Lead Security Engineer - Threat modeling
Bengaluru, Karnataka, India
We have an exciting and rewarding opportunity for you to advance your security engineering career. Join a team where your expertise shapes the future of cybersecurity.
As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity and Technology Controls team, you design and deliver trusted cybersecurity architecture solutions for software applications and platforms. You collaborate with cross-functional teams to implement technology solutions and communicate risk and mitigation options using best practices in support of the firm’s business objectives. You play a key role in protecting the firm’s data and infrastructure.
Job responsibilities
- Perform analysis and reporting against security risks to protect data, applications, and infrastructure using modern tools
- Conduct reviews on existing security controls with minimal oversight
- Identify gaps in network architecture and create documentation of threats and mitigations for small software applications
- Create secure and high-quality production code and maintain algorithms that run synchronously with appropriate systems
- Produce architecture and design artifacts for complex applications, ensuring design constraints are met by software code development
- Gather, analyze, synthesize, and develop visualizations and reporting from large, diverse data sets in service of continuous improvement of software applications and systems
- Proactively identify hidden problems and patterns in data and use these insights to drive improvements to coding hygiene and system architecture
- Contribute to software engineering communities of practice and events that explore new and emerging technologies
- Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
- Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations
Required qualifications, capabilities and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Experience creating cybersecurity solutions based on existing security parameters
- Ability to evaluate current cybersecurity technologies to recommend ways to optimize architecture
- Hands-on practical experience in system design, application development, testing, and operational stability
- Proficient in coding in one or more languages
- Strong working knowledge of information and network security, IT risk management, and architectural concepts and patterns
- Hands-on practical experience performing threat modeling for software applications and systems
- CISSP or CCSP certification
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
- Demonstrated knowledge of software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
Preferred qualifications, capabilities and skills
- Familiarity with modern front-end technologies
- Exposure to cloud technologies
- AWS or GCP
Deliver secure, high-quality cybersecurity solutions as a Lead Security Engineer in a leading financial institution