Lead Security Engineer - Attack Simulation Engineer

JPMorgan Chase & Co.
Columbus, OH, United States
1 day ago
Apply on jpmc.fa.oraclecloud.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Foundry CompTIA Security+ Cyber Security Continuous Integration
+26 more
Github Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language) Windows PowerShell Ansible Azure Machine Learning Software Engineering Systems Integration TypeScript Virtualization Technology Software Vulnerability Management Data Logging Scripting Google Cloud Enterprise Software Applications High Performance Computing Mitre Att&ck Gitlab-ci Kubernetes Information Technology Machine Learning Operations Terraform Jenkins Vulnerability Analysis Golang

Job description

  • Lead the strategy, architecture, engineering, and lifecycle management of platforms supporting cybersecurity operations across cloud and on-premises environments
  • Translate cybersecurity mission requirements into modern, secure, scalable, and reusable technology capabilities that serve the firm at enterprise scale
  • Design and operate complex hybrid environments spanning cloud infrastructure, networks, systems, virtualization, storage, identity, and security tooling
  • Engineer integrations between security platforms, enterprise services, infrastructure, and operational workflows to improve reliability and operational efficiency
  • Develop software, automation, infrastructure-as-code, and continuous integration and delivery capabilities that drive repeatability and reduce operational risk
  • Establish and uphold standards for secure configuration, access management, monitoring, logging, patching, backup, recovery, and technology lifecycle management
  • Define and continuously improve platform resiliency, availability, capacity, performance, and recovery objectives to meet mission and regulatory expectations
  • Lead technical troubleshooting, incident response, root-cause analysis, and remediation for platform and service issues
  • Establish measurable operational controls and evidence practices that support auditability and regulatory compliance
  • Leverage enterprise-authorized AI and large language model capabilities to accelerate engineering, security analysis, testing, documentation, and automation - while validating outputs and protecting sensitive information
  • Build strong partnerships across cybersecurity, infrastructure, cloud, software engineering, and enterprise technology teams to deliver new capabilities and drive continuous improvement

Requirements

  • Formal training or certification on software engineering concepts and 10+ years applied experience
  • Demonstrated experience leading the architecture, engineering, and operation of complex enterprise or mission-critical platforms
  • Strong experience across several of the following areas: cloud infrastructure and cloud security, network engineering and administration, systems administration and virtualization, storage and compute operations, software development and enterprise integrations, automation and infrastructure-as-code, cybersecurity platforms and security tooling, identity and access management, or platform resiliency and observability
  • Advanced programming or scripting skills in one or more languages such as Python, Go, Java, JavaScript/TypeScript, PowerShell, or Bash
  • In-depth experience with AWS, Azure, Google Cloud Platform, or comparable cloud platforms
  • Experience building automation and integrations across security, infrastructure, cloud, and enterprise technology services
  • Experience with secure software development lifecycle practices, threat modeling, vulnerability management, security testing, and platform resiliency
  • Demonstrated experience using enterprise-authorized AI and large language model capabilities in engineering or security workflows, including the ability to evaluate outputs for security, correctness, reliability, and compliance
  • Strong communication, stakeholder management, and technical leadership skills with the ability to influence decisions across organizational boundaries and engage effectively with senior technical and business stakeholders, * Advanced degree or relevant professional qualification in computer science, engineering, cybersecurity, or a related field
  • Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, AWS Security Specialty, or equivalent
  • Experience supporting security operations, security testing, threat emulation, vulnerability research, attack analysis, or cyber-defense validation
  • Experience with Kubernetes, containers, immutable infrastructure, or cloud-native platform engineering
  • Experience with infrastructure-as-code and pipeline tooling such as Terraform, Ansible, Jenkins, GitHub Actions, or GitLab CI
  • Experience with GPU-enabled infrastructure, AI/ML platforms, model-serving systems, or high-performance computing environments
  • Familiarity with threat-informed defense principles and frameworks such as MITRE ATT&CK, and experience establishing service-level objectives, operational metrics, and disaster-recovery plans

Benefits & conditions

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

About the company

Join one of the world’s most influential financial institutions and help build the technology that protects it. At JPMorganChase, our cybersecurity engineering teams operate at a scale few organizations can match - and we’re looking for bold, technically deep engineers who want to make a real impact.

As a Lead Security Engineer at JPMorganChase within the Cyber Technology & Controls organization, you will lead the design, engineering, and lifecycle management of platforms that power cybersecurity operations across the firm. You will help build and operate secure, resilient, and scalable capabilities used for security testing, adversarial simulation, vulnerability research, attack analysis, and validation of cyber defenses - spanning cloud and on-premises environments. Your work will directly shape the technical strategy and engineering standards that protect one of the world’s largest financial institutions, and you will collaborate across cybersecurity, infrastructure, cloud, and enterprise technology teams to continuously deliver and improve mission-critical services., JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jpmc.fa.oraclecloud.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:31 min

Implementing initial GitOps architecture with Jenkins and Argo CD

Lian Li · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

Videos

See all

Related articles

See all