2

Lead Security Engineer - Cloud Security | Azure

260312-South Florida Region Admin
Full-time
On-site
Columbus, Ohio, United States
Description

Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies.



As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity and Technology Controls organization, you are an integral part of team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions. 


This role is within the CTC Product Security team aligned to the Azure Cloud Enablement (ACE) program. As a Cloud Security Engineer, your primary responsibility will be to ensure that Public Cloud is adopted in a secure and compliant manner. You will play an important role in identifying and managing risk related issues and actions with respective technology. You will have an eye for detail and an ability to see the big picture across security issues.


Job responsibilities



  • Executes creative security solutions, design, development, and technical troubleshooting with the ability to think beyond routine or conventional approaches to build solutions and break down technical problems

  • Support the execution and enhancement of a long term information risk and control strategy designed to keep the information assets of the public cloud secure.

  • Deliver risk based assessments of secure technology controls relating to cloud services, cloud platforms and architectural components.

  • Support business technology teams to understand firm control requirements and implementations across a broad range of cloud architectures.

  • Perform security reviews of infrastructure-as-code for cloud platform development.

  • Contribute to documentation and agile processes in support of security programs.

  • Minimizes security vulnerabilities by following industry insights and governmental regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls

  • Interface with wider CTC teams ensuring platform integration with security operations, threat intelligence, IAM and network security.

  • Works with stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability

  • Conducts discovery, vulnerability, penetration testing, and threat scenarios on multiple organizational assets to identify and assess if vulnerabilities are present, and executes threat modeling for multiple applications including external applications interacting with the internal JPMorgan Chase network


Required qualifications, capabilities, and skills



  • Formal training or certification on security engineering concepts and 5+ years applied experience

  • Hands on experience of developing, engineering or architecting within a public cloud environment.

  • Skilled in planning, designing, and implementing enterprise level security solutions.

  • Expertise in Azure public cloud.  

  • Proficient in all aspects of the Software Development Life Cycle

  • Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security

  • Experience with threat modeling, discovery, vulnerability, and penetration testing

  • In-depth knowledge of the financial services industry and their IT systems


Preferred qualifications, capabilities, and skills



  • Knowledge of AWS and/or Google cloud are an added benefit.

  • Experience engineering with Terraform or Infrastructure-as-Code (IoC) would be an advantage.

  • Certifications in Azure, AWS and/or Google Cloud.