JPMorganChase Logo

JPMorganChase

Sr. Lead Security Engineer

Posted 17 Days Ago
Be an Early Applicant
Hybrid
Dublin
Senior level
Hybrid
Dublin
Senior level
Leads enterprise product security across Google Cloud, AWS, AI applications, and software development. Designs security solutions, develops threat-modeling frameworks, conducts code reviews and vulnerability testing, integrates secure practices into the SDLC, and creates security policies. Triages threats, assesses risks, manages corrective actions, communicates findings to technical and executive stakeholders, and validates AI-assisted security recommendations for security, resiliency, data protection, and auditability.
The summary above was generated by AI

Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.

As a Senior Lead Security Engineer at JPMorganChase within the Enterprise Product Security with expertise in Google Cloud, artificial intelligence (AI), application security, threat modelling and the software development lifecycle (SDLC), you are an integral part of an agile team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behaviour. Drive significant business impact through your capabilities and contributions and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.

Job responsibilities


  • Facilitates security requirements clarification for multiple networks to enable multi-level security to satisfy organisational needs.
  • Works with stakeholders and senior business leaders to recommend business modifications during periods of vulnerability and serve as function-wide subject matter expert in one or more areas of focus 
  • Be responsible for triaging based on risk assessments of various threats, manage resources to cover impact of disruptive events and implement corrective actions to prevent future occurrences.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesising threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations. 
  • Develop and enhance threat modelling frameworks, processes, and documentation tailored to organizational needs. Communicate threat modelling findings and risk mitigation strategies to both technical and non-technical stakeholders, including executive leadership.
  • Cloud Security: Design, implement, and manage security solutions in Google Cloud Platform (GCP) to protect sensitive data and applications.
  • AI Security: Develop and enforce security controls for AI applications, particularly those involving coding assistants, ensuring they are resilient against threats and vulnerabilities.
  • Application Security: conduct threat modelling, code reviews, and vulnerability testing for applications to identify and mitigate security risks.
  • SDLC Integration: Collaborate with development teams to integrate security practices into the software development lifecycle, ensuring security is a fundamental aspect of application design and deployment.
  • Policy Development: Develop and maintain security policies, standards, and procedures to ensure compliance with industry regulations and best practices.

Required qualifications, capabilities, and skills

  • Experience in security engineering or related field and a bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field
  • Proven experience with Google Cloud Platform (GCP) security services and tools and practical cloud native experience, in particular AWS,
  • Experience with designing, building and running security solutions at scale and knowledge of security frameworks and standards (e.g., OWASP, NIST, ISO 27001).
  • Strong understanding of application security principles and practices.
  • Experience with the software development lifecycle (SDLC) and secure coding practices.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Skilled in planning, designing, and implementing enterprise-level security solutions
  • Advanced in one or more programming languages (e.g., Python, Java) and advanced knowledge of software application development and technical processes with considerable in-depth knowledge in one or more technical disciplines (e.g., cloud, artificial intelligence, machine learning, mobile, etc.)
  • Extensive experience with threat modelling, discovery, vulnerability, and penetration testing
  • Strong analytical and problem-solving skills, the ability to work independently and as part of a team and excellent communication and collaboration abilities.

Preferred qualifications, capabilities, and skills

  • Relevant certifications such as CISSP, CISM, CEH, or Google Cloud Professional Cloud Security Engineer are a plus.
  • Experience with multiple cloud solutions 

About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Similar Jobs

Yesterday
Remote or Hybrid
Expert/Leader
Expert/Leader
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead Site Reliability Engineer responsible for application reliability, scalability, performance, observability, automation, incident response, capacity planning, and operational risk management. The role develops high-availability solutions, supports production readiness, troubleshoots complex issues, applies cloud and DevOps practices, improves monitoring and resilience, and mentors junior engineers.
Top Skills: AWSAzureBashCi/CdContainer OrchestrationContainerizationGoGoogle Cloud PlatformLinuxPythonUnix
Yesterday
Hybrid
Senior level
Senior level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead the planning, architecture, development, and delivery of scalable software solutions for Mastercard’s Emerging Data Signals product. Drive AI and emerging-technology initiatives from concept through production, champion automation across the software lifecycle, collaborate with global engineering and business teams, and provide technical leadership for customer integrations and platform adoption.
Top Skills: Ai ModelsAPIsJavaJestNode.jsNpmReactWebpack
Yesterday
Hybrid
Entry level
Entry level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Provides independent second-line oversight of technology and security risks across European markets. Reviews control design and effectiveness, monitors remediation, maintains technology risk frameworks, develops risk metrics and reporting, supports operational resilience and security strategies, represents risk at governance forums, and assists with regulatory examinations and submissions.
Top Skills: Governance Risk And Compliance (Grc) ToolsIsoNist Csf

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account