> Markdown version of [/jobs/ext/2976916-sr-lead-cybersecurity-architect-product-security-lead](https://www.wearedevelopers.com/jobs/ext/2976916-sr-lead-cybersecurity-architect-product-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Lead Cybersecurity Architect - Product Security Lead - **Company:** JPMorgan Chase & Co. - **Location:** Jersey City, NJ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, C++ (Programming Language), Cloud Computing, Code Review, Cyber Security, Python (Programming Language), Open Web Application Security, Secure Coding, Software Engineering, Software Vulnerability Management, Policy as Code, Software Security, Devsecops, Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/requisitions/preview/210747026 ## About the Role We are seeking an experienced Product Security Team Member to drive our product security initiatives. The ideal candidate is a hands-on expert in product security with a strong technical background and a deep understanding of secure development practices. You will collaborate with cross-functional teams to identify, assess, and mitigate security risks throughout the product lifecycle., * Formal Training or certification with 5 + years of experience in a product security role with a track record of driving security initiatives. * Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten). * Experience with threat modeling, risk assessment, and vulnerability management. * Proficiency in programming languages (e.g., Java, Python, C/C++). * Familiarity with security frameworks (e.g., NIST Cybersecurity Framework) and industry regulations (e.g., GDPR, HIPAA). * Excellent leadership, communication, and interpersonal skills. * Security certifications such as CISSP, CISM, or relevant certifications are a plus. * Cloud Certifications such as AWS Solutions Architecture Associate/Professional, AWS Security Specialty * Experience with DevSecOps practices and tools is desirable. * Ability to lead and work effectively in a cross-functional team environment. * Strong problem-solving skills and the ability to think critically Preferred qualifications , capabilities and skills * Security certifications (e.g., CISSP, CISM, CCSP) and/or cloud certifications (e.g., AWS Security Specialty, Solutions Architect). * Experience with DevSecOps and continuous compliance controls (policy-as-code, guardrails, automated evidence). ## Description * Partnering with the Engineering & Architecture teams to integrate security controls into platforms (e.g. AWS, GCP, etc. based public cloud platforms) and frameworks * Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions * Assisting and guiding engineering teams in the secure development of infrastructure services and products * Ensure security considerations are delivered in compliance with firmwide technology controls from the start and throughout the Software Development Lifecycle. * Developing extensible security solutions aligned to the product strategy in future developments. * Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks. * Work with architects and developers to design and implement secure code practices, conduct code reviews, and ensure security is embedded in the design. * Knowledge of emerging security threats, vulnerabilities, and trends relevant to our products. * Drive security education and awareness across the organization, ensuring all employees understand their role in maintaining product security. * Provide regular security updates to senior management and stakeholders, translating technical security issues into business impact. * Improve security policies, standards, and guidelines related to product security. * Stay up-to-date with the latest security technologies, trends, and best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)