Your seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Software Security Engineer - Associate within Cybersecurity Technology & Controls, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm’s business objectives
Job responsibilities
Executes security solutions design, development, and technical troubleshooting with the ability to apply knowledge of existing security solutions to satisfy security requirements for internal clients (e.g., product, platform, application owners) Creates secure and high-quality production code and maintains algorithms that run synchronously with appropriate systems Applies specialized tools (e.g., vulnerability scanner) to analyze and correlate incident data to identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilities Minimizes security vulnerabilities by following industry insights and governmental regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls Conducts discovery, vulnerability, penetration testing, and threat scenarios on multiple organizational assets to identify and assess if vulnerabilities are present Executes threat modeling for multiple applications including external applications interacting with the internal JPMorgan Chase network Leads delivery of continuity related awareness, training, educational activities, and exercises in collaboration with senior stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability Adds to team culture of diversity, opportunity, inclusion, and respectRequired qualifications, capabilities, and skills
Obtain 3+ years of experience or equivalent knowledge with a Bachelors of Science in developing security engineering solutions, along with design and implementation of cloud security solutions on AWS, Azure, or GCP for best technical practices Experience developing security engineering solutions Overall knowledge of the Software Development Life Cycle Proficient in coding in one of more languages and frameworks (e.g., Python, Shell Scripting, automation tools, Terraform, etc.) Implement security best practices and compliance requirements into actionable policies for a secure cloud environment Manage policy changes using version control systems like GIT and collaborate with teams on platforms in GIT or Bit bucket Solid understanding of agile methodologies such as CI/CD, utilizing Terraform and Jenkins/Jules for infrastructure as a code to enhance deployments and updates for application resiliency, and security Demonstrates effective communication, and interpersonal skills Preferred qualifications, capabilities, and skills Familiar with software engineering concepts in a major public cloud platform like AWS, Azure, or GCP or hybrid cloud experience Proficient in Python for automation, backend development, and cloud management tool integration, with additional skills in Java being advantageous Strong understanding of security best practices and compliance standards for cloud environments