Join JPMorganChase's Cybersecurity and Technology Controls organization, where the work you do directly protects one of the world's most complex and consequential technology ecosystems. Here, your engineering decisions matter — not just for the firm, but for the millions of clients and communities we serve every day. This is a place where deep technical ownership, intellectual curiosity, and a commitment to quality are celebrated and rewarded.
As a Lead Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls organization, you are an integral part of a team that delivers software solutions designed to prevent misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit-defensible methods across multiple technical areas and business functions. You will drive system design, engineering practices, development, and operations across services to deliver high-quality, resilient systems in private and public cloud environments.
Job responsibilities
- Design and evolve distributed systems with a focus on reliability, scalability, security, and operability across private and public cloud environments
- Contribute hands-on code in Java and Python, setting the standard for design, readability, testability, and maintainability
- Develop and maintain production-ready services using Java Spring frameworks, ensuring performance and resilience at scale
- Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
- Identify and remediate architectural risks, technical debt, and systemic quality gaps before they impact production
- Review design proposals and code changes for correctness, resilience, and long-term maintainability
- Own production behavior of systems end-to-end, including reliability, performance, incident response, and post-incident improvements
- Champion strong software development lifecycle practices including design reviews, testing strategy, release hygiene, and rollback planning
- Ensure systems continuously meet security, audit, and compliance expectations as a core part of day-to-day engineering
- Serve as a technical mentor and role model, elevating the craft of senior engineers across the team
- Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Demonstrated experience designing and operating cloud-native systems in production environments
- Strong proficiency in Java and/or Python with a proven track record of delivering high-quality, maintainable code
- Experience designing and working with relational and NoSQL databases (e.g., DynamoDB, MongoDB) in production systems.
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
- Solid understanding of software engineering best practices including automated testing, continuous integration and delivery, and release management
- Experience owning production systems including incident management, on-call responsibilities, and post-incident reviews
- Excellent written and verbal communication skills, with the ability to clearly articulate technical decisions to both technical and non-technical audiences.
Preferred qualifications, capabilities, and skills
- Experience working in regulated or highly controlled environments such as financial services, healthcare, or government
- Deep understanding of cloud and event-driven architectures and their security implications
- Familiarity with security compliance frameworks and audit-defensible engineering practices
- Strong grasp of operational excellence principles including monitoring, alerting, and observability strategies
- Experience with networking concepts in cloud environments, including virtual private clouds, security groups, and traffic management
#CTC