Lead Security Engineer [Multiple Positions Available]

J.P. Morgan
J.P. Morgan

USD 221k-260k / year + Equity

Posted on Jul 27, 2026

DESCRIPTION:

Duties: Provide security solutions across a number of domains in the core platform. Develop and take ownership of security enablement services used in SDLC. Engage and collaborate with engineers across the business to understand use-cases and to define best practices for use of the security. Bring in the new and latest technologies and techniques for security and identity while driving their adoption where appropriate. Own and implement firm wide federal controls and regulations.

QUALIFICATIONS:

Minimum education and experience required: Bachelor's degree in Engineering (any), Computer Science, Computer Information Systems, or related field of study plus five (5) years of experience in the job offered or as Lead Security Engineer, Devops Engineer, Application Developer, Java Technical Lead, or related occupation. The employer will alternatively accept a Master's degree in Engineering (any), Computer Science, Computer Information Systems, or related field of study plus three (3) years of experience in the job offered or as Lead Security Engineer, Devops Engineer, Application Developer, Java Technical Lead, or related occupation.

Skills Required: This position requires three (3) years of experience with the following: designing secure VPCs, subnets, WAF rules, and Kubernetes clusters; developing and maintaining IaC for a Kubernetes cluster using tools such as Terraform, Terragrunt, or Helm; managing secrets, keys, and certificates within secure key management systems including policies for secret rotation and revocation; monitoring production cloud environments for security compliance; ensuring application and infrastructure compliance to financial security requirements such as PCI, DSS, SOC2, or 27001; handling security compliance reporting to upper management and auditors; leading threat modeling exercises using one of the following frameworks: STRIDE, OWASP, or MITRE ATT&CK; working with application developer teams to prioritize identified security gaps and implement suitable solutions. This position requires one (1) year of experience with the following: securing applications that use end-to-end encryption; implementing pipeline steps in a modern CI/CD tool such as GitHub, Jenkins, or harness; leading vulnerability management programs, implementing controls with CI/CD pipelines using tools such as Wiz, Snyk, or AWS Inspector; implementing security controls including SAST, DAST, and SCA scans within CI/CD pipelines; implementing systems that use OIDC and OAuth2 protocols; implementing mTLS communication between servers; producing hardened docker containers; developing applications that issue, hold, or verify credentials in either W3C or mDL (ISO 18013-5) formats; implementing systems that use decentralized identifiers; implementing systems that use either DIDComm or OID4VC verifiable credential protocols; and developing software using one or more of the following languages: Golang, Java, Python, or Bash.

Job Location: 237 Park Avenue, New York, NY 10017.

Full-Time. Salary: $221,000.00-$260,000.00 per year.


JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans


Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
Provide security solutions across a number of domains in the core platform.