Lead Security Engineer

JPMorgan Chase & Co.

Plano (TX)

On-site

USD 150,000 - 210,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JPMorgan Chase & Co. is seeking a Lead Software Security Engineer to enhance and deliver trusted security-focused technology products. You will work in an agile team, applying deep technical expertise to tackle diverse security challenges across multiple technologies and applications.

Responsibilities include driving security requirements, automating cloud security, and collaborating with senior leaders to manage risk and ensure policy compliance in a large-scale cloud environment.

Qualifications

  • 5+ years of applied experience in security engineering or related field.
  • Strong coding skills in Java and Python/Go; Terraform experience.
  • Deep knowledge of AWS infrastructure, networking, and cloud security.
  • Experience with threat modeling, vulnerability management, and CI/CD integration.
  • Familiarity with WAFs (AWS WAF, Cloudflare, Akamai) and security automation.

Responsibilities

  • Clarify security requirements across multiple networks to enable secure ingress/egress and drive SDLC security maturity.
  • Deploy, administer, and integrate Cloud Network Security Platforms with a DevOps security approach.
  • Lead cloud security implementations for end-to-end automation, architecture, and operations transition.
  • Ensure engineering deliverables meet firm security standards and auditability requirements.
  • Collaborate with stakeholders and leadership to triage risk and guide resource allocation during incidents.
  • Apply AI-assisted practices within SDLC/toolchains to strengthen testing and compliance.

Job description

As a Lead Software Security Engineer at JPMorganChase, you are an integral part of an agile team that works to enhance, build, and deliver trusted technology products in a secure, stable, and scalable way. Drive significant business impact through your capabilities and contributions, and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of challenges that span multiple technologies and applications.

Job responsibilities
  • Facilitate security requirements clarification for multiple networks to enable multi-level security, satisfying organizational needs for both ingress and egress traffic. Work at code-level using java/ Python and drive the maturity of the Cybersecurity software development lifecycle with an advanced understanding of line of business technology drivers.
  • Perform deployment, administration, management, configuration, testing, documentation, operations, and integration tasks related to Cloud Network Security Platforms, championing a DevOps security model to ensure security is automated and elastic across all platforms.
  • Lead and develop new Cloud Security Implementations for both ingress and egress traffic. Design and develop strategies to provide end-to-end automation, architecture design, performance and monitoring, best practices, proof of concepts, product design, and transition to operations.
  • Ensure quality control of engineering deliverables and ensure firm policies are compliant with strict security standards. Drive decision-making by analyzing complex data systems, ensuring all engineering activities are in conformance with firm policies & objectives. Leverage DevOps tools to build, harden, maintain, and develop a comprehensive Cloud-based security orchestration platform for network security and infrastructure as code. Develop automated security and compliance capabilities in support of DevOps processes in a large-scale Cloud computing environment.
  • Collaborate with technologists, stakeholders, and senior business leaders to recommend business modifications during periods of vulnerability. Be responsible for triaging based on risk assessments of various threats and managing resources to cover the impact of disruptive events.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations. Collaborate with cross-functional teams, including IT, development, and operations, to ensure web application security.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
Required qualifications, capabilities, and skills
  • Formal training or certification on Security Engineering concepts and 5+ years of applied experience.
  • Advanced hands-on coding experience in java or Python/Go and Terraform. Expertise with AWS Infrastructure such as networking, EC2, Lambdas, server-less solutions, VPC, Route 53, autoscaling, Transit Gateway, API Gateway, Step Functions, secrets manager, and storage services.
  • Proficient in core concepts for Networking, Infrastructure as Code (IaaC), Public Cloud architecture, and Cloud Security.
  • Expertise in developing and designing complex cloud architectures, deploying scalable solutions, creating, and handling CI/CD pipelines, application resiliency, security design and implementation, and triaging issues in Agile Software Development Lifecycle methodology.
  • Extensive experience with threat modeling, discovery, vulnerability, and penetration testing. Ability to tackle design and functionality problems independently with little to no oversight.
  • Experience with WAF technologies such as AWS WAF, Akamai, Cloudflare, or similar.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
Preferred qualifications, capabilities, and skills
  • API Gateway Development
  • Custom proxy development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer- Java, Python
Lead Security Engineer- Java, Python

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 140,000 - 190,000
Sr Lead Security Engineer - Role Core
Sr Lead Security Engineer - Role Core

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 130,000 - 200,000
Lead Security Engineer
Lead Security Engineer

JPMorgan Chase & Co. • Tampa (FL)

On-site
USD 120,000 - 180,000
Sr Lead Security Engineer
Sr Lead Security Engineer

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 150,000 - 190,000
Lead Security Engineer
Lead Security Engineer

JPMorgan Chase • Plano (TX)

On-site
USD 150,000 - 230,000
Sr Lead Security Engineer - Workforce
Sr Lead Security Engineer - Workforce

JPMorgan Chase & Co. • Wilmington (DE)

Hybrid
USD 140,000 - 220,000
Sr Lead Security Engineer
Sr Lead Security Engineer

JPMorgan Chase & Co. • Wilmington (DE)

On-site
USD 140,000 - 200,000
Lead Security Engineer - Python
Lead Security Engineer - Python

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 140,000 - 170,000
Lead Security Engineer (Collab & Comm)
Lead Security Engineer (Collab & Comm)

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 140,000 - 200,000
Security Engineer III - (Java/Python full stack)
Security Engineer III - (Java/Python full stack)

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 120,000 - 150,000