Hiring Event - Security Architecture & Engineering - Sep 24-25th 2026

JPMorgan Chase & Co.
Jersey City, NJ, United States
24 days ago
Apply on jpmc.fa.oraclecloud.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Amazon S3 Applications Architecture Microsoft Azure C++ (Programming Language) Cloud Computing Cloud Computing Security Cloud Engineering
+35 more
Cyber Security Databases Continuous Integration Data Security DevOps Identity and Access Management Python (Programming Language) Machine Learning Node.Js OAuth Systems Development Life Cycle RabbitMQ Role-Based Access Control Service-Oriented Architecture Software Engineering SQL Databases Software Vulnerability Management Web Applications Web Services SSL Certificate Management Google Cloud Spring Cloud Istio Software Security Mitre Att&ck Infrastructure as Code (IaC) Kubernetes Production Code Apache Kafka Video Streaming CIS Benchmarks Api Gateway Terraform Golang Microservices

Job description

  • Design, develop, and troubleshoot creative security solutions, producing secure, high-quality production code and reviewing code. Architect complex, scalable, and reusable cybersecurity frameworks for cloud and on-premises environments, driving standardization and consistency across the organization
  • Continuously evolve security protocols by assessing current controls, identifying gaps, and implementing improvements aligned with industry standards and governmental regulations
  • Implement and manage IAM protocols (RBAC, OAuth2.0, SCIM, WebAuthN, OPA, PBAC) and apply advanced security principles including encryption, data security, and risk management. Lead cybersecurity strategy for AI-enabled products and drive adoption of new technical methods, including leading proof-of-concept initiatives for emerging technologies
  • Translate complex technical issues to leadership, enabling strategic decisions about target state architecture
  • Serve as a subject matter expert, providing technical guidance to stakeholders, business leaders, technical teams, contractors, and vendors
  • Mentor engineering teams, advocate for firmwide SDLC best practices, and champion a culture of diversity, inclusion, and continuous learning.
  • Leverages enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity architecture analysis and decisioning (e.g., risk identification and documentation), validating outputs and handling data according to sensitivity and security requirements.
  • Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing and remediation quality with traceability/auditability and resiliency expectations.

Requirements

  • Formal training or certification in software engineering/architecture with applied experience in system design, application development, and operational stability .Advanced proficiency in one or more languages: Java, Python, C/C++, Node, or Golang
  • Experience planning, designing, and implementing enterprise-level security solutions with fluent understanding of SDLC and agile methodologies (CI/CD, Application Resiliency)
  • Practical cybersecurity experience in one or more disciplines: AI/ML, Application Development, Cloud, Infrastructure, Mobile, Offensive Security, or Vulnerability Management
  • Extensive cloud-native experience (AWS, Azure, GCP) including Kubernetes, Lambda, ECS, S3, Aurora, API Gateway, and DevOps practices
  • Experience in security assessment, threat modeling, and secure design for cloud-native applications, including A2A security, certificate management, API security, and service mesh architectures
  • Expertise in IAM principles (RBAC, OAuth2.0, SCIM, WebAuthN, OPA, PBAC) with deep understanding of encryption, data security, and risk management
  • Experience with CIS Security baselines, configuration drift remediation, and hands-on security architecture
  • Proven experience building scalable microservices, enterprise-grade APIs, and high-availability database architectures (SQL, data modeling), with knowledge of streaming technologies (Kafka, RabbitMQ) .
  • Strong cross-functional influence, technical thought leadership, and ability to communicate complex concepts to senior executives.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Preferred Qualifications, Capabilities, and Skills

  • Experience with threat modeling methodologies such as STRIDE, MITRE ATT&CK, VAST, DREAD, IriusRisk, and PASTA
  • Experience with web, API, and microservices technologies including Web Applications, Web Services, and Service Oriented Architectures. Experience with Infrastructure as Code (IaC) utilizing tools such as Terraform
  • Experience with cloud security platforms such as AWS, Azure, and Google Cloud. Familiarity with security frameworks such as NIST, ISO 27001, and SOC 2
  • Proficiency in MCP and its application on how it can be used to secure agentic systems
  • Experience with Vendor Product Management, Services, and Tooling
  • Experience leading cross-functional security projects with strong communication and stakeholder management skills
  • Strategic thinker with a proactive approach to problem-solving, strong organizational and project management skills, and a commitment to continuous learning and professional development
  • Professional certifications such as CISSP, CISM, or CCSP . AWS certifications including Practitioner, Cloud Engineer, Software Development Engineer, Cloud Security Engineer, Cloud Security Architect, and Application Architect. Offensive Security certifications including OSCP, OSWP, OSCE, OSEE, OSWE, OSEP, and CEH

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

As a Cybersecurity Architect/Engineer , you play a pivotal role in shaping secure solutions for software applications and platform products, driving meaningful business impact through deep technical expertise and innovative problem-solving. You will leverage advanced architecture capabilities to identify, communicate, and mitigate risk while collaborating across the organization to drive best-in-class outcomes , and lead the creation of AI-enabled cybersecurity solutions and reusable frameworks at the forefront of industry best practices., JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jpmc.fa.oraclecloud.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all