As a Platform Engineer at JPMorgan Chase within the Platform SDLC team, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects – and depending on your strengths and interests, you'll have the opportunity to move between them.
While we’re looking for professional skills, culture is just as important to us. We understand that everyone's unique – and that diversity of thought, experience and background is what makes a good team great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference – on us as a company, and on our clients and business partners around the world.
Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies.
As a Lead Security Engineer at JP Morgan Chase within the Platform team, you are an integral part of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behaviour. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions.
Job responsibilities
Design and enforce security best practices in public cloud (AWS, Azure, GCP)Show strong experience defining and implementing infrastructure as Code (IaC), working with CI/CD pipelines, and associated automation tooling.Integrate and implement security testing into CI/CD pipelines (eg: SCA, SAST, DAST …)Perform code reviews, threat modelling, and vulnerability assessments on new and existing applicationsDesign and develop production deployments with the ability to think beyond routine or conventional approaches in order to deliver technology solutions for key stakeholders.Develop scripts and automation to streamline security operations, and implement complex business logic using Python or Go.Engage effectively with third-party vendors and communicate and collaborate with a broad range of internal teams.Minimize security vulnerabilities by following industry insights and government regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls.Critically evaluate security architecture and seek to simplify, optimize and automate security measures.Work with stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability.Analyse the current architecture, applications and processes and provide guidance on how to simplify and secure them.Develop, implement and use frameworks and tooling to perform automated detection of potential threats within our infrastructure.Ensure security controls are hardened through testing and as part of production deployments.Assess potential technology risks including information and cyber security control weaknesses as well as application security threats (e.g. OWASP)Build solid, professional relationships with external teams within the business and (wherever applicable) seek to share knowledge and understanding for the betterment of all those involved.Required qualifications, capabilities, and skills
Formal training or certification on Engineering and/or Cybersecurity concepts and 5+ years applied experience as a cloud engineer, deployment engineer, DevOps engineer, or equivalent role that involves deploying enterprise software to public cloud platforms.Demonstrated skills in planning, designing, and implementing enterprise level security solutions.Strong knowledge of a programming/scripting language for automation and integration tasks.Proficiency in all aspects of the Software Development Life Cycle.Strong analytical experience with problem solving mindset and the ability to solve complex challenges. Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security.Experience in applying Security Testing in CI/CD pipelinesExperience with Cloud Native Security (including Kubernetes, Docker)Preferred qualifications, capabilities, and skills
Cloud computing related certifications with a GCP focus are strongly preferred, such as Certified Solutions Architect, DevOps Engineer, or similar.Specific experience deploying commercial software at scale into an enterprise environment.Experience effectively communicating with senior business leaders.
#ICBCareers