
at J.P. Morgan
Bulge Bracket Investment BanksPosted 12 days ago
No clicks
**Lead Security Engineer - Threat Modeling** As a Lead Security Engineer, you'll drive trusted architecture solutions for software applications at JPMorgan Chase, collaborating with cross-functional teams to implement technology solutions. Your key responsibilities include performing risk analyses and creating threat models. With 5+ years of experience and formal security engineering training, you'll use your coding proficiency and CISSP/CCSP certification to identify and mitigate risks. Proficient in AI-assisted tools and familiar with cloud technologies, you'll ensure software solutions align with the firm's business objectives and protect data and infrastructure.
- Compensation
- Not specified
- City
- Not specified
- Country
- United States
Currency: Not specified
Full Job Description
Location: Plano, TX, United States
Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies.
As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity and Technology Controls team, you design and deliver trusted cybersecurity architecture solutions for software applications and platforms. You collaborate with cross-functional teams to implement technology solutions and communicate risk and mitigation options using best practices in support of the firms business objectives. You play a key role in protecting the firms data and infrastructure
Job responsibilities
- Perform analysis and reporting against security risks to protect data, applications, and infrastructure using modern tools
- Conduct reviews on existing security controls with minimal oversight
- Identify gaps in network architecture and create documentation of threats and mitigations for small software applications
- Create secure and high-quality production code and maintain algorithms that run synchronously with appropriate systems
- Produce architecture and design artifacts for complex applications, ensuring design constraints are met by software code development
- Gather, analyze, synthesize, and develop visualizations and reporting from large, diverse data sets in service of continuous improvement of software applications and systems
- Proactively identify hidden problems and patterns in data and use these insights to drive improvements to coding hygiene and system architecture
- Contribute to software engineering communities of practice and events that explore new and emerging technologies
- Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
- Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Experience creating cybersecurity solutions based on existing security parameters
- Ability to evaluate current cybersecurity technologies to recommend ways to optimize architecture
- Hands-on practical experience in system design, application development, testing, and operational stability
- Proficient in coding in one or more languages
- Strong working knowledge of information and network security, IT risk management, and architectural concepts and patterns
- Hands-on practical experience performing threat modeling for software applications and systems
- CISSP or CCSP certification
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
- Demonstrated knowledge of software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
Preferred qualifications, capabilities, and skills
- Familiarity with modern front-end technologies
- Exposure to cloud technologies
- AWS or GCP
#CTC




