Senior Lead Security Engineer

JPMorgan Chase & Co.

New York (NY)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

JPMorgan Chase & Co. is seeking a Senior Lead Security Engineer to partner with product, technology, and business stakeholders to evaluate and secure features, platforms, and third‑party solutions.

The role emphasizes secure design, threat modeling, and risk‑based decisions to reduce misuse and risk across modern tech environments. You will translate complex findings into actionable mitigation options and architecture recommendations for senior leaders while driving secure design across

Qualifications

  • 5+ years of applied cybersecurity experience in enterprise settings.
  • Experience delivering security controls and secure design patterns.
  • Expertise in threat modeling, threat assessments, secure design reviews, vulnerability analysis, risk evaluation, and security requirements definition.

Responsibilities

  • Provide guidance to product, engineering, business, contractor, and vendor teams to support secure design and delivery of new capabilities
  • Conduct and maintain threat models, threat assessments, and secure design reviews for enterprise applications, cloud platforms, APIs, integrations, and third‑party vendor solutions
  • Identify, document, and communicate cybersecurity risks, mitigation options, compensating controls, and recommended solutions across multiple technical areas and business functions
  • Partner with stakeholders and senior business leaders to recommend design, implementation, or operational changes during periods of vulnerability, incident response, remediation, or emerging risk
  • Evaluate current and emerging technologies, including external vendor offerings and internal platforms, through outcomes‑oriented review of security designs, technical capabilities, and fit within existing systems and cybersecurity architecture
  • Identify opportunities to eliminate, reduce, or automate recurring security issues and improve the overall security posture of applications, systems, and technology processes
  • Leverage enterprise‑authorized artificial intelligence capabilities to accelerate security architecture and engineering workflows, while validating outputs and handling data according to sensitivity and security requirements
  • Drive reuse‑first adoption of AI‑assisted security validation within the SDLC and delivery toolchain to improve control testing, remediation quality, traceability, auditability, and resiliency
  • Lead or contribute to communities of practice that promote awareness, consistency, and adoption of cybersecurity technologies, secure design patterns, and risk management practices

Skills

Threat modeling
Security architecture
Security engineering
Cloud security
Risk assessment
Secure design patterns
Communication skills
Programming knowledge

Tools

AWS
Azure
GCP
SAML

Job description


Join one of the world’s most influential companies and leverage your cybersecurity expertise to make a direct and meaningful impact across the financial industry.

As a Senior Lead Security Engineer at JPMorganChase within Cybersecurity and Technology Controls, you will partner with product, technology, and business stakeholders to evaluate the security of new features, platforms, applications, and third‑party solutions. You will apply secure design principles, threat modeling, and risk‑based decision‑making to reduce misuse, circumvention, and malicious behaviour across modern technology environments. You will serve as a senior technical advisor, translating complex findings into clear mitigation options, architecture recommendations, and risk narratives for senior stakeholders.

Job responsibilities
  • Provide technical guidance and direction to product, engineering, business, contractor, and vendor teams to support secure design and delivery of new capabilities
  • Conduct and maintain threat models, threat assessments, and secure design reviews for enterprise applications, cloud platforms, application programming interfaces, integrations, and third‑party vendor solutions
  • Identify, document, and communicate cybersecurity risks, mitigation options, compensating controls, and recommended solutions across multiple technical areas and business functions
  • Partner with stakeholders and senior business leaders to recommend design, implementation, or operational changes during periods of vulnerability, incident response, remediation, or emerging risk
  • Evaluate current and emerging technologies, including external vendor offerings and internal platforms, through outcomes‑oriented review of security designs, technical capabilities, and fit within existing systems and cybersecurity architecture
  • Identify opportunities to eliminate, reduce, or automate recurring security issues and improve the overall security posture of applications, systems, and technology processes
  • Leverage enterprise‑authorized artificial intelligence capabilities to accelerate security architecture and engineering workflows (for example, risk identification, threat assessment synthesis, documentation, and decision support), while validating outputs and handling data according to sensitivity and security requirements
  • Drive reuse‑first adoption of artificial intelligence–assisted security validation within the software development life cycle and delivery toolchain to improve control testing, remediation quality, traceability, auditability, and resiliency
  • Lead or contribute to communities of practice that promote awareness, consistency, and adoption of cybersecurity technologies, secure design patterns, and risk management practices
Required qualifications, capabilities and skills
  • Formal training or certification in cybersecurity, security architecture, security engineering, or a related technical discipline, with 5+ years of applied experience
  • Hands‑on experience delivering, advising on, or implementing enterprise cybersecurity solutions, security controls, secure design patterns, or risk mitigation strategies
  • Expertise in threat modeling, threat assessments, secure design reviews, vulnerability analysis, risk evaluation, and security requirements definition
  • Proficiency in modern technology environments across one or more disciplines such as public cloud, application programming interfaces, identity and access management, artificial intelligence and machine learning, mobile, infrastructure, or application security
  • Ability to evaluate current and emerging technologies and recommend practical security solutions aligned to target architecture, business priorities, resiliency expectations, and risk appetite
  • Deep expertise in one or more programming languages, platforms, cloud services, security tools, or application technologies, with the ability to review technical designs and engage credibly with engineering teams
  • Experience partnering with product and technology teams to remediate vulnerabilities, incidents, control gaps, recurring issues, or design weaknesses
  • Experience using enterprise‑authorized artificial intelligence capabilities to support cybersecurity workflows, with strong validation practices and awareness of data sensitivity
  • Strong written and verbal communication skills, including the ability to explain complex technical risks, trade‑offs, and recommendations to senior business leaders and technical stakeholders
Preferred qualifications, capabilities and skills
  • Experience with cloud‑native security architecture, application programming interface security, identity federation, OAuth, SAML, secrets management, service‑to‑service authentication, or Zero Trust patterns
  • Familiarity with vulnerability management, penetration testing outputs, security testing methodologies, incident remediation, or secure‑by‑design practices
  • Experience evaluating third‑party vendor solutions, software as a service platforms, integrations, or emerging technologies from a cybersecurity architecture and risk perspective
  • Knowledge of security capabilities such as Security Service Edge, Cloud Access Security Broker, Security Information and Event Management, application programming interface gateways, proxy technologies, traffic inspection, or security monitoring platforms
  • Experience leading cross‑functional security reviews, design forums, architecture governance discussions, or communities of practice
  • Ability to balance technical depth with pragmatic, risk‑based decision‑making in complex enterprise environments

#CTC

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Lead Security Engineer
Sr Lead Security Engineer

JPMorgan Chase & Co. • Wilmington (DE)

On-site
USD 140,000 - 200,000
Sr Lead Security Engineer - Workforce
Sr Lead Security Engineer - Workforce

JPMorgan Chase & Co. • Wilmington (DE)

Hybrid
USD 140,000 - 220,000
Sr Lead Security Engineer
Sr Lead Security Engineer

Next Frontier Capital • Wilmington (DE)

On-site
USD 140,000 - 210,000
Lead Cybersecurity Architect
Lead Cybersecurity Architect

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 120,000 - 160,000
Lead Security Engineer - Cloud Threat Hunting
Lead Security Engineer - Cloud Threat Hunting

JPMorgan Chase & Co. • Kentucky

On-site
USD 150,000 - 210,000
Sr Lead Security Engineer
Sr Lead Security Engineer

Next Frontier Capital • Plano (TX)

On-site
USD 160,000 - 210,000
Sr Lead Cybersecurity Architect
Sr Lead Cybersecurity Architect

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 130,000 - 210,000
Lead Security Engineer - Python/Java Developer
Lead Security Engineer - Python/Java Developer

JPMorgan Chase & Co. • Wilmington (DE)

On-site
USD 140,000 - 190,000
Lead Cybersecurity Architect
Lead Cybersecurity Architect

JPMorgan Chase & Co. • Chicago (IL)

On-site
USD 130,000 - 160,000
Lead Cybersecurity Architect
Lead Cybersecurity Architect

JPMorganChase • Chicago (IL)

On-site
USD 157,000 - 215,000