JOB DESCRIPTION
Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.
As a Lead Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls you are an integral part of an agile team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Drive significant business impact through your capabilities and contributions and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.
Job responsibilities
-
Facilitates security requirements clarification for multiple networks to enable networks with multi-level security to satisfy organizational needs
-
Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
-
Works with stakeholders and senior business leaders to recommend business modifications during periods of vulnerability
-
Responsible for triaging based on risk assessments of various threats and managing resources to cover impact of disruptive events
-
Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
-
Establish secure-by-design engineering practices (threat modeling, secure coding standards, dependency hygiene, security testing) integrated into the SDLC/CI/CD.
-
Works effectively with Product, Data, Security, and Risk/Compliance to shape requirements, define controls, and drive approvals without stalling delivery.
-
Coaches engineers on agent patterns, secure coding, and testing; raises the bar through pairing, design reviews, and documentation that scales.
-
Sets a coherent architecture, makes trade-offs explicit (quality vs. latency vs. cost vs. risk), and aligns stakeholders on a roadmap that reduces rework.
Required Qualifications Capabilities and Skills
-
Formal training or certification on software engineering concepts and advanced applied experience
-
Skilled in planning, designing, and implementing enterprise-level security solutions
-
Proven experience designing and delivering production-grade AI agent platforms or services — including orchestration, tool routing, memory and state management, and failure handling — or equivalent distributed systems
-
Advanced proficiency in one or more programming languages with the ability to tackle design and functionality problems independently with little to no oversight
-
Advanced knowledge of software application development and technical processes with considerable depth in one or more disciplines such as cloud, artificial intelligence, machine learning, or mobile
-
Extensive experience with threat modeling, discovery, vulnerability assessment, and penetration testing
-
Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows, with strong validation habits and awareness of data sensitivity
-
Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations
-
Ability to design multi-step agent workflows — including planning, execution, reflection, memory, tool routing, and guardrails — with state management and recovery from partial failures
Preferred qualifications, capabilities, and skills
Advanced Cloud, AI and Cybersecurity certifications such as AWS Certified Generative AI Developer, AWS DevOps, OCP, CCSP
Demonstrated experience with multiple programming languages: Java, Python
Demonstrated experience of designing, developing and running large scale systems on AWS and Infrastructure as Code (Terraform)
ABOUT US
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
ABOUT THE TEAM
Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.