> Markdown version of [/jobs/ext/3532719-lead-security-engineer-attack-simulation-engineer](https://www.wearedevelopers.com/jobs/ext/3532719-lead-security-engineer-attack-simulation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - Attack Simulation Engineer - **Company:** JPMorgan Chase & Co. - **Location:** Columbus, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Foundry, CompTIA Security+, Cyber Security, Continuous Integration, Github, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Windows PowerShell, Ansible, Azure Machine Learning, Software Engineering, Systems Integration, TypeScript, Virtualization Technology, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Enterprise Software Applications, High Performance Computing, Mitre Att&ck, Gitlab-ci, Kubernetes, Information Technology, Machine Learning Operations, Terraform, Jenkins, Vulnerability Analysis, Golang - **Published:** October 2, 2026 - **Apply:** https://jpmc.fa.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1001/requisitions/preview/210792943 ## About the Role * Formal training or certification on software engineering concepts and 10+ years applied experience * Demonstrated experience leading the architecture, engineering, and operation of complex enterprise or mission-critical platforms * Strong experience across several of the following areas: cloud infrastructure and cloud security, network engineering and administration, systems administration and virtualization, storage and compute operations, software development and enterprise integrations, automation and infrastructure-as-code, cybersecurity platforms and security tooling, identity and access management, or platform resiliency and observability * Advanced programming or scripting skills in one or more languages such as Python, Go, Java, JavaScript/TypeScript, PowerShell, or Bash * In-depth experience with AWS, Azure, Google Cloud Platform, or comparable cloud platforms * Experience building automation and integrations across security, infrastructure, cloud, and enterprise technology services * Experience with secure software development lifecycle practices, threat modeling, vulnerability management, security testing, and platform resiliency * Demonstrated experience using enterprise-authorized AI and large language model capabilities in engineering or security workflows, including the ability to evaluate outputs for security, correctness, reliability, and compliance * Strong communication, stakeholder management, and technical leadership skills with the ability to influence decisions across organizational boundaries and engage effectively with senior technical and business stakeholders, * Advanced degree or relevant professional qualification in computer science, engineering, cybersecurity, or a related field * Industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, AWS Security Specialty, or equivalent * Experience supporting security operations, security testing, threat emulation, vulnerability research, attack analysis, or cyber-defense validation * Experience with Kubernetes, containers, immutable infrastructure, or cloud-native platform engineering * Experience with infrastructure-as-code and pipeline tooling such as Terraform, Ansible, Jenkins, GitHub Actions, or GitLab CI * Experience with GPU-enabled infrastructure, AI/ML platforms, model-serving systems, or high-performance computing environments * Familiarity with threat-informed defense principles and frameworks such as MITRE ATT&CK, and experience establishing service-level objectives, operational metrics, and disaster-recovery plans ## Description * Lead the strategy, architecture, engineering, and lifecycle management of platforms supporting cybersecurity operations across cloud and on-premises environments * Translate cybersecurity mission requirements into modern, secure, scalable, and reusable technology capabilities that serve the firm at enterprise scale * Design and operate complex hybrid environments spanning cloud infrastructure, networks, systems, virtualization, storage, identity, and security tooling * Engineer integrations between security platforms, enterprise services, infrastructure, and operational workflows to improve reliability and operational efficiency * Develop software, automation, infrastructure-as-code, and continuous integration and delivery capabilities that drive repeatability and reduce operational risk * Establish and uphold standards for secure configuration, access management, monitoring, logging, patching, backup, recovery, and technology lifecycle management * Define and continuously improve platform resiliency, availability, capacity, performance, and recovery objectives to meet mission and regulatory expectations * Lead technical troubleshooting, incident response, root-cause analysis, and remediation for platform and service issues * Establish measurable operational controls and evidence practices that support auditability and regulatory compliance * Leverage enterprise-authorized AI and large language model capabilities to accelerate engineering, security analysis, testing, documentation, and automation - while validating outputs and protecting sensitive information * Build strong partnerships across cybersecurity, infrastructure, cloud, software engineering, and enterprise technology teams to deliver new capabilities and drive continuous improvement ## Related Videos - [GitLab CI pipelines for a whole company](https://www.wearedevelopers.com/videos/143-gitlab-ci-pipelines-for-a-whole-company) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)