Lead Software Security Engineer

JPMorgan Chase & Co.
United States
2 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Software System Penetration Testing Cloud Computing Cloud Computing Security Data Systems DevOps Python (Programming Language) Network Security Systems Development Life Cycle
+15 more
Akamai Web Application Security Security Software Cloud-native Network Functions (CNF) Autoscaling Software Security AWS Lambda Amazon Virtual Private Cloud (VPC) Cloudflare Route53 Api Gateway Software Coding Terraform Devsecops Vulnerability Analysis

Job description

As a Lead Software Security Engineer at JPMorganChase, you are an integral part of an agile team that works to enhance, build, and deliver trusted technology products in a secure, stable, and scalable way. Drive significant business impact through your capabilities and contributions, and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of challenges that span multiple technologies and applications., * Facilitate security requirements clarification for multiple networks to enable multi-level security, satisfying organizational needs for both ingress and egress traffic. Work at code-level using java/ Python and drive the maturity of the Cybersecurity software development lifecycle with an advanced understanding of line of business technology drivers.

  • Perform deployment, administration, management, configuration, testing, documentation, operations, and integration tasks related to Cloud Network Security Platforms, championing a DevOps security model to ensure security is automated and elastic across all platforms.
  • Lead and develop new Cloud Security Implementations for both ingress and egress traffic. Design and develop strategies to provide end-to-end automation, architecture design, performance and monitoring, best practices, proof of concepts, product design, and transition to operations.
  • Ensure quality control of engineering deliverables and ensure firm policies are compliant with strict security standards. Drive decision-making by analyzing complex data systems, ensuring all engineering activities are in conformance with firm policies & objectives. Leverage DevOps tools to build, harden, maintain, and develop a comprehensive Cloud-based security orchestration platform for network security and infrastructure as code. Develop automated security and compliance capabilities in support of DevOps processes in a large-scale Cloud computing environment.
  • Collaborate with technologists, stakeholders, and senior business leaders to recommend business modifications during periods of vulnerability. Be responsible for triaging based on risk assessments of various threats and managing resources to cover the impact of disruptive events.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations. Collaborate with cross-functional teams, including IT, development, and operations, to ensure web application security.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately., Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Requirements

  • Formal training or certification on Security Engineering concepts and 5+ years of applied experience.
  • Advanced hands-on coding experience in java or Python/Go and Terraform. Expertise with AWS Infrastructure such as networking, EC2, Lambdas, server-less solutions, VPC, Route 53, autoscaling, Transit Gateway, API Gateway, Step Functions, secrets manager, and storage services.
  • Proficient in core concepts for Networking, Infrastructure as Code (IaaC), Public Cloud architecture, and Cloud Security.
  • Expertise in developing and designing complex cloud architectures, deploying scalable solutions, creating, and handling CI/CD pipelines, application resiliency, security design and implementation, and triaging issues in Agile Software Development Lifecycle methodology.
  • Extensive experience with threat modeling, discovery, vulnerability, and penetration testing. Ability to tackle design and functionality problems independently with little to no oversight.
  • Experience with WAF technologies such as AWS WAF, Akamai, Cloudflare, or similar.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Preferred qualifications, capabilities, and skills

  • API Gateway Development
  • Custom proxy development

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:58 min

Application performance and its direct business impact

Jérôme Vieilledent · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all