Senior Lead Cybersecurity Engineer

JPMorgan Chase & Co.
Charing Cross, United Kingdom
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Charing Cross, United Kingdom

Tech stack

C
Artificial Intelligence
Software System Penetration Testing
Assembly Language
BIOS
C++
Cloud Computing
Computer Security
Firmware
Intrusion Detection Systems
Joint Test Action (IEEE Standards)
Python
Machine Learning
Reverse Engineering
Software Engineering
Blue Team (Cyber Security)
Hardware Debugging
Programming Languages

Job description

As a Senior Lead Security Engineer at JPMorganChase within the CTC, you are an integral part of an agile team that works to deliver security solutions focused on firmware and hardware threat detection. You will help safeguard critical infrastructure by identifying, investigating, and responding to threats at the firmware level, ensuring the integrity of our systems and preventing misuse, circumvention, and malicious behavior. Drive significant business impact through your capabilities and contributions, applying deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains., * Triage alerts to identify potential firmware threats

  • Distinguish false positives from real threats and escalate as appropriate
  • Investigate unauthorized firmware changes and anomalies in BIOS, BMC, and network firmware
  • Perform root cause analysis to determine what changed, when, how, and who/what triggered it
  • Collaborate with the blue team for log monitoring and detection
  • Work closely with firmware subject matter experts for deep technical analysis
  • Facilitate security requirements clarification for multiple networks to enable multi-level security
  • Recommend business modifications during periods of vulnerability to senior business leaders
  • Manage resources and triage based on risk assessments of various threats
  • Contribute to a team culture of diversity, opportunity, inclusion, and respect

Requirements

  • Incident response and detection background, preferably with experience in endpoint detection (CrowdStrike, Defender, etc.) or network detection (IDS/IPS, Zeek, etc.)
  • Skilled in planning, designing, and implementing enterprise-level security solutions
  • Advanced in one or more programming languages, including C++, C, Python, and/or assembly language (to demonstrate depth of technical knowledge)
  • Advanced knowledge of software application development and technical processes, with considerable in-depth knowledge in one or more technical disciplines (e.g., cloud, artificial intelligence, machine learning, mobile, etc.)
  • Extensive experience with threat modeling, discovery, vulnerability, and penetration testing
  • Ability to tackle design and functionality problems independently with little to no oversight
  • Practical cloud native experience
  • Strong documentation skills
  • Strong collaboration skills with engineering, architecture, and software development teams

Preferred qualifications, capabilities, and skills

  • Exposure to firmware/BIOS security (not mandatory, but a plus)
  • Understanding of supply chain risks
  • Proficiency in reverse engineering firmware and hardware
  • Experience with hardware debugging tools (JTAG, logic analyzers, oscilloscopes)
  • Bug bounty achievements
  • Experience collaborating with cross-functional teams, including engineering and architecture

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers., JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management., Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.

Apply for this position