**Lead Cybersecurity Architect** at JPMorgan Chase shapes secure technology solutions, collaborating with top professionals. Design and deliver high-quality cybersecurity solutions, ensuring software applications and platform products are secure by design, resilient, and aligned with regulatory expectations. Key responsibilities include performing secure design reviews and threat modeling, leveraging AI capabilities, and driving reuse-first adoption. Lead cross-functional teams and stakeholders, demonstrate deep product understanding, and drive impactful outcomes for the firm and its clients. Bring your expert knowledge in cybersecurity architecture, applications, technical processes, and 5+ years of applied experience to thrive in this role. Must-haves include advanced knowledge of security engineering concepts, strong DevSecOps methodologies, experience with cloud security posture management, and hands-on software development experience.
Full Job Description
Location: Bengaluru, Karnataka, India
Join a team where your expertise in cybersecurity architecture shapes the future of secure technology solutions. Grow your career by collaborating with top engineering, product, and business professionals.
As a Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity and Technology Controls team, you will design and deliver high-quality cybersecurity solutions for software applications and platform products. You will partner with engineering, product, and business stakeholders to ensure solutions are secure by design, resilient, and aligned to regulatory and audit expectations. You will play a key role in supporting Chase UK and JPMorgan Personal Investing, contributing to a collaborative and innovative team culture. You will help drive impactful outcomes for the firm and its clients.
Job responsibilities
Perform secure design reviews and threat modeling with application teams to ensure products are secure by design.Demonstrate deep understanding of product strategy, roadmap, and key investment programs.Identify and learn unfamiliar technology components, capabilities, and business concepts, applying critical thinking to uncover hidden issues.Leverages enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity architecture analysis and decisioning (e.g., risk identification and documentation), validating outputs and handling data according to sensitivity and security requirements.Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing and remediation quality with traceability/auditability and resiliency expectations.Share best practices and serve as the point of escalation and subject matter expert for Cybersecurity and Technology Controls.Collaborate with product, technology, and business colleagues for audit, regulatory, risk, and project initiatives.Work with Third Party Oversight teams to manage technology risk for vendors, focusing on cloud computing and emerging technologies.Required qualifications, capabilities and skills
Formal training or certification on security engineering concepts and 5+ years applied experienceAdvanced knowledge of cybersecurity architecture, applications, and technical processes with expertise in one or more technical disciplinesAbility to design and implement effective cybersecurity and technology controlsStrong knowledge of security best practices and DevSecOps methodologiesExperience with cloud security posture management and vulnerability managementDemonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.Understanding of network security, network design, segmentation, firewalls, and cloud networking patternsExperience implementing and reviewing authentication and authorization controls and best practicesHands-on experience in software development with strong understanding of SDLC and secure SDLC practicesKnowledge of modern application architectures including microservices, APIs, and event-driven patternsPreferred qualifications, capabilities and skills
Experience with identity federation, least privilege, RBAC/ABAC conceptsExperience with cloud security technologies and emerging security trendsAbility to influence and partner across product supply chainsExperience working with Third Party Oversight teams and managing vendor technology risk Shape and lead global technology risk and controls, driving innovation and scalable outcomes across the enterprise.