Jobs · Delaware

Sr Lead Security Engineer - Workforce

JPMorganChase · Wilmington, DE · 1 mo ago
On-siteFull-time

Job Responsibilities

  • Independently design, build, and implement advanced security solutions across cloud, hybrid, and on-prem environments, ensuring alignment with the latest industry best practices and regulatory requirements.
  • Actively write code, develop automation, and integrate security controls throughout the software development lifecycle, collaborating with engineering teams to embed security from ideation to deployment.
  • Facilitate security requirements clarification for multiple networks to enable multi-level security that satisfies organizational needs.
  • Drive adoption and direct implementation of emerging cybersecurity technologies (e.g., zero trust architectures, container security, AI/ML-driven security analytics) to enhance the organization's security posture.
  • Be responsible for triaging based on risk assessments of various threats and manage resources to cover the impact of disruptive events.
  • Utilize a deep understanding of the threat landscape and risk to build security into products and new features.
  • Mentor and provide technical guidance to junior engineers through code reviews and knowledge sharing, while remaining an individual contributor.
  • Collaborate cross-functionally with product, infrastructure, and business teams to ensure security requirements are understood, prioritized, and implemented effectively.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
  • Stay abreast of the latest cybersecurity trends, threat intelligence, and attack techniques, and translate insights into actionable improvements for the organization.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  • Develop and maintain incident response playbooks, and lead post-incident reviews to drive continuous improvement from a technical perspective.

Required Qualifications, Capabilities, And Skills

  • Obtain 5 plus years of applied training or certification on software engineering concepts.
  • Proven track record in hands-on design, development, and deployment of enterprise-grade security solutions in public cloud environments (AWS, GCP, Azure), with direct experience integrating security controls into cloud-native architectures.
  • Demonstrated ability to perform comprehensive threat modeling and risk assessments for applications, systems, and architectures using frameworks such as STRIDE, DREAD, or PASTA.
  • Advanced proficiency in at least one modern programming language (e.g., Python, C/C#, Go, Java) and scripting for automation and security tooling, with a focus on building and deploying solutions.
  • Deep understanding of secure software development practices, including code review, static/dynamic analysis, and vulnerability remediation across multiple technology domains (cloud, AI/ML, mobile, etc.).
  • Experience implementing and managing CI/CD pipelines (e.g., Jenkins, GitHub Actions) with integrated security testing and controls.
  • Expertise in version control systems (e.g., Git, BitBucket) and agile work management tools (e.g., Jira), with a focus on collaborative, cross-functional engineering environments.
  • Ability to independently solve complex design and functionality challenges, proactively identifying and mitigating security risks with minimal oversight.
  • Experience working with vendors to assess the sufficiency of their security practices and controls to meet industry standards.
  • Experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.

Preferred Qualifications, Capabilities, And Skills

  • Hands-on experience with cloud-native security tools (e.g., AWS Security Hub, Azure Sentinel, GCP Security Command Center) and container orchestration platforms (e.g., Kubernetes).
  • Active participation in the cybersecurity community, such as contributing to open-source projects, attending or speaking at conferences, or publishing research.
  • Experience implementing zero trust architectures, micro-segmentation, or advanced identity and access management solutions.
  • Strong understanding of privacy and data protection regulations (e.g., GDPR, CCPA) and their impact on security engineering.
  • Relevant advanced certifications (e.g., CISSP, CCSP, AWS Certified Security Specialty, GIAC, OSCP) are highly desirable.
  • Excellent communication and presentation skills, with the ability to convey complex security concepts to technical and non-technical audiences.
  • Experience with security automation and orchestration using tools like Terraform, Ansible, or custom scripting.
  • Prior experience in highly regulated industries (finance, healthcare, etc.).
  • Willingness to learn and drive to excel.

Similar jobs

Sr Security Engineer

MeijerMichigan, United States· 1 mo ago
Information Technologyapply on meijer.wd5.myworkdayjobs.com

Sr Lead Support Engineer

Northern TrustChicago, IL· 5 days ago
Information Technology$115k–$195k/yrapply on ntrs.wd1.myworkdayjobs.com

Sr Systems Security Engineer

Sierra Nevada CorporationLone Tree, CO· 1 mo ago
Information Technology$143k–$197k/yrapply on snc.wd1.myworkdayjobs.com