Lead Infrastructure Engineer - Proxy/SSE Network Security

JPMorgan Chase & Co.

Greater London

On-site

GBP 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

JPMorganChase & Co. is seeking a Lead Software Engineer - Proxy/SSE Network Security in Greater London to lead secure network solutions across perimeter, proxy, and SSE services.

You will architect ZTNA, IAP, and gateway patterns, drive AI-assisted development practices, and ensure strong security controls across multi-cloud and on-prem environments. The role emphasizes leadership, secure coding, and collaboration with cybersecurity, network services, and operations teams to reduce risk and

Qualifications

  • Proven depth in network security/SASE/SSE/identity security.
  • Strong understanding of Zero Trust, policy-based access, segmentation, and secure egress.
  • Demonstrated experience leading AI-assisted software development tools usage with team validation of AI outputs.
  • Experience delivering regional ownership in the US/North America for infrastructure or security platforms.

Responsibilities

  • Executes network security software solutions with capable design and troubleshooting.
  • Develops secure production code and reviews code written by others.
  • Architects and implements ZTNA patterns for user-to-app and user-to-internet access.
  • Builds and operates IAP/policy enforcement for web and app access.
  • Implements Secure Gateway/SWG capabilities including TLS inspection and malware protection.
  • Drives enterprise AI-assisted engineering practices and reusable patterns across the team.
  • Owns the US perimeter, proxy, and SSE/SASE engineering roadmap and execution.
  • Defines standards, reference architectures, and patterns for perimeter and egress controls.

Skills

Network security
Zero Trust
SASE
SSE
AI-assisted development
IAP patterns
Security engineering
Leadership

Tools

Zscaler
Netskope
Palo Alto
ProxySG

Job description

Lead Software Engineer - Proxy/SSE Network Security

As a Lead Software Engineer at JPMorganChase within the Corporate Sector - Enterprise Technology, youare an integral part of an agile team that works to enhance, build, and deliver trusted market-leading technology products in a secure, stable, and scalable way. As a core technical contributor, you are responsible for conducting critical technology solutions across multiple technical areas within various business functions in support of the firm’s business objectives.

Job responsibilities

  • Executes creative Network security software solutions, design, development, and technical troubleshooting with ability to think beyond routine or conventional approaches to build solutions or break down technical problems
  • Develops secure high-quality production code, and reviews and debugs code written by others
  • Architect and implementZero Trust Network Access (ZTNA)patterns for user-to-app and user-to-internet access, minimizing implicit trust and reducing lateral movement.
  • Build and operate anIdentity-Aware Proxy (IAP)/policy enforcement pointfor web and application access, enforcing identity, device, and context-based policy decisions.
  • Implement or integrateSecure Gateway / Secure Web Gateway (SWG)capabilities (URL filtering, TLS inspection where approved, malware protection, sandboxing, egress controls, DNS security).
  • Experience with other SaaS based Secure Gateway vendor e.g. Zscaler, Netskope, paloalto, Broadcom ProxySG etc
  • Drives team adoption of enterprise-authorized AI-assisted engineering practices within the work environment to improve code quality, delivery speed, and operational outcomes (e.g., AI-assisted code review/refactoring, test strategy acceleration, incident/root-cause analysis support), while establishing consistent validation standards (secure coding, peer review, automated testing) and promoting reuse of effective patterns across the team.
  • Applies knowledge of tools within the Software Development Life Cycle toolchain, including enterprise-authorized AI-assisted development and automation capabilities, to improve the value realized by automation.
  • Good understanding of network infrastructure, network security concepts and application layer protocols (http/https) and vulnerability mitigation
  • Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems
  • Own the US perimeter, proxy, and SSE/SASE engineering roadmap and execution, including intake, prioritization, dependency management, delivery governance, and stakeholder alignment across cybersecurity, network services, operations, and application and platform teams.
  • Define and operationalize standards, reference architectures, and reusable engineering patterns for perimeter and egress controls, including forward proxy and secure web gateway patterns, access brokering and identity-aware access concepts where applicable, enterprise egress enforcement, segmentation and policy patterns, and design considerations such as TLS inspection and traffic steering, expressed at a pattern and control-integration level.
  • Provide engineering leadership across edge and connectivity adjacencies that materially impact perimeter posture and service delivery, including Cisco and Arista edge environments, colocation and interconnect ecosystems (including Equinix Fabric), and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLink, with awareness of multi-cloud interconnect considerations.
  • Establish and run governance mechanisms that accelerate remediation while preserving strong controls, including backlog governance, exception handling, risk acceptance and closure workflows, traceability and auditability requirements, and reporting that ties delivery milestones to risk reduction and resilience outcomes.
  • Drive operational excellence at scale for perimeter, proxy, and SSE services in the US, including incident, change, and problem management rigor, observability and resiliency validation practices, automation to improve repeatability and evidence quality, reduction of client and partner impact, and execution of Technology Lifecycle Management (TLM) and modernization outcomes tied to stability and risk reduction.

Required qualifications, capabilities, and skills

  • Proven experience in network security / SASE/ SSE/ identity security / security engineering (or equivalent depth).
  • Strong understanding ofZero Trustprinciples, policy-based access, segmentation, and secure egress.
  • Hands-on experience withproxy/gateway architectures(forward proxy, reverse proxy, IAP patterns) and secure internet access controls. Deep knowledge ofSAML, OIDC, OAuth 2.0 concepts, JWT(signing, verification, JWKs, rotation, scopes/claims, replay protection).
  • Demonstrated experience leading effective use of approved AI-assisted software development tools (e.g., for coding, code review, test acceleration, troubleshooting) with the ability to set team expectations for validating AI outputs for correctness, performance, and security.
  • Strong understanding of responsible AI use in engineering workflows, including data sensitivity considerations, secure handling of inputs/outputs, and adherence to resiliency and security expectations; experience coaching engineers on safe, compliant adoption within delivery practices
  • Demonstrated experience delivering regional execution ownership in the US (or North America) for infrastructure and/or security platforms, including prioritization, cross-team coordination, and sustained accountability for operational and delivery outcomes.
  • Experience supervising engineers and delivering cross-team remediation, modernization, and platform programs with clear scope, dependency management, delivery milestones, and measurable outcomes.
  • Strong knowledge of network and perimeter security architecture and controls, including segmentation, routing and policy considerations, encryption and access control patterns, and defense-in-depth design principles.
  • Experience designing, delivering, or operating proxy and/or SSE capabilities at enterprise scale, including the ability to translate security requirements into deployable patterns and operational guardrails.
  • Strong experience translating security requirements into deployable edge and perimeter-adjacent connectivity patterns, including Cisco and Arista environments, and the ability to align engineering decisions to operational and control requirements.
  • Working knowledge of interconnect and colocation connectivity models (including Equinix Fabric) and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLink, with the ability to incorporate these into perimeter and egress designs without compromising stability or controls.

Preferred qualifications, capabilities, and skills

  • Experience integrating US delivery requirements and stakeholder needs into global standards, reference architectures, and governance models while maintaining a consistent global risk posture.
  • Experience leading AI-threat-informed remediation programs, including adapting standards and engineering patterns to account for high-velocity reconnaissance, rapid technique iteration, and automation-driven exploitation attempts, without sacrificing control integrity or operational stability.
  • Experience building enterprise-scale governance programs for security engineering, including controls-by-design, exception frameworks, audit-ready traceability, and measurable risk reduction reporting.
  • Experience with large-scale operations for externally facing or security enforcement services, including observability strategy, resilience testing, incident response alignment, and reduction of repeat incidents and client-impacting events.
  • Experience designing and operating hybrid edge architectures and cloud interconnect patterns across multiple cloud providers.
  • Security certifications such as CISSP, CCSP, or comparable credentials.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Infrastructure Engineer - Proxy/SSE Network Security
Lead Infrastructure Engineer - Proxy/SSE Network Security

JPMorgan Chase & Co. • City of Westminster

On-site
GBP 90,000 - 140,000
Lead Infrastructure Engineer - Proxy/SSE Network Security
Lead Infrastructure Engineer - Proxy/SSE Network Security

JPMorgan Chase & Co. • City Of London

On-site
GBP 120,000 - 160,000
Lead Infrastructure Engineer - Proxy/SSE Network Security
Lead Infrastructure Engineer - Proxy/SSE Network Security

JPMorganChase • Greater London

On-site
GBP 120,000 - 160,000
Lead Software Engineer - Proxy & SSE Network Security
Lead Software Engineer - Proxy & SSE Network Security

Next Frontier Capital • Greater London

On-site
GBP 112,000 - 138,000
Lead Software Engineer - Proxy/SSE Network Security
Lead Software Engineer - Proxy/SSE Network Security

Next Frontier Capital • Greater London

On-site
GBP 112,000 - 138,000
Lead Infrastructure Engineer - Zero Trust & Proxy/SSE
Lead Infrastructure Engineer - Zero Trust & Proxy/SSE

JPMorganChase • Greater London

On-site
GBP 120,000 - 160,000
Senior Infrastructure Engineer - Secure Proxy & SSE Network
Senior Infrastructure Engineer - Secure Proxy & SSE Network

JPMorgan Chase & Co. • City Of London

On-site
GBP 120,000 - 160,000
Senior Proxy & SSE Network Security Lead
Senior Proxy & SSE Network Security Lead

JPMorgan Chase & Co. • Greater London

On-site
GBP 120,000 - 180,000
Lead Network Security Engineer — Zero Trust & SSE Architect
Lead Network Security Engineer — Zero Trust & SSE Architect

JPMorgan Chase & Co. • City of Westminster

On-site
GBP 90,000 - 140,000
Lead Security Engineer
Lead Security Engineer

JPMorganChase • Greater London

On-site
GBP 80,000 - 120,000