Job responsibilities
- Conduct and facilitate security configuration, deployment, design, and architecture reviews of the firm's products to ensure alignment with organizational policies and standards.
- Collaborate with product teams across various technology domains to review architecture and deployment patterns for compliance with security methodologies.
- Identify security weaknesses in the product's attack surface using an adversary-led approach, verify security controls, and recommend risk mitigation strategies.
- Identify thematic issues and coordinate remediation efforts with stakeholders.
- Provide excellent service to stakeholders during and after architecture reviews.
- Work collaboratively to build meaningful relationships and achieve common goals.
- Contribute to the development of strategic security solutions supporting JPMC businesses.
Required qualifications, capabilities, and skills
- Formal training or certification Cybersecurity concepts and 3+ years applied experience.
- Proficient in application, data, and infrastructure architecture disciplines.
- Demonstrates strong analytical skills with the ability to conduct root cause analysis.
- Hands on experience in offensive security, including penetration testing and red teaming.
- Proficiency in Python or other scripting languages.
- Expertise in security design/architecture reviews and code review/threat modeling at an enterprise level for a minimum of 2 years.
- Experience in areas such as Data Security, Infrastructure Security, Application Security, Cloud Security, Endpoint/Platform Security, Security Analytics, and security testing or compliance frameworks.
- Exhibits strategic thinking with a strong interest in business strategy and processes.
Preferred qualifications, capabilities, and skills
- Familiar with Microservices Architecture, Multi-Cloud environments (AWS, GCP, Azure), and OAuth.