JPMorganChase Logo

JPMorganChase

Senior Lead Security Engineer

Reposted 16 Days Ago
Be an Early Applicant
Hybrid
2 Locations
Senior level
Hybrid
2 Locations
Senior level
Leads enterprise cybersecurity engineering and secure-design reviews across applications, cloud platforms, APIs, integrations, and third-party solutions. Conducts threat modeling, risk assessments, vulnerability remediation, and architecture evaluations; advises senior stakeholders on mitigations, compensating controls, and secure implementation. Promotes automation and AI-assisted security validation throughout the software development lifecycle, while ensuring data sensitivity, auditability, and resiliency. Partners with product, engineering, business, vendor, and technology teams and leads cybersecurity communities of practice.
The summary above was generated by AI

 


Join one of the world’s most influential companies and leverage your cybersecurity expertise to make a direct and meaningful impact across the financial industry.

As a Senior Lead Security Engineer at JPMorganChase within Cybersecurity and Technology Controls, you will partner with product, technology, and business stakeholders to evaluate the security of new features, platforms, applications, and third-party solutions. You will apply secure design principles, threat modeling, and risk-based decision-making to reduce misuse, circumvention, and malicious behavior across modern technology environments. You will serve as a senior technical advisor, translating complex findings into clear mitigation options, architecture recommendations, and risk narratives for senior stakeholders.

Job responsibilities

  • Provide technical guidance and direction to product, engineering, business, contractor, and vendor teams to support secure design and delivery of new capabilities
  • Conduct and maintain threat models, threat assessments, and secure design reviews for enterprise applications, cloud platforms, application programming interfaces, integrations, and third-party vendor solutions
  • Identify, document, and communicate cybersecurity risks, mitigation options, compensating controls, and recommended solutions across multiple technical areas and business functions
  • Partner with stakeholders and senior business leaders to recommend design, implementation, or operational changes during periods of vulnerability, incident response, remediation, or emerging risk
  • Evaluate current and emerging technologies, including external vendor offerings and internal platforms, through outcomes-oriented review of security designs, technical capabilities, and fit within existing systems and cybersecurity architecture
  • Identify opportunities to eliminate, reduce, or automate recurring security issues and improve the overall security posture of applications, systems, and technology processes
  • Leverage enterprise-authorized artificial intelligence capabilities to accelerate security architecture and engineering workflows (for example, risk identification, threat assessment synthesis, documentation, and decision support), while validating outputs and handling data according to sensitivity and security requirements
  • Drive reuse-first adoption of artificial intelligence–assisted security validation within the software development life cycle and delivery toolchain to improve control testing, remediation quality, traceability, auditability, and resiliency
  • Lead or contribute to communities of practice that promote awareness, consistency, and adoption of cybersecurity technologies, secure design patterns, and risk management practices

Required qualifications, capabilities and skills

  • Formal training or certification in cybersecurity, security architecture, security engineering, or a related technical discipline, with 5+ years of applied experience
  • Hands-on experience delivering, advising on, or implementing enterprise cybersecurity solutions, security controls, secure design patterns, or risk mitigation strategies
  • Expertise in threat modeling, threat assessments, secure design reviews, vulnerability analysis, risk evaluation, and security requirements definition
  • Proficiency in modern technology environments across one or more disciplines such as public cloud, application programming interfaces, identity and access management, artificial intelligence and machine learning, mobile, infrastructure, or application security
  • Ability to evaluate current and emerging technologies and recommend practical security solutions aligned to target architecture, business priorities, resiliency expectations, and risk appetite
  • Deep expertise in one or more programming languages, platforms, cloud services, security tools, or application technologies, with the ability to review technical designs and engage credibly with engineering teams
  • Experience partnering with product and technology teams to remediate vulnerabilities, incidents, control gaps, recurring issues, or design weaknesses
  • Experience using enterprise-authorized artificial intelligence capabilities to support cybersecurity workflows, with strong validation practices and awareness of data sensitivity
  • Strong written and verbal communication skills, including the ability to explain complex technical risks, trade-offs, and recommendations to senior business leaders and technical stakeholders

Preferred qualifications, capabilities and skills

  • Experience with cloud-native security architecture, application programming interface security, identity federation, OAuth, SAML, secrets management, service-to-service authentication, or Zero Trust patterns
  • Familiarity with vulnerability management, penetration testing outputs, security testing methodologies, incident remediation, or secure-by-design practices
  • Experience evaluating third-party vendor solutions, software as a service platforms, integrations, or emerging technologies from a cybersecurity architecture and risk perspective
  • Knowledge of security capabilities such as Security Service Edge, Cloud Access Security Broker, Security Information and Event Management, application programming interface gateways, proxy technologies, traffic inspection, or security monitoring platforms
  • Experience leading cross-functional security reviews, design forums, architecture governance discussions, or communities of practice
  • Ability to balance technical depth with pragmatic, risk-based decision-making in complex enterprise environments

#CTC

About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
HQ

JPMorganChase New York, New York, USA Office

270 Park Avenue, New York, NY, United States, 10017-2014

JPMorganChase New York, New York, USA Office

4 Metrotech Center, New York, NY, United States, 11201

Similar Jobs

14 Days Ago
Hybrid
Jersey City, NJ, USA
Senior level
Senior level
Financial Services
Design and develop secure, resilient full-stack systems and microservices using Java or Python and AWS. Build digital asset custody components, blockchain integrations, APIs, and cloud applications across the software development lifecycle. Create architecture artifacts, troubleshoot production issues, analyze data, and improve reliability. Lead responsible adoption of AI-assisted engineering tools for coding, testing, reviews, refactoring, and incident analysis while coaching teams on secure, compliant practices.
Top Skills: Amazon Api GatewayAmazon RdsAmazon S3Amazon SnsAmazon SqsAWSBlockchainCi/CdEthereumEvmJavaMicroservicesPythonTerraform
Yesterday
Hybrid
Senior level
Senior level
Financial Services
Lead design, implementation, and lifecycle management of HSM and cryptographic infrastructure (Thales/FutureX). Create architecture, runbooks, and diagrams; drive migrations, DR, and compliance (PCI, FIPS). Troubleshoot Linux/Unix systems, OpenSSL and certificate auth, cloud KMS/HSM, and automate via Terraform. Collaborate cross-functionally on standards, participate in risk assessments, audits, and incident response, and validate AI-assisted security outputs.
Top Skills: Certificate-Based AuthenticationCloud HsmCloud Key Management Service (Kms)Confidential ComputingEnterprise-Authorized AiFuturexHardware Security Module (Hsm)LinuxOpensslSplunkTerraformThalesUnix
26 Days Ago
Hybrid
Senior level
Senior level
Financial Services
Senior hands-on security engineer responsible for designing, building, and implementing enterprise security solutions across cloud, hybrid, and on-prem environments. Integrates security into SDLC, automates controls, performs threat modeling and risk assessments, leverages AI-assisted tools, mentors junior engineers, and leads incident response and post-incident improvements.
Top Skills: Ai/MlAnsibleAWSAws Security HubAzureAzure SentinelBitbucketCC#Ci/CdContainer SecurityDreadGCPGcp Security Command CenterGitGithub ActionsGoJavaJenkinsJIRAKubernetesPastaPythonStrideTerraformZero Trust

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account