Security Engineer III-Python, Bash, Vulnerability Assessments

JPMorgan Chase & Co.
Columbus, OH, United States
29 days ago
Apply on jpmc.fa.oraclecloud.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Agile Methodology Artificial Intelligence Bash Shell Cloud Engineering Configuration Management Cyber Security Continuous Integration Data Centers Data Security Linux Python (Programming Language)
+14 more
Networking Basics Windows PowerShell Systems Development Life Cycle Cloud Services Software Engineering Software Vulnerability Management Data Processing Delivery Pipeline Infrastructure Automation Frameworks Api Design Firewall Services Module Software Version Control Qualys Vulnerability Analysis

Job description

As a Security Engineer III at JPMorganChase within the Cybersecurity & Technology Controls, Runtime Vulnerability Assessment team, you serve as a seasoned member of a team responsible for operating and advancing the firm’s global vulnerability scanning program. You will help ensure comprehensive, timely detection across every asset - from on-premises data centers to cloud environments - and contribute to the scanning backbone that supports enterprise-wide risk decisions. You will carry out critical technology solutions with rigorous, audit-ready methods across multiple technical areas in support of the firm’s business objectives., * Operate and maintain the firm’s global scanner fleet, including appliance deployment, health monitoring, scan profile tuning, and failure recovery across Asia-Pacific, Europe, Middle East & Africa, and North American data centers

  • Develop and maintain automation tooling for scanner lifecycle management, including provisioning frameworks, agent packaging for Linux and Windows platforms, and integration with internal deployment pipelines.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security analysis and vulnerability assessment documentation, validating outputs and ensuring sensitive data is handled appropriately.
  • Apply vulnerability scanning platforms to assess detection coverage, correlate findings, and identify gaps across managed and unmanaged asset populations
  • Collaborate with infrastructure and cloud engineering teams to ensure scan reachability across segmented networks, cloud workloads, and hybrid environments
  • Contribute to the development and maintenance of operational runbooks, continuity documentation, and coverage exercises to sustain scanning through infrastructure changes and major platform events
  • Analyze scan data and detection trends to surface actionable insights that inform enterprise risk prioritization and remediation workflows
  • Partner with cross-functional teams to support compliance scanning requirements and ensure alignment with regulatory and audit standards.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
  • Champion engineering best practices, including infrastructure-as-code, version control, and change management, within the vulnerability management program

Requirements

  • Formal training or certification on security engineering concepts and 3+ years applied experience
  • Experience designing and operating vulnerability scanning solutions at enterprise scale, including scanner infrastructure, agent management, and scan orchestration
  • Proficiency in scripting and automation using one or more languages such as Python, Bash, PowerShell, or configuration management frameworks.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted code/security recommendations before use, escalating when uncertain and following security and data handling requirements.
  • Solid understanding of the software development lifecycle, including infrastructure-as-code practices and change management controls
  • Working knowledge of network fundamentals, including segmentation, firewall rules, and connectivity as they relate to scan reachability
  • Familiarity with agile methodologies and continuous integration and delivery practices within a security engineering context
  • Ability to communicate technical findings and operational risks clearly to both technical and non-technical stakeholders

Preferred qualifications, capabilities, and skills

  • Hands-on experience administering Qualys or Tenable platforms, including appliance deployment, option profile configuration, and API-driven automation
  • Familiarity with agent-based scanning, binary packaging pipelines, and manifest version control for endpoint security tooling
  • Experience supporting Payment Card Industry Data Security Standard compliance scanning or equivalent regulatory scanning requirements
  • Exposure to cloud-native security tooling and vulnerability management across major cloud providers

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jpmc.fa.oraclecloud.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all