About this role
Join one of the world's most influential companies and leverage your skills in cybersecurity to have a real impact on the financial industry.
As a Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity Technology & Controls, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications on modern cloud-based technologies. As a core technical contributor, you are responsible for carrying out critical cybersecurity architecture solutions by identifying, creating, and communicating risk, mitigation options, and solutions across multiple technical areas within various business functions in support of project goals.
Job responsibilities
- Leverages enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity architecture analysis and decisioning (e.g., risk identification and documentation), validating outputs and handling data according to sensitivity and security requirements.
- Defines the technical target state of their cybersecurity product and drives achievement of the strategy.
- Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall cybersecurity of software applications and systems
- Leads evaluation sessions with external vendors, startups, and internal teams to drive outcomes-oriented probing of cybersecurity designs, technical credentials, and applicability for use within existing systems and cybersecurity architecture
- Leads communities of practice to drive awareness and use of new and leading-edge cybersecurity technologies
- Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing and remediation quality with traceability/auditability and resiliency expectations.
- Conduct risk analysis on the key drivers behind the metrics (e.g., exposure, likelihood, impact, control gaps, and threat trends), including root-cause analysis and explanations.
- Develop analytics tools and products such as dashboards, metric pipelines, reporting applications, and self-service datasets—using modern engineering practices and agentic coding approaches to translate cybersecurity risk data into decision-ready insights for executives (BISO organizations, CIO/CTO leaders, business stakeholders, and risk committees).
- Design data models and pipelines that integrate multiple sources (security tooling, GRC platforms, asset inventories/CMDB, IAM, ticketing systems, cloud logs, and findings repositories), with strong controls for data quality, lineage, and repeatability.
- Establish and run an analytics operating cadence (weekly, monthly, and quarterly) to support risk reviews, including metric definitions, refresh schedules, exception management, and stakeholder sign-offs.
- Automate insight generation where feasible (anomaly detection, threshold-based alerts, auto-generated narratives, and drill-down workflows) to reduce manual reporting effort.
Required qualifications, capabilities, and skills
- Formal training or certification on cybersecurity architecture and 5+ years applied experience
- Hands-on practical experience in developing risk visualization capabilities and delivering enterprise level cybersecurity solutions and controls
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
- Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
- Working knowledge of cybersecurity risk management concepts: threat, vulnerability, exposure, likelihood/impact, control design vs. operating effectiveness, residual risk, risk appetite/limits.
- Deep expertise in one or more programming language(s), software(s), and/or applications
- Proficient across SDLC execution, including automation/continuous delivery practices and agile methodologies such as continuous integration/delivery, application resiliency, and security
- Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, AI/ML, mobile, etc.), including practical cloud-native experience
- Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture
- Experience effectively communicating with senior business leaders
#CTC