Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.
As a Senior Lead Security Engineer at JPMorgan Chase within the Cybersecurity Technology and Controls, you are an integral part of an agile team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Drive significant business impact through your capabilities and contributions and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.
Job responsibilities
Execute creative security solutions, design, development, and technical troubleshooting—think beyond routine or conventional approachesBuild work pipeline management tools for IAM and DB-PSL threat modeling teamsDesign and implement workflow automation for security assessment processesDevelop secure, high-quality production code (Java, Python, Node.js) and review/debug code written by othersBuild custom detections and attack path queries for enterprise AD environmentCollaborates with stakeholders and senior business leaders to recommend business modifications during periods of vulnerabilityBe responsible for triaging based on risk assessments of various threats and managing resources to cover impact of disruptive events
Required qualifications, capabilities, and skills
Formal training or certification on security concepts and 5+ years of applied experience in software engineering or software development, including experience building internal tools or workflow automationSkilled in planning, designing, and implementing enterprise-level solutionsExperience building internal tools, workflow automation, or pipeline management systemsExpertise in IAM technologies: OAuth2.0, SAML, ABAC, RBAC, PBAC, OPA.Advanced proficiency in Java, Python, or Node.js—production-quality codeAdvanced understanding of agile methodologies, CI/CD, Application Resiliency, Security, Service OwnershipExtensive experience with threat modeling, discovery, vulnerability, and penetration testingDeep understanding of Active Directory security: attack paths, Kerberos authentication, delegation, DACL/SACL permissions, Group Policy, and trust relationships
Preferred qualifications, capabilities, and skills
Experience with dashboard and reporting tools: Grafana, Splunk, Prometheus, custom dashboards.Experience with hybrid identity environments: Azure AD/Entra ID Connect, AWS Cognito, OIDC FederationFamiliarity with regulated industry environments (financial services, healthcare, government)Experience with BloodHound, SharpHound, or equivalent AD attack path analysis toolsCertifications: CISSP, AWS/Azure certifications