Lead Cybersecurity Architect

JPMorgan Chase & Co.
Chicago, IL, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Training Data Application Programming Interfaces (APIs) Artificial Intelligence Software Applications Cyber Security Continuous Integration Information Leak Prevention Identity and Access Management Key Management Machine Learning Network Segmentation Role-Based Access Control
+11 more
Azure Machine Learning Software Engineering Data Logging Data Processing Data Classification Large Language Models Multi-Agent Systems Software Security Information Technology Machine Learning Operations Programming Languages

Job description

As a Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity Technology & Controls, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications on modern cloud-based technologies. As a core technical contributor, you are responsible for carrying out critical cybersecurity architecture solutions by identifying, creating, and communicating risk, mitigation options, and solutions across multiple technical areas within various business functions in support of project goals., * Engages technical teams and business stakeholders to discuss and propose technical approaches to meet current and future cybersecurity needs

  • Defines the technical target state of their cybersecurity product and drives achievement of the strategy
  • Develop software, use firmwide AI/ML tools to enhance, automate, improve secure design and threat assessment processes.
  • Own and drive SDRs for AI/ML platforms, agentic systems, and MCP integrations; document decisions, required controls, and risk acceptances
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Define and govern secure reference architectures for agentic systems and MCP-enabled workflows, including isolation, segmentation, encryption, and identity management
  • Define security requirements for authentication, authorization, data classification, and encrypted communications for MCP servers and agentic workflows
  • Conduct and maintain threat models for agentic systems, MCP servers, and LLM Suite integrations, identifying and mitigating risks such as prompt injection, data leakage, and supply chain threats

Requirements

  • Obtain 5+ years of cybersecurity architectural knowledge with hands-on practical experience delivering enterprise-level solutions and controls
  • Advanced in one or more programming languages
  • Hands on experience in coding and use AI / ML, agents to improve security assessments. Willing to work on POC on new innovative ideas
  • Demonstrate ownership of Security Design Reviews (SDRs), security requirements, and architecture governance for large-scale platforms.
  • Proven expertise in threat modeling and mitigating AI/ML risks such as prompt injection, data poisoning, model extraction/inversion, training data leakage, and third-party/supply-chain exposure.
  • Strong hands-on technical depth across cloud and application security: IAM/least privilege, encryption & key management, secrets, network segmentation, secure APIs, logging/monitoring, and secure SDLC/CI/CD.
  • Experience securing agentic AI systems and tool integrations (including MCP-based tool/data connectivity or similar protocols), with the ability to set guardrails for tool access, data handling, and runtime controls.
  • Proficiency in all aspects of the Software Development Life Cycle
  • Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
  • In-depth knowledge of the financial services industry along with their IT systems and experience communicating with senior leaders
  • Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jpmc.fa.oraclecloud.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

2:20 min

Architecting language translation with focused training data

Jaroslaw Kutylowski Jaroslaw Kutylowski +1 · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

Videos

See all

Related articles

See all