JobConnect

Lead Security Engineer - Application Security

Join a world-class security engineering team where your expertise directly protects one of the most complex financial institutions in the world. At JPMorganChase, security engineers are empowered to think boldly, solve hard problems, and build solutions that matter — at a scale few organizations can offer. You will work alongside talented technologists and business leaders who are committed to staying ahead of evolving threats, and you will have access to the tools, resources, and support to grow your career in meaningful ways. This is your opportunity to make a lasting impact on the security posture of a global firm.

As a Lead Security Engineer at JPMorganChase within the Security Engineering team, you will serve as a core technical contributor responsible for designing, developing, and delivering high-quality security solutions that protect critical business functions. You will bring deep technical expertise and creative problem-solving to address complex security challenges across multiple technology domains. Your work will directly influence how the firm identifies, mitigates, and responds to security vulnerabilities — ensuring our systems remain resilient, compliant, and defensible. You will collaborate closely with stakeholders and senior business leaders to align security capabilities with evolving business needs.

Job Responsibilities

  • Design and implement creative, enterprise-grade security solutions that go beyond conventional approaches to address complex technical and threat-based challenges
  • Develop secure, high-quality production code and conduct thorough code reviews to identify and remediate vulnerabilities introduced by others
  • Minimize security risk by continuously monitoring industry insights and regulatory guidance to evolve security protocols and assess the effectiveness of existing controls
  • Partner with stakeholders and business leaders to understand security requirements and recommend strategic modifications during periods of elevated vulnerability or risk
  • Architect and maintain tamper-proof, audit-defensible methods across multiple technical areas and business functions
  • Leverage cloud-native services and infrastructure-as-code practices to build scalable, secure, and observable solutions in AWS environments
  • Apply enterprise-authorized AI-assisted development tools to accelerate engineering workflows, while critically validating outputs for correctness, security, and performance

Required qualifications, capabilities, and skills

  • Demonstrated ability to plan, design, and implement enterprise-level security solutions across complex, multi-domain environments
  • Advanced proficiency in Python with a strong focus on security best practices and secure coding standards
  • Proficiency across all phases of the Software Development Life Cycle, with an understanding of how security integrates at each stage
  • Advanced understanding of agile methodologies and continuous integration and delivery practices, including tools such as Jenkins, GitHub, and Spinnaker, as well as application resiliency and security principles
  • Proven ability to communicate effectively with senior business leaders on security risks, recommendations, and technical trade-offs
  • Hands-on experience with AWS cloud services — including Elastic Container Service, Elastic Compute Cloud, Lambda, EventBridge, S3, Identity and Access Management, CloudWatch, and Secrets Manager — as well as Terraform for infrastructure provisioning
  • Hands-on experience using enterprise-authorized AI-assisted software development tools within the work environment (e.g., for coding, test creation, troubleshooting, or documentation) with demonstrated ability to critically evaluate, validate, and refine AI-generated outputs for correctness, performance, and security
  • Understanding of responsible AI use in engineering workflows, including data sensitivity considerations, secure handling of inputs and outputs, and adherence to resiliency and security expectations; ability to guide peers on safe and effective usage within team practices

Preferred qualifications, capabilities, and skills

  • Familiarity with machine learning methodologies and model training concepts as applied to security use cases
  • Experience with AWS Aurora PostgreSQL or other SQL relational database platforms
  • Exposure to observability and monitoring tooling such as Dynatrace, Grafana, or Splunk
  • Working knowledge of Go or Java programming languages
  • Experience with automated functional and integration testing frameworks

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

Skills

  • Application Security
  • Secure Software Development Lifecycle (SSDLC)
  • Threat Modeling
  • Vulnerability Management
  • Cloud Security (AWS/Azure/GCP)
  • Security Architecture
  • Risk assessment

Related jobs

JPMorgan Chase & Co.Apply for this job