Expoint - all jobs in one place

המקום בו המומחים והחברות הטובות ביותר נפגשים

Limitless High-tech career opportunities - Expoint

JPMorgan Lead Security Engineer 
United Kingdom, England, London 
252763773

Yesterday

As a Lead Security Engineer at JP Morgan Chaseyou are an integral part of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behaviour. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions.


Job responsibilities

  • Design and enforce security best practices in public cloud (AWS, Azure, GCP)
  • Show strong experience defining and implementing infrastructure as Code (IaC), working with CI/CD pipelines, and associated automation tooling.
  • Integrate and implement security testing into CI/CD pipelines (eg: SCA, SAST, DAST …)
  • Perform code reviews, threat modelling, and vulnerability assessments on new and existing applications
  • Design and develop production deployments with the ability to think beyond routine or conventional approaches in order to deliver technology solutions for key stakeholders.
  • Develop scripts and automation to streamline security operations, and implement complex business logic using Python or Go.
  • Engage effectively with third-party vendors and communicate and collaborate with a broad range of internal teams.
  • Minimize security vulnerabilities by following industry insights and government regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls.
  • Critically evaluate security architecture and seek to simplify, optimize and automate security measures.
  • Work with stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability.
  • Analyse the current architecture, applications and processes and provide guidance on how to simplify and secure them.
  • Develop, implement and use frameworks and tooling to perform automated detection of potential threats within our infrastructure.
  • Ensure security controls are hardened through testing and as part of production deployments.
  • Assess potential technology risks including information and cyber security control weaknesses as well as application security threats (e.g. OWASP)
  • Build solid, professional relationships with external teams within the business and (wherever applicable) seek to share knowledge and understanding for the betterment of all those involved.

Required qualifications, capabilities, and skills

  • Formal training or certification on Engineering and/or Cybersecurity concepts and 5+ years applied experience as a cloud engineer, deployment engineer, DevOps engineer, or equivalent role that involves deploying enterprise software to public cloud platforms.
  • Demonstrated skills in planning, designing, and implementing enterprise level security solutions.
  • Strong knowledge of a programming/scripting language for automation and integration tasks.
  • Proficiency in all aspects of the Software Development Life Cycle.
  • Strong analytical experience with problem solving mindset and the ability to solve complex challenges.
  • Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security.
  • Experience in applying Security Testing in CI/CD pipelines
  • Experience with Cloud Native Security (including Kubernetes, Docker)

Preferred qualifications, capabilities, and skills

  • Cloud computing related certifications with a GCP focus are strongly preferred, such as Certified Solutions Architect, DevOps Engineer, or similar.
  • Specific experience deploying commercial software at scale into an enterprise environment.
  • Experience effectively communicating with senior business leaders.