About the role
What will you do at JPMorganChase?
As a Lead Software Security Engineer at JPMorganChase, you are an integral part
of an agile team that works to enhance, build, and deliver trusted technology
products in a secure, stable, and scalable way. Drive significant business
impact through your capabilities and contributions, and apply deep technical
expertise and problem-solving methodologies to tackle a diverse array of
challenges that span multiple technologies and applications.
Job responsibilities
* Facilitate security requirements clarification for multiple networks to
enable multi-level security, satisfying organizational needs for both ingress
and egress traffic. Work at code-level using java/ Python and drive the
maturity of the Cybersecurity software development lifecycle with an advanced
understanding of line of business technology drivers.
* Perform deployment, administration, management, configuration, testing,
documentation, operations, and integration tasks related to Cloud Network
Security Platforms, championing a DevOps security model to ensure security is
automated and elastic across all platforms.
* Lead and develop new Cloud Security Implementations for both ingress and
egress traffic. Design and develop strategies to provide end-to-end
automation, architecture design, performance and monitoring, best practices,
proof of concepts, product design, and transition to operations.
* Ensure quality control of engineering deliverables and ensure firm policies
are compliant with strict security standards. Drive decision-making by
analyzing complex data systems, ensuring all engineering activities are in
conformance with firm policies & objectives. Leverage DevOps tools to build,
harden, maintain, and develop a comprehensive Cloud-based security
orchestration platform for network security and infrastructure as code.
Develop automated security and compliance capabilities in support of DevOps
processes in a large-scale Cloud computing environment.
* Collaborate with technologists, stakeholders, and senior business leaders to
recommend business modifications during periods of vulnerability. Be
responsible for triaging based on risk assessments of various threats and
managing resources to cover the impact of disruptive events.
* Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to
strengthen security testing and control validation, ensuring
traceability/auditability and alignment to resiliency and security
expectations. Collaborate with cross-functional teams, including IT,
development, and operations, to ensure web application security.
* Uses enterprise-authorized AI capabilities within the work environment to
accelerate threat modeling, vulnerability analysis synthesis, and security
documentation, validating outputs and ensuring sensitive data is handled
appropriately.
Required qualifications, capabilities, and skills
* Formal training or certification on Security Engineering concepts and 5+
years of applied experience.
* Advanced hands-on coding experience in java or Python/Go and Terraform.
Expertise with AWS Infrastructure such as networking, EC2, Lambdas,
server-less solutions, VPC, Route 53, autoscaling, Transit Gateway, API
Gateway, Step Functions, secrets manager, and storage services.
* Proficient in core concepts for Networking, Infrastructure as Code (IaaC),
Public Cloud architecture, and Cloud Security.
* Expertise in developing and designing complex cloud architectures, deploying
scalable solutions, creating, and handling CI/CD pipelines, application
resiliency, security design and implementation, and triaging issues in Agile
Software Development Lifecycle methodology.
* Extensive experience with threat modeling, discovery, vulnerability, and
penetration testing. Ability to tackle design and functionality problems
independently with little to no oversight.
* Experience with WAF technologies such as AWS WAF, Akamai, Cloudflare, or
similar.
* Demonstrated experience using enterprise-authorized AI capabilities within
the work environment to support security engineering workflows with strong
validation habits and awareness of data sensitivity.
* Ability to review and validate AI-assisted code/security recommendations
before adoption, escalating uncertainty and ensuring outcomes align to
security, resiliency, and auditability expectations.
Preferred qualifications, capabilities, and skills
* API Gateway Development
* Custom proxy development
#CTC
JPMorganChase, one of the oldest financial institutions, offers innovative
financial solutions to millions of consumers, small businesses and many of the
world’s most prominent corporate, institutional and government clients under the
J.P. Morgan and Chase brands. Our history spans over 200 years and today we are
a leader in investment banking, consumer and small business banking, commercial
banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined
based on the role, experience, skill set and location. Those in eligible roles
may receive commission-based pay and/or discretionary incentive compensation,
paid in the form of cash and/or forfeitable equity, awarded in recognition of
individual achievements and contributions. We also offer a range of benefits and
programs to meet employee needs, based on eligibility. These benefits include
comprehensive health care coverage, on-site health and wellness centers, a
retirement savings plan, backup childcare, tuition reimbursement, mental health
support, financial coaching and more. Additional details about total
compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring
to our global workforce are directly linked to our success. We are an equal
opportunity employer and place a high value on diversity and inclusion at our
company. We do not discriminate on the basis of any protected attribute,
including race, religion, color, national origin, gender, sexual orientation,
gender identity, gender expression, age, marital or veteran status, pregnancy or
disability, or any other basis protected under applicable law. We also make
reasonable accommodations for applicants’ and employees’ religious practices and
beliefs, as well as mental health or physical disability needs. Visit our FAQs
[https://careers.jpmorgan.com/us/en/how-we-hire/faqs] for more information about
requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including
Disability/Veterans
Our professionals in our Corporate Functions cover a diverse range of areas from
finance and risk to human resources and marketing. Our corporate teams are an
essential part of our company, ensuring that we’re setting our businesses,
clients, customers and employees up for success.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Lead Security Engineer
JPMorganChase · Columbus, Ohio, United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Lead Security Engineer - Advanced Cryptography
JPMorganChase · Palo Alto, California, United States
Open Source Software LEAD Security Engineer - Software Supply Chain
Truist · Greensboro, Virginia, United States
Security Engineer
Brightspot · Reston, Virginia, United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Role information can change. Confirm current details on the original application page.
