Lead Software Engineer - Cloud Proxy

JPMorgan Chase & Co.
Plano, TX, United States
29 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$152,000.0 - $215,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Cloud Computing Complex Networks Computer Networks Continuous Integration Domain Name System (DNS) Identity and Access Management Python (Programming Language) Network Configuration and Change Management Network Connections
+16 more
Public Key Infrastructure Systems Development Life Cycle Reverse Proxy Software Engineering Squid (Proxy Server) SSL Certificate Management Cloud Platform System System Availability Boto3 AWS Lambda Amazon Virtual Private Cloud (VPC) Production Code Route53 Cloudwatch Terraform Vulnerability Analysis

Job description

As a Lead Security Engineer at JPMorganChase within the Cloud Edge Proxy team, you will help design, secure, and operate a critical cloud network perimeter platform that governs outbound cloud traffic at enterprise scale. You will work across engineering and business teams to ensure cloud connectivity is secure, reliable, and compliant - while enabling application teams to onboard and operate confidently., * Designs, develops, and maintains secure software solutions for cloud network perimeter infrastructure, writing high-quality production code and reviewing code written by others across the full development lifecycle

  • Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
  • Builds and manages infrastructure-as-code (IaC) to automate the provisioning, configuration, and scaling of cloud networking and proxy infrastructure in a consistent, repeatable, and auditable manner
  • Manages and operates enterprise-scale proxy infrastructure, ensuring high availability, performance, and security of egress traffic controls across cloud environments
  • Develops and maintains automation tooling to streamline network configuration, proxy onboarding workflows, certificate management, and policy enforcement
  • Troubleshoots complex network and proxy connectivity issues across cloud environments, applying structured diagnostic approaches to identify root cause and drive resolution
  • Collaborates with application teams, platform engineers, and architects to design secure and scalable network connectivity patterns that meet both technical and business requirements
  • Minimizes security vulnerabilities by following industry insights and evolving best practices, continuously improving network perimeter controls and validating their effectiveness
  • Adds to team culture of diversity, opportunity, inclusion, and respect
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.

Requirements

  • Formal training or certification in software engineering, security engineering, or network engineering concepts and 5+ years of applied experience in one or more of these disciplines
  • Strong Infrastructure-as-Code (IaC) experience using Terraform to provision and manage cloud networking and proxy infrastructure (e.g., reusable modules, remote state management, CI/CD integration, drift detection, and change controls)
  • Strong Python experience building automation for cloud infrastructure and networking workflows, including authoring AWS Lambda functions and using boto3 to automate AWS operations.
  • Hands-on AWS experience implementing and troubleshooting core services across networking, compute, security, and observability (e.g., AWS Lambda, EC2, VPC, Transit Gateway, PrivateLink/VPC endpoints, NLB, Route 53, CloudWatch, IAM). .
  • Knowledge of security best practices and relevant regulatory expectations, with experience evolving controls and implementing mechanisms to measure/validate control effectiveness over time
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Good communication skills, teamwork capabilities, and a self-learning attitude
  • Demonstrated experience using enterprise-authorized AI capabilities to accelerate security engineering workflows (e.g., threat modeling, vulnerability analysis synthesis, documentation), with strong validation habits and appropriate handling of sensitive data, * Experience with forward or reverse proxy technologies and architectures at enterprise scale (e.g., F5, Squid, Envoy, or equivalent)
  • Hands-on experience with TLS/SSL certificate management, PKI, mTLS, and truststore configuration in cloud-native environments
  • Strong understanding of proxy protocols (HTTP CONNECT, HTTPS, SOCKS5), DNS-based routing, and network egress control patterns
  • Experience effectively communicating with senior business leaders
  • AWS Certifications (e.g., Solutions Architect, Security Specialty, Advanced Networking Specialty)

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:12 min

Validating risky service requests safely via dry runs

Modood Alvi · World Congress 2025

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:14 min

Solving complex platform architecture challenges at an enterprise scale

Maria Apazoglou · Coffee With Developers

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

3:32 min

Creating basic Terraform resources and local state files

Thomas Hartenstein · LIVE

Videos

See all

Related articles

See all