Your seniority as a security engineer puts you in the ranks of the top talent in your field. You will play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Security Engineer III - AWS Cloud at JPMorgan Chase within the Cybersecurity & Controls - Product Security team, you serve as a seasoned member of a team that works to deliver security solutions that satisfy functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. You will carry out critical security solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm’s business objectives. Within the CTC Product Security team, this role will be is aligned to the JPMC Public Cloud platform within AWS. The primary responsibility is to ensure that Pubic Cloud is adapted in a secure and compliant manner.
Job responsibilities
Support business technology teams to understand firm control requirements and implementations across a broad range of cloud architecturesApplies specialized tools to analyze, correlate, identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilitiesSupport the execution and enhancement of a long-term information risk and controls strategy designed to keep the information assets of the public cloud secureDeliver threat models and risk-based assessments of secure technology controls relating to cloud services, cloud platforms and architectural componentsPerform security reviews of infrastructure-as-code for cloud platform development Develop preventive and detective controls to enforce control requirements Interface with wider CTC teams ensuring platform integration with security operations, threat intelligence, infrastructure access management, and network securityAdds to team culture of diversity, equity, inclusion, and respectRequired qualifications, capabilities, and skills
Formal training or certification on security and software engineering concepts and 3+ years of applied experienceExperience in developing security engineering, and architecting solutions within public cloud technologiesExperience with threat modeling, discovery, vulnerability, and penetration testingProficiency in cloud security posture management (e.g., Wiz, Prisma Cloud, Crowd Strike Falcon Cloud Security, etc.)Experience engineering with infrastructure as code (e.g., Terraform, Cloud Formation, etc.) Solid understanding of agile methodologies such as DevOps, CI/CD, application resiliency, and securityAbility to convey complex security concepts to technical stakeholdersStrong analytical and evaluation skills to identify and address security challenges effectively with both technical and non-technical stakeholders at many levels within and outside of the firmCloud native experience (e.g., AWS, Azure, or Google cloud)Preferred qualifications, capabilities, and skillsCybersecurity certifications (i.e., Security, CEH, CCSP, GSEC, etc.)Cloud certifications would a plus (e.g., AWS, Azure, or GCP)