Lead Security Engineer [Multiple Positions Available]

JPMorgan Chase & Co.New York, NY
$221,000 - $260,000Onsite

About The Position

JPMorgan Chase & Co. is seeking Lead Security Engineers to provide security solutions across multiple domains within the core platform. This role involves developing and owning security enablement services used in the Software Development Life Cycle (SDLC). The Lead Security Engineer will collaborate with engineers across the business to understand use-cases, define best practices for security, and drive the adoption of new security and identity technologies and techniques. A key responsibility will be to own and implement firm-wide federal controls and regulations.

Requirements

  • Bachelor's degree in Engineering (any), Computer Science, Computer Information Systems, or related field of study plus five (5) years of experience in the job offered or as Lead Security Engineer, Devops Engineer, Application Developer, Java Technical Lead, or related occupation.
  • Alternatively, a Master's degree in Engineering (any), Computer Science, Computer Information Systems, or related field of study plus three (3) years of experience in the job offered or as Lead Security Engineer, Devops Engineer, Application Developer, Java Technical Lead, or related occupation.
  • Three (3) years of experience with designing secure VPCs, subnets, WAF rules, and Kubernetes clusters.
  • Three (3) years of experience developing and maintaining IaC for a Kubernetes cluster using tools such as Terraform, Terragrunt, or Helm.
  • Three (3) years of experience managing secrets, keys, and certificates within secure key management systems including policies for secret rotation and revocation.
  • Three (3) years of experience monitoring production cloud environments for security compliance.
  • Three (3) years of experience ensuring application and infrastructure compliance to financial security requirements such as PCI, DSS, SOC2, or 27001.
  • Three (3) years of experience handling security compliance reporting to upper management and auditors.
  • Three (3) years of experience leading threat modeling exercises using one of the following frameworks: STRIDE, OWASP, or MITRE ATT&CK.
  • Three (3) years of experience working with application developer teams to prioritize identified security gaps and implement suitable solutions.
  • One (1) year of experience securing applications that use end-to-end encryption.
  • One (1) year of experience implementing pipeline steps in a modern CI/CD tool such as GitHub, Jenkins, or harness.
  • One (1) year of experience leading vulnerability management programs, implementing controls with CI/CD pipelines using tools such as Wiz, Snyk, or AWS Inspector.
  • One (1) year of experience implementing security controls including SAST, DAST, and SCA scans within CI/CD pipelines.
  • One (1) year of experience implementing systems that use OIDC and OAuth2 protocols.
  • One (1) year of experience implementing mTLS communication between servers.
  • One (1) year of experience producing hardened docker containers.
  • One (1) year of experience developing applications that issue, hold, or verify credentials in either W3C or mDL (ISO 18013-5) formats.
  • One (1) year of experience implementing systems that use decentralized identifiers.
  • One (1) year of experience implementing systems that use either DIDComm or OID4VC verifiable credential protocols.
  • One (1) year of experience developing software using one or more of the following languages: Golang, Java, Python, or Bash.

Responsibilities

  • Provide security solutions across a number of domains in the core platform.
  • Develop and take ownership of security enablement services used in SDLC.
  • Engage and collaborate with engineers across the business to understand use-cases and to define best practices for use of the security.
  • Bring in the new and latest technologies and techniques for security and identity while driving their adoption where appropriate.
  • Own and implement firm wide federal controls and regulations.

Benefits

  • Comprehensive health care coverage
  • On-site health and wellness centers
  • Retirement savings plan
  • Backup childcare
  • Tuition reimbursement
  • Mental health support
  • Financial coaching
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service