> Markdown version of [/jobs/ext/3556163-sr-lead-security-engineer-threat-modelling](https://www.wearedevelopers.com/jobs/ext/3556163-sr-lead-security-engineer-threat-modelling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Lead Security Engineer -Threat modelling - **Company:** JPMorgan Chase & Co. - **Location:** Wilmington, DE, United States - **Experience:** Expert - **Salary:** $175,750.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Artificial Intelligence, Amazon Web Services, JIRA, Microsoft Azure, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Dynamic Program Analysis, Github, Identity and Access Management, Python (Programming Language), Machine Learning, Network Segmentation, Open Source Technology, Systems Development Life Cycle, Ansible, Security Software, Software Engineering, Systems Integration, Software Vulnerability Management, Scripting, Google Cloud, Delivery Pipeline, Mitre Att&ck, Infrastructure as Code (IaC), Git, Kubernetes, Bitbucket, Terraform, Software Version Control, Devsecops, Security Orchestration, Automation & Response, Jenkins, Golang, Programming Languages - **Published:** October 2, 2026 - **Apply:** https://dejobs.org/x/x/1AF035E0486F460E812161C429E27CD9/job/ ## About the Role * Obtain 5 plus years of applied training or certification on software engineering concepts * Proven track record in hands-on design, development, and deployment of enterprise-grade security solutions in public cloud environments (AWS, GCP, Azure), with direct experience integrating security controls into cloud-native architectures. * Demonstrated ability to perform comprehensive threat modeling and risk assessments for applications, systems, and architectures using frameworks such as STRIDE, DREAD, or PASTA. * Advanced proficiency in at least one modern programming language (e.g., Python, C/C#, Go, Java) and scripting for automation and security tooling, with a focus on building and deploying solutions. * Deep understanding of secure software development practices, including code review, static/dynamic analysis, and vulnerability remediation across multiple technology domains (cloud, AI/ML, mobile, etc.). * Experience implementing and managing CI/CD pipelines (e.g., Jenkins, GitHub Actions) with integrated security testing and controls. * Expertise in version control systems (e.g., Git, BitBucket) and agile work management tools (e.g., Jira), with a focus on collaborative, cross-functional engineering environments. * Ability to independently solve complex design and functionality challenges, proactively identifying and mitigating security risks with minimal oversight. * Experience working with vendors to assess the sufficiency of their security practices and controls to meet industry standards. * Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. * Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity. Preferred Qualifications, Capabilities, and Skills * Experience with modern security engineering practices, such as infrastructure as code (IaC), DevSecOps, and automated security testing. * Hands-on experience with cloud-native security tools (e.g., AWS Security Hub, Azure Sentinel, GCP Security Command Center) and container orchestration platforms (e.g., Kubernetes). * Active participation in the cybersecurity community, such as contributing to open-source projects, attending or speaking at conferences, or publishing research. * Experience implementing zero trust architectures, micro-segmentation, or advanced identity and access management solutions. * Strong understanding of privacy and data protection regulations (e.g., GDPR, CCPA) and their impact on security engineering. * Experience within Cyber Security is preferred with a good understanding of industry frameworks like MITRE ATT&CK, NIST, CIS, etc. * Relevant advanced certifications (e.g., CISSP, CCSP, AWS Certified Security Specialty, GIAC, OSCP) are highly desirable. * Excellent communication and presentation skills, with the ability to convey complex security concepts to technical and non-technical audiences. * Experience with security automation and orchestration using tools like Terraform, Ansible, or custom scripting. * Prior experience in highly regulated industries (finance, healthcare, etc.). * Willingness to learn and drive to excel. ## Description * Independently design, build, and implement advanced security solutions across cloud, hybrid, and on-prem environments, ensuring alignment with the latest industry best practices and regulatory requirements. * Actively write code, develop automation, and integrate security controls throughout the software development lifecycle, collaborating with engineering teams to embed security from ideation to deployment. * Facilitate security requirements clarification for multiple networks to enable multi-level security that satisfies organizational needs. * Drive adoption and direct implementation of emerging cybersecurity technologies (e.g., zero trust architectures, container security, AI/ML-driven security analytics) to enhance the organization's security posture. * Be responsible for triaging based on risk assessments of various threats and managing resources to cover the impact of disruptive events. * Utilize a deep understanding of the threat landscape and risk to build security into products and new features. * Mentor and provide technical guidance to junior engineers through code reviews and knowledge sharing, while remaining an individual contributor. * Collaborate cross-functionally with product, infrastructure, and business teams to ensure security requirements are understood, prioritized, and implemented effectively. * Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations. * Stay abreast of the latest cybersecurity trends, threat intelligence, and attack techniques, and translate insights into actionable improvements for the organization. * Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately. * Develop and maintain incident response playbooks, and lead post-incident reviews to drive continuous improvement from a technical perspective. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)