DescriptionTake on a crucial role where youll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the worlds largest and most influential companies.
As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity & Tech Controls team you are an integral part of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse circumvention and malicious behavior. As a core technical contributor you are responsible for carrying out critical technology solutions with tamper-proof audit defensible methods across multiple technical areas within various business functions.
Job responsibilities
- Executes creative security solutions design development and technical troubleshooting with the ability to think beyond routine or conventional approaches to build solutions and break down technical problems.
- Develops secure and high-quality production code and reviews and debugs code written by others with a focus on Python backend development and Public cloud (AWS/Azure/GCP).
- Designs and develops APIs and backend services using Java or modules ensuring robust and scalable solutions.
- Minimizes security vulnerabilities by following industry insights and governmental regulations to continuously evolve security protocols including creating processes to determine the effectiveness of current controls.
- Works with stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability.
- Conducts discovery vulnerability penetration testing and threat scenarios on multiple organizational assets to identify and assess if vulnerabilities are present and executes threat modeling for multiple applications including external applications interacting with the internal JPMorgan Chase network.
- Adds to team culture of diversity equity inclusion and respect.
Required qualifications capabilities and skills
- Formal training or certification on Security engineering concepts and 3 years applied experience
- Experience in Python programming and cloud security engineering gained through both formal experience and practical application.
- Experience in Infrastructure as Code (IaC) tools such as Terraform Pulumi AWS CloudFormation Google Deployment Manager and Azure Resource Manager.
- Capable of planning designing and implementing enterprise-level security solutions.
- Proficient in all aspects of the Software Development Life Cycle within a public cloud environment.
- Have an advanced understanding of agile methodologies including CI/CD application resiliency and security
Preferred qualifications capabilities and skills
- Specific experience deploying commercial software at scale into an enterprise environment.
- Cloud computing related certifications with an AWS/Azure/GCP focus are strongly preferred such as AWS Certified Security Solutions Architect Developer Engineer or similar.
- Hands-on programming skills in one or more programming languages with a preference for Python.
- Experience effectively communicating with senior business leaders.