Job responsibilities
- Engages technical teams and business stakeholders to discuss and propose technical approaches to meet current and future cybersecurity needs
- Defines the technical target state of their cybersecurity product and drives achievement of the AI/ML strategy
- Leads evaluation sessions with external vendors, startups, and internal teams to drive continuous improvement and assess cybersecurity design and technical credentials for use in existing systems and architecture
- Provide thought leadership for securing on premise and cloud based AI/ML solution architecture
- Design comprehensive security architectures for cloud infrastructure projects
- Design secure networks and systems based on industry standards and best practices
- Identify and address security vulnerabilities, security risks, and other compliance issues
- Exhibit a solid understanding of core security architecture, data systems and data environments, and processes that are necessary for the implementation AI/ML models
- Create and communicate threat models
- Partner with product managers to create key objectives and roadmaps
- Drive innovation and ensure that JPMC maximizes the business benefits while minimizing security risk across your product
Required qualifications, capabilities, and skills
- Formal training or certification on software engineering/architecture concepts and 5+ years applied experience
- Advanced Technical knowledge in architecting, designing, and Integrating security solutions in a large-scale enterprise of highly distributed applications
- Experience developing and understanding information security architecture, mitigation of threats, and compensating controls.
- Hands-on practical experience delivering enterprise architecture Threat Models
- Strong knowledge of Artificial Intelligence and Machine Learning Security concepts, threats, and vulnerabilities including Generative Large Language Models
- Strong understanding of cloud computing concepts and services such as AWS, Azure, GCP, etc.
- Advanced in one or more programming languages – Java, Python, C/C++, etc..
- Advanced understanding of agile methodologies such as continuous integration and delivery, application resiliency, and security
- Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence and machine learning)
- Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture
- Experience effectively communicating with senior business leaders
Preferred qualifications, capabilities, and skills:
- Knowledge of networking protocols and techniques, such as TCP/IP, routing, DNS, DHCP, etc.
- Knowledge of IAM concepts, including but not limited to provisioning, PAM, RBAC, ABAC, SCIM, LDAP, and governance and authorization standards
- Experience with federated identity platforms/products
- Experience with API security and public cloud APIs and integration
- Deep familiarity with frameworks such as NIST 800-53, OWASP, CVSS, the MITRE ATT&CK frame, MITRE Atlas, PCI, and Gramm-Leach-Bliley Act (GLBA).
- Experience using cloud infrastructure as code (IaC) using frameworks like Terraform
- Experience with microservices designs and implementations including docker, Kubernetes, etc…