As a Security Engineer III at JPMorgan Chase within the Cybersecurity & Tech Controls team, youserve as a seasoned member of a team aligned to the Cloud Service Enablement function. As a Cloud Security Engineer, your primary responsibility will be to ensure that Public Cloud is adopted in a secure and compliant manner. You will play an important role in defining the process to securely enable public cloud services (across AWS, Azure and GCP) within the firm. You will have an eye for detail and an ability to grasp how various products fit into the Governance, Risks and Compliance ecosystem.
Job responsibilities
- Drive integration between various security products and tools to streamline the service enablement process for public cloud within JPMC.
- Build strong relationships with product and engineering teams to influence and drive their roadmap.
- Conduct user acceptance testing for security products and manage the SSE team's intake queue and backlog.
- Develop control procedures and processes to enhance the firm's public cloud security posture.
- Propose solutions to reduce risk, eliminate toil, and improve security processes, while producing reports and metrics for senior management and audit.
- Organize and run working groups and workshops with multiple product teams to foster collaboration between stakeholders.
- Conduct demos, talks, and training sessions for other product security leads and product lines on security processes, and perform security reviews of infrastructure-as-code for cloud platform development
Required qualifications, capabilities, and skills
- Formal training or certification on Security engineering concepts and 3+ years applied experience
- Hands-on practical experience in developing, engineering or architecting within a public cloud environment .
- Ability to prioritize and work under stringent timelines.
- Experience engineering with Terraform or infrastructure-as-code
- Self-disciplined, self-managed, self-motivated and strong sense of ownership, urgency, and drive.
- Proficient verbal and written communication skills, including the ability to effectively participate in discussions and meetings with internal management, peer groups, regulators and senior stakeholders
Preferred qualifications, capabilities, and skills
- AWS, Azure or Google Cloud certifications
- Understanding of DevOps or CI/CD concepts would be an advantage.