Lead Security Engineer - Platform Engineer - Endpoint Security

JPMorgan Chase & Co.

Columbus (OH)

On-site

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

JPMorgan Chase & Co. seeks an experienced security-focused software engineer to design, build, and ship production-quality software across Mac, Windows, Linux, and virtual desktop environments.

The role leads a portfolio of endpoint security platforms, architects a managed binary allowlisting platform via infrastructure-as-code, and advances cross‑platform authentication tooling with containerized deployment in mind.

Qualifications

  • Formal training or certification on security engineering concepts and 5+ years applied experience
  • Advanced proficiency in one or more major programming languages such as Python, Java, JavaScript/TypeScript, Go, Rust, or C++, with a demonstrated ability to build and ship production software
  • Hands-on enterprise experience managing at least two of the following endpoint platforms: Mac, Windows, virtual desktop infrastructure, or Linux
  • Proven experience with containers (Docker, Kubernetes), public cloud platforms, and infrastructure-as-code tooling
  • Proficiency across the full software development lifecycle, including CI/CD pipelines, GitOps workflows, and automated testing practices
  • Working knowledge of secure development practices with the ability to design, build, and operate controls that are audit-defensible and tamper-resistant
  • Demonstrated ability to decompose complex, ambiguous technical problems into clearly scoped, deliverable engineering work
  • Experience serving as a technical lead — driving execution, setting technical direction, and mentoring engineers through code reviews — while remaining hands-on in the codebase

Responsibilities

  • Design, build, and ship production-quality software across Mac, Windows, Linux, and virtual desktop environments, serving as the primary technical contributor for a portfolio of endpoint security platforms
  • Architect and operate a managed binary allowlisting platform deployed via infrastructure-as-code in a private cloud environment, including automation that generates per-binary rules at application-packaging time
  • Develop and maintain cross-platform endpoint authentication tooling — written in a compiled language — that enables applications to authenticate through enterprise proxy infrastructure, including upcoming support for containerized deployment
  • Modernize system policy deployment across Windows and virtual desktop environments using GitOps principles, building automated pipelines that scan, grade, and deploy changes in a controlled, auditable manner
  • Drive technical direction and day-to-day execution across the team's engineering portfolio, ensuring delivery against milestones while maintaining high standards for code quality, security, and resilience
  • Conduct rigorous design and code reviews, mentoring associate engineers and elevating the technical capabilities of the team through hands-on guidance
  • Identify manual, high-overhead processes and architect automation solutions that eliminate operational toil and scale across the firm's endpoint estate
  • Collaborate cross-functionally with application teams, infrastructure, and security stakeholders to ensure platforms are consumable, audit-defensible, and aligned to enterprise standards
  • Apply secure development practices throughout the full software development lifecycle, designing controls that are tamper-resistant and hold up to regulatory scrutiny

Skills

Python
Java
JavaScript/TypeScript
Go
Rust
C++
Security engineering
CI/CD
GitOps workflows
Docker
Kubernetes
Terraform

Tools

Docker
Kubernetes
Terraform

Job description

Job responsibilities


  • Design, build, and ship production-quality software across Mac, Windows, Linux, and virtual desktop environments, serving as the primary technical contributor for a portfolio of endpoint security platforms

  • Architect and operate a managed binary allowlisting platform deployed via infrastructure-as-code in a private cloud environment, including automation that generates per-binary rules at application-packaging time

  • Develop and maintain cross-platform endpoint authentication tooling — written in a compiled language — that enables applications to authenticate through enterprise proxy infrastructure, including upcoming support for containerized deployment

  • Modernize system policy deployment across Windows and virtual desktop environments using GitOps principles, building automated pipelines that scan, grade, and deploy changes in a controlled, auditable manner

  • Drive technical direction and day-to-day execution across the team's engineering portfolio, ensuring delivery against milestones while maintaining high standards for code quality, security, and resilience

  • Conduct rigorous design and code reviews, mentoring associate engineers and elevating the technical capabilities of the team through hands‑on guidance

  • Identify manual, high‑overhead processes and architect automation solutions that eliminate operational toil and scale across the firm's endpoint estate

  • Collaborate cross‑functionally with application teams, infrastructure, and security stakeholders to ensure platforms are consumable, audit‑defensible, and aligned to enterprise standards

  • Apply secure development practices throughout the full software development lifecycle, designing controls that are tamper‑resistant and hold up to regulatory scrutiny


Required qualifications, capabilities, and skills


  • Formal training or certification on security engineering concepts and 5+ years applied experience

  • Advanced proficiency in one or more major programming languages such as Python, Java, JavaScript/TypeScript, Go, Rust, or C++, with a demonstrated ability to build and ship production software

  • Hands‑on enterprise experience managing at least two of the following endpoint platforms: Mac, Windows, virtual desktop infrastructure, or Linux

  • Proven experience with containers (Docker, Kubernetes), public cloud platforms, and infrastructure‑as‑code tooling

  • Proficiency across the full software development lifecycle, including CI/CD pipelines, GitOps workflows, and automated testing practices

  • Working knowledge of secure development practices with the ability to design, build, and operate controls that are audit‑defensible and tamper‑resistant

  • Demonstrated ability to decompose complex, ambiguous technical problems into clearly scoped, deliverable engineering work

  • Experience serving as a technical lead — driving execution, setting technical direction, and mentoring engineers through code reviews — while remaining hands‑on in the codebase


Preferred qualifications, capabilities, and skills


  • Experience building security‑focused or systems‑level software on Mac, Windows, or Linux platforms

  • Familiarity with endpoint security concepts such as binary allowlisting, proxy and authentication flows, or system policy management

  • Experience implementing or evolving security controls within a large, regulated enterprise environment

  • Background in banking, financial services, or another highly regulated industry such as insurance or healthcare

  • Experience as a full‑stack developer in a large enterprise environment, with comfort across both application and infrastructure layers

  • Experience responsibly using enterprise‑authorized AI capabilities to accelerate development and validation, with strong habits around output validation and data sensitivity


#CTC
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Client Engineer
IT Client Engineer

Figureai • San Jose (CA)

On-site
USD 120,000 - 180,000
IT Client Engineer
IT Client Engineer

Figure • San Jose (CA)

On-site
USD 180,000 - 210,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Information Technology Security Engineer
Information Technology Security Engineer

DTG Consulting Solutions, Inc. • New York (NY)

On-site
USD 110,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Lead Security Engineer - Platform Engineer - Endpoint Security
Lead Security Engineer - Platform Engineer - Endpoint Security

Fairygodboss • Columbus (OH)

On-site
USD 150,000 - 210,000
Principal Application Security Engineer
Principal Application Security Engineer

CDW • United States

On-site
USD 180,000 - 240,000
Lead Security Engineer - Platform Engineer - Endpoint Security
Lead Security Engineer - Platform Engineer - Endpoint Security

JPMorganChase • Columbus (OH)

On-site
USD 130,000 - 200,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000