About this role
Join one of the world's most influential financial institutions and help build the technology that protects it. At JPMorganChase, our cybersecurity engineering teams operate at a scale few organizations can match — and we're looking for bold, technically deep engineers who want to make a real impact.
As a Lead Security Engineer at JPMorganChase within the Cyber Technology & Controls organization, you will lead the design, engineering, and lifecycle management of platforms that power cybersecurity operations across the firm. You will help build and operate secure, resilient, and scalable capabilities used for security testing, adversarial simulation, vulnerability research, attack analysis, and validation of cyber defenses — spanning cloud and on-premises environments. Your work will directly shape the technical strategy and engineering standards that protect one of the world's largest financial institutions, and you will collaborate across cybersecurity, infrastructure, cloud, and enterprise technology teams to continuously deliver and improve mission-critical services.
Job responsibilities
- Lead the strategy, architecture, engineering, and lifecycle management of platforms supporting cybersecurity operations across cloud and on-premises environments
- Translate cybersecurity mission requirements into modern, secure, scalable, and reusable technology capabilities that serve the firm at enterprise scale
- Design and operate complex hybrid environments spanning cloud infrastructure, networks, systems, virtualization, storage, identity, and security tooling
- Engineer integrations between security platforms, enterprise services, infrastructure, and operational workflows to improve reliability and operational efficiency
- Develop software, automation, infrastructure-as-code, and continuous integration and delivery capabilities that drive repeatability and reduce operational risk
- Establish and uphold standards for secure configuration, access management, monitoring, logging, patching, backup, recovery, and technology lifecycle management
- Define and continuously improve platform resiliency, availability, capacity, performance, and recovery objectives to meet mission and regulatory expectations
- Lead technical troubleshooting, incident response, root-cause analysis, and remediation for platform and service issues
- Establish measurable operational controls and evidence practices that support auditability and regulatory compliance
- Leverage enterprise-authorized AI and large language model capabilities to accelerate engineering, security analysis, testing, documentation, and automation — while validating outputs and protecting sensitive information
- Build strong partnerships across cybersecurity, infrastructure, cloud, software engineering, and enterprise technology teams to deliver new capabilities and drive continuous improvement
Required qualifications, capabilities, and skills
- Formal training or certification on software engineering concepts and 10+ years applied experience
- Demonstrated experience leading the architecture, engineering, and operation of complex enterprise or mission-critical platforms
- Strong experience across several of the following areas: cloud infrastructure and cloud security, network engineering and administration, systems administration and virtualization, storage and compute operations, software development and enterprise integrations, automation and infrastructure-as-code, cybersecurity platforms and security tooling, identity and access management, or platform resiliency and observability
- Advanced programming or scripting skills in one or more languages such as Python, Go, Java, JavaScript/TypeScript, PowerShell, or Bash
- In-depth experience with AWS, Azure, Google Cloud Platform, or comparable cloud platforms
- Experience building automation and integrations across security, infrastructure, cloud, and enterprise technology services
- Experience with secure software development lifecycle practices, threat modeling, vulnerability management, security testing, and platform resiliency
- Demonstrated experience using enterprise-authorized AI and large language model capabilities in engineering or security workflows, including the ability to evaluate outputs for security, correctness, reliability, and compliance
- Strong communication, stakeholder management, and technical leadership skills with the ability to influence decisions across organizational boundaries and engage effectively with senior technical and business stakeholders
Preferred qualifications, capabilities, and skills
- Advanced degree or relevant professional qualification in computer science, engineering, cybersecurity, or a related field
- Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, AWS Security Specialty, or equivalent
- Experience supporting security operations, security testing, threat emulation, vulnerability research, attack analysis, or cyber-defense validation
- Experience with Kubernetes, containers, immutable infrastructure, or cloud-native platform engineering
- Experience with infrastructure-as-code and pipeline tooling such as Terraform, Ansible, Jenkins, GitHub Actions, or GitLab CI
- Experience with GPU-enabled infrastructure, AI/ML platforms, model-serving systems, or high-performance computing environments
- Familiarity with threat-informed defense principles and frameworks such as MITRE ATT&CK, and experience establishing service-level objectives, operational metrics, and disaster-recovery plans
#CTC