> Markdown version of [/jobs/ext/1444736-lead-software-engineer-proxy-sse-network-security](https://www.wearedevelopers.com/jobs/ext/1444736-lead-software-engineer-proxy-sse-network-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Software Engineer - Proxy/SSE Network Security - **Company:** JPMorganChase - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Layers, Software Applications, Audit Trail, Automation of Tests, Software as a Service, Software Quality, Code Review, Domain Name System Security Extensions, Network Security, Network Architecture, Routing, Network Service, OAuth, OpenID, Software Tools, Broadcom, Zero Trust Network Access, Reverse Proxy, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Software Engineering, Software Systems, Strategies of Testing, Toolchain, Network Switches, Enterprise Software Applications, Production Code, Code Restructuring, Cisco - **Published:** July 26, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=7562c87a60d2eaa1 ## About the Role * 5+ years in network security / SASE/ SSE/ identity security / security engineering (or equivalent depth). * Strong understanding of Zero Trust principles, policy-based access, segmentation, and secure egress. * Hands-on experience with proxy/gateway architectures (forward proxy, reverse proxy, IAP patterns) and secure internet access controls. * Deep knowledge of SAML, OIDC, OAuth 2.0 concepts, JWT (signing, verification, JWKs, rotation, scopes/claims, replay protection). * Demonstrated experience leading effective use of approved AI-assisted software development tools (e.g., for coding, code review, test acceleration, troubleshooting) with the ability to set team expectations for validating AI outputs for correctness, performance, and security. * Strong understanding of responsible AI use in engineering workflows, including data sensitivity considerations, secure handling of inputs/outputs, and adherence to resiliency and security expectations; experience coaching engineers on safe, compliant adoption within delivery practices * Demonstrated experience delivering regional execution ownership in the US (or North America) for infrastructure and/or security platforms, including prioritization, cross-team coordination, and sustained accountability for operational and delivery outcomes. * Experience supervising engineers and delivering cross-team remediation, modernization, and platform programs with clear scope, dependency management, delivery milestones, and measurable outcomes. * Strong knowledge of network and perimeter security architecture and controls, including segmentation, routing and policy considerations, encryption and access control patterns, and defense-in-depth design principles. * Experience designing, delivering, or operating proxy and/or SSE capabilities at enterprise scale, including the ability to translate security requirements into deployable patterns and operational guardrails. * Strong experience translating security requirements into deployable edge and perimeter-adjacent connectivity patterns, including Cisco and Arista environments, and the ability to align engineering decisions to operational and control requirements. * Working knowledge of interconnect and colocation connectivity models (including Equinix Fabric) and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLink, with the ability to incorporate these into perimeter and egress designs without compromising stability or controls., * Experience integrating US delivery requirements and stakeholder needs into global standards, reference architectures, and governance models while maintaining a consistent global risk posture. * Experience leading AI-threat-informed remediation programs, including adapting standards and engineering patterns to account for high-velocity reconnaissance, rapid technique iteration, and automation-driven exploitation attempts, without sacrificing control integrity or operational stability. * Experience building enterprise-scale governance programs for security engineering, including controls-by-design, exception frameworks, audit-ready traceability, and measurable risk reduction reporting. * Experience with large-scale operations for externally facing or security enforcement services, including observability strategy, resilience testing, incident response alignment, and reduction of repeat incidents and client-impacting events. * Experience designing and operating hybrid edge architectures and cloud interconnect patterns across multiple cloud providers. * Security certifications such as CISSP, CCSP, or comparable credentials. ## Description As a Lead Software Engineer at JPMorganChase within the Corporate Sector - Enterprise Technology, you are an integral part of an agile team that works to enhance, build, and deliver trusted market-leading technology products in a secure, stable, and scalable way. As a core technical contributor, you are responsible for conducting critical technology solutions across multiple technical areas within various business functions in support of the firm's business objectives., * Executes creative Network security software solutions, design, development, and technical troubleshooting with ability to think beyond routine or conventional approaches to build solutions or break down technical problems * Develops secure high-quality production code, and reviews and debugs code written by others * Architect and implement Zero Trust Network Access (ZTNA) patterns for user-to-app and user-to-internet access, minimizing implicit trust and reducing lateral movement. * Build and operate an Identity-Aware Proxy (IAP) / policy enforcement point for web and application access, enforcing identity, device, and context-based policy decisions. * Implement or integrate Secure Gateway / Secure Web Gateway (SWG) capabilities (URL filtering, TLS inspection where approved, malware protection, sandboxing, egress controls, DNS security). * Experience with other SaaS based Secure Gateway vendor e.g. Zscaler, Netskope, paloalto, Broadcom ProxySG etc * Drives team adoption of enterprise-authorized AI-assisted engineering practices within the work environment to improve code quality, delivery speed, and operational outcomes (e.g., AI-assisted code review/refactoring, test strategy acceleration, incident/root-cause analysis support), while establishing consistent validation standards (secure coding, peer review, automated testing) and promoting reuse of effective patterns across the team. * Applies knowledge of tools within the Software Development Life Cycle toolchain, including enterprise-authorized AI-assisted development and automation capabilities, to improve the value realized by automation. * Good understanding of network infrastructure, network security concepts and application layer protocols (http/https) and vulnerability mitigation * Identifies opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systems * Own the US perimeter, proxy, and SSE/SASE engineering roadmap and execution, including intake, prioritization, dependency management, delivery governance, and stakeholder alignment across cybersecurity, network services, operations, and application and platform teams. * Define and operationalize standards, reference architectures, and reusable engineering patterns for perimeter and egress controls, including forward proxy and secure web gateway patterns, access brokering and identity-aware access concepts where applicable, enterprise egress enforcement, segmentation and policy patterns, and design considerations such as TLS inspection and traffic steering, expressed at a pattern and control-integration level. * Provide engineering leadership across edge and connectivity adjacencies that materially impact perimeter posture and service delivery, including Cisco and Arista edge environments, colocation and interconnect ecosystems (including Equinix Fabric), and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLink, with awareness of multi-cloud interconnect considerations. * Establish and run governance mechanisms that accelerate remediation while preserving strong controls, including backlog governance, exception handling, risk acceptance and closure workflows, traceability and auditability requirements, and reporting that ties delivery milestones to risk reduction and resilience outcomes. * Drive operational excellence at scale for perimeter, proxy, and SSE services in the US, including incident, change, and problem management rigor, observability and resiliency validation practices, automation to improve repeatability and evidence quality, reduction of client and partner impact, and execution of Technology Lifecycle Management (TLM) and modernization outcomes tied to stability and risk reduction., Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Are Software Engineer Wages Being Pushed Down? A Report on Tech Salaries](https://www.wearedevelopers.com/magazine/417-are-software-engineer-wages-being-pushed-down-a-report-on-tech-salaries) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)