Lead Security Engineer - Attack Simulation Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+26 more
Job description
- Lead the strategy, architecture, engineering, and lifecycle management of platforms supporting cybersecurity operations across cloud and on-premises environments
- Translate cybersecurity mission requirements into modern, secure, scalable, and reusable technology capabilities that serve the firm at enterprise scale
- Design and operate complex hybrid environments spanning cloud infrastructure, networks, systems, virtualization, storage, identity, and security tooling
- Engineer integrations between security platforms, enterprise services, infrastructure, and operational workflows to improve reliability and operational efficiency
- Develop software, automation, infrastructure-as-code, and continuous integration and delivery capabilities that drive repeatability and reduce operational risk
- Establish and uphold standards for secure configuration, access management, monitoring, logging, patching, backup, recovery, and technology lifecycle management
- Define and continuously improve platform resiliency, availability, capacity, performance, and recovery objectives to meet mission and regulatory expectations
- Lead technical troubleshooting, incident response, root-cause analysis, and remediation for platform and service issues
- Establish measurable operational controls and evidence practices that support auditability and regulatory compliance
- Leverage enterprise-authorized AI and large language model capabilities to accelerate engineering, security analysis, testing, documentation, and automation - while validating outputs and protecting sensitive information
- Build strong partnerships across cybersecurity, infrastructure, cloud, software engineering, and enterprise technology teams to deliver new capabilities and drive continuous improvement
Requirements
- Formal training or certification on software engineering concepts and 10+ years applied experience
- Demonstrated experience leading the architecture, engineering, and operation of complex enterprise or mission-critical platforms
- Strong experience across several of the following areas: cloud infrastructure and cloud security, network engineering and administration, systems administration and virtualization, storage and compute operations, software development and enterprise integrations, automation and infrastructure-as-code, cybersecurity platforms and security tooling, identity and access management, or platform resiliency and observability
- Advanced programming or scripting skills in one or more languages such as Python, Go, Java, JavaScript/TypeScript, PowerShell, or Bash
- In-depth experience with AWS, Azure, Google Cloud Platform, or comparable cloud platforms
- Experience building automation and integrations across security, infrastructure, cloud, and enterprise technology services
- Experience with secure software development lifecycle practices, threat modeling, vulnerability management, security testing, and platform resiliency
- Demonstrated experience using enterprise-authorized AI and large language model capabilities in engineering or security workflows, including the ability to evaluate outputs for security, correctness, reliability, and compliance
- Strong communication, stakeholder management, and technical leadership skills with the ability to influence decisions across organizational boundaries and engage effectively with senior technical and business stakeholders, * Advanced degree or relevant professional qualification in computer science, engineering, cybersecurity, or a related field
- Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, AWS Security Specialty, or equivalent
- Experience supporting security operations, security testing, threat emulation, vulnerability research, attack analysis, or cyber-defense validation
- Experience with Kubernetes, containers, immutable infrastructure, or cloud-native platform engineering
- Experience with infrastructure-as-code and pipeline tooling such as Terraform, Ansible, Jenkins, GitHub Actions, or GitLab CI
- Experience with GPU-enabled infrastructure, AI/ML platforms, model-serving systems, or high-performance computing environments
- Familiarity with threat-informed defense principles and frameworks such as MITRE ATT&CK, and experience establishing service-level objectives, operational metrics, and disaster-recovery plans
Benefits & conditions
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
About the company
Join one of the world’s most influential financial institutions and help build the technology that protects it. At JPMorganChase, our cybersecurity engineering teams operate at a scale few organizations can match - and we’re looking for bold, technically deep engineers who want to make a real impact.
As a Lead Security Engineer at JPMorganChase within the Cyber Technology & Controls organization, you will lead the design, engineering, and lifecycle management of platforms that power cybersecurity operations across the firm. You will help build and operate secure, resilient, and scalable capabilities used for security testing, adversarial simulation, vulnerability research, attack analysis, and validation of cyber defenses - spanning cloud and on-premises environments. Your work will directly shape the technical strategy and engineering standards that protect one of the world’s largest financial institutions, and you will collaborate across cybersecurity, infrastructure, cloud, and enterprise technology teams to continuously deliver and improve mission-critical services., JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Upskilling And Reskilling is Important For Developers
Best Paying Jobs in Technology