmentDetection RulesSecurity OperationsThreat IntelligenceIncident ResponseCloud-nativeFinancial ServicesComplianceArchitectureAutomationSecurity Posture ManagementGCP

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.