DescriptionJoin a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.
As a Senior Lead Security Engineer at JPMorganChase within the CTC you are an integral part of an agile team that works to deliver security solutions focused on firmware and hardware threat detection. You will help safeguard critical infrastructure by identifying investigating and responding to threats at the firmware level ensuring the integrity of our systems and preventing misuse circumvention and malicious behavior. Drive significant business impact through your capabilities and contributions applying deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.
Job responsibilities
- Triage alerts to identify potential firmware threats
- Distinguish false positives from real threats and escalate as appropriate
- Investigate unauthorized firmware changes and anomalies in BIOS BMC and network firmware
- Perform root cause analysis to determine what changed when how and who/what triggered it
- Collaborate with the blue team for log monitoring and detection
- Work closely with firmware subject matter experts for deep technical analysis
- Facilitate security requirements clarification for multiple networks to enable multi-level security
- Recommend business modifications during periods of vulnerability to senior business leaders
- Manage resources and triage based on risk assessments of various threats
- Contribute to a team culture of diversity opportunity inclusion and respect
Required qualifications capabilities and skills
- Incident response and detection background preferably with experience in endpoint detection (CrowdStrike Defender etc.) or network detection (IDS/IPS Zeek etc.)
- Skilled in planning designing and implementing enterprise-level security solutions
- Advanced in one or more programming languages including C C Python and/or assembly language (to demonstrate depth of technical knowledge)
- Advanced knowledge of software application development and technical processes with considerable in-depth knowledge in one or more technical disciplines (e.g. cloud artificial intelligence machine learning mobile etc.)
- Extensive experience with threat modeling discovery vulnerability and penetration testing
- Ability to tackle design and functionality problems independently with little to no oversight
- Practical cloud native experience
- Strong documentation skills
- Strong collaboration skills with engineering architecture and software development teams
Preferred qualifications capabilities and skills
- Exposure to firmware/BIOS security (not mandatory but a plus)
- Understanding of supply chain risks
- Proficiency in reverse engineering firmware and hardware
- Experience with hardware debugging tools (JTAG logic analyzers oscilloscopes)
- Bug bounty achievements
- Experience collaborating with cross-functional teams including engineering and architecture
Required Experience:
Senior IC
DescriptionJoin a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.As a Senior Lead Security Engineer at JPMorganChase within the CTC you are an integral part of an agile team that ...
DescriptionJoin a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.
As a Senior Lead Security Engineer at JPMorganChase within the CTC you are an integral part of an agile team that works to deliver security solutions focused on firmware and hardware threat detection. You will help safeguard critical infrastructure by identifying investigating and responding to threats at the firmware level ensuring the integrity of our systems and preventing misuse circumvention and malicious behavior. Drive significant business impact through your capabilities and contributions applying deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.
Job responsibilities
- Triage alerts to identify potential firmware threats
- Distinguish false positives from real threats and escalate as appropriate
- Investigate unauthorized firmware changes and anomalies in BIOS BMC and network firmware
- Perform root cause analysis to determine what changed when how and who/what triggered it
- Collaborate with the blue team for log monitoring and detection
- Work closely with firmware subject matter experts for deep technical analysis
- Facilitate security requirements clarification for multiple networks to enable multi-level security
- Recommend business modifications during periods of vulnerability to senior business leaders
- Manage resources and triage based on risk assessments of various threats
- Contribute to a team culture of diversity opportunity inclusion and respect
Required qualifications capabilities and skills
- Incident response and detection background preferably with experience in endpoint detection (CrowdStrike Defender etc.) or network detection (IDS/IPS Zeek etc.)
- Skilled in planning designing and implementing enterprise-level security solutions
- Advanced in one or more programming languages including C C Python and/or assembly language (to demonstrate depth of technical knowledge)
- Advanced knowledge of software application development and technical processes with considerable in-depth knowledge in one or more technical disciplines (e.g. cloud artificial intelligence machine learning mobile etc.)
- Extensive experience with threat modeling discovery vulnerability and penetration testing
- Ability to tackle design and functionality problems independently with little to no oversight
- Practical cloud native experience
- Strong documentation skills
- Strong collaboration skills with engineering architecture and software development teams
Preferred qualifications capabilities and skills
- Exposure to firmware/BIOS security (not mandatory but a plus)
- Understanding of supply chain risks
- Proficiency in reverse engineering firmware and hardware
- Experience with hardware debugging tools (JTAG logic analyzers oscilloscopes)
- Bug bounty achievements
- Experience collaborating with cross-functional teams including engineering and architecture
Required Experience:
Senior IC
View more
View less