Senior Lead Cybersecurity Architect

JPMorgan Chase & Co.
Plano, TX, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$137,750.0 - $225,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software Applications Cloud Engineering Cyber Security Continuous Integration Software Design Patterns Distributed Systems Information Systems Security Architecture Professional Software Engineering Devsecops Microservices

Job description

  • You will guide the evaluation of current cybersecurity processes, controls and lead the evaluation of new technology using existing standards and frameworks.
  • Contribute toward the development of new controls and design patterns for existing or emerging technologies.
  • Regularly provide technical guidance and direction to support the business and its technical teams, contractors, and vendors.
  • Lead threat modeling for complex applications and platform services (including cloud-native and distributed architectures), document findings, and drive mitigations into architecture decisions and engineering backlogs.
  • Serve as function-wide subject matter expert in one or more areas of focus.
  • Actively contribute to the engineering community as an advocate of firmwide frameworks, tools, and practices of a secure Software Development Life Cycle.
  • Influence peers and project decision-makers to consider the use and application of secure leading-edge technologies., Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Requirements

  • 6+ years of applied experience in cybersecurity architecture.
  • Experience delivering enterprise-level cybersecurity solutions and controls for software applications and/or platforms.
  • Experience designing security architecture and controls for modern environments (e.g., public cloud, containers, and distributed systems). Experience integrating security into the software development lifecycle, including continuous integration and continuous delivery (CI/CD) and DevSecOps workflows.

  • Demonstrated experience leading threat modeling for complex systems (e.g., cloud-native, containerized, microservices, or distributed platforms) and translating results into actionable security requirements and design changes.
  • Experience applying recognized threat modeling methodologies and frameworks (e.g., STRIDE or PASTA) and producing audit-ready artifacts (e.g., threat models, abuse cases, risk statements, mitigation plans).
  • Experience modernizing existing security controls for emerging technologies by creating reusable architecture patterns and implementation guidance that engineering teams can adopt.
  • Ability to evaluate current and emerging technologies and recommend security architecture options for future-state designs.
  • Experience partnering with engineering teams to influence architecture and implementation decisions.
  • Experience communicating complex security concepts to senior business leaders and technical stakeholders in writing and verbally.
  • Working knowledge of common security standards and frameworks used to assess and design controls (e.g., NIST frameworks).

Preferred qualifications, capabilities, and skills:

  • Knowledge of threat landscape for artificial intelligence.
  • CISSP, CCSP. Technical Writing.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • Retirement plan, We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

Play a vital role in shaping the future of an iconic company and make a direct impact in a dynamic environment designed for top achievers.

As a Senior Lead Cybersecurity Architect at JPMorganChase, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications and platform products. Drive significant business impact through your capabilities and contributions, and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains., JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all