LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Sr. Lead Cybersecurity Architect - Product Security Lead

ExperiencedNo visa sponsorship
J.P. Morgan logo

at J.P. Morgan

Bulge Bracket Investment Banks

Posted 12 days ago

No clicks

**Senior Lead Cybersecurity Architect - Product Security Lead** Direct software security initiatives in Jersey City, NJ. Collaborate cross-functionally to mitigate risks throughout the product lifecycle. Key responsibilities include integrating security controls into AWS/GCP-based platforms, creating security design patterns, assisting engineering teams in secure development, and leading security assessments. Proficient in secure software development practices, threat modeling, and risk assessment. Proficiency in Java, Python, and C/C++, along with knowledge of industry regulations. Lead cross-functional teams, manage stakeholders, and drive security policies. Preferred candidates hold CISSP/CISM certifications and experience with DevSecOps. Track record of driving security initiatives.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
United States

Full Job Description

Location: Jersey City, NJ, United States

We are seeking an experienced Product Security Team Member to drive our product security initiatives. The ideal candidate is a hands-on expert in product security with a strong technical background and a deep understanding of secure development practices. You will collaborate with cross-functional teams to identify, assess, and mitigate security risks throughout the product lifecycle.

 

       Job responsibilities

  • Partnering with the Engineering & Architecture teams to integrate security controls into platforms (e.g. AWS, GCP, etc. based public cloud platforms) and frameworks
  • Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
  • Assisting and guiding engineering teams in the secure development of infrastructure services and products
  • Ensure security considerations are delivered in compliance with firmwide technology controls from the start and throughout the Software Development Lifecycle.
  • Developing extensible security solutions aligned to the product strategy in future developments.
  • Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
  • Work with architects and developers to design and implement secure code practices, conduct code reviews, and ensure security is embedded in the design.
  • Knowledge of emerging security threats, vulnerabilities, and trends relevant to our products.
  • Drive security education and awareness across the organization, ensuring all employees understand their role in maintaining product security.
  • Provide regular security updates to senior management and stakeholders, translating technical security issues into business impact.
  • Improve security policies, standards, and guidelines related to product security.
  • Stay up-to-date with the latest security technologies, trends, and best practices.

 

 

 

       Required qualifications, capabilities, and skills

 

  • Formal Training or certification with 5 + years of experience in a product security role with a track record of driving security initiatives.
  • Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
  • Experience with threat modeling, risk assessment, and vulnerability management.
  • Proficiency in programming languages (e.g., Java, Python, C/C++).
  • Familiarity with security frameworks (e.g., NIST Cybersecurity Framework) and industry regulations (e.g., GDPR, HIPAA).
  • Excellent leadership, communication, and interpersonal skills.
  • Security certifications such as CISSP, CISM, or relevant certifications are a plus.
  • Cloud Certifications such as AWS Solutions Architecture Associate/Professional, AWS Security Specialty
  • Experience with DevSecOps practices and tools is desirable.
  • Ability to lead and work effectively in a cross-functional team environment.
  • Strong problem-solving skills and the ability to think critically

    Preferred qualifications , capabilities and skills

  • Security certifications (e.g., CISSP, CISM, CCSP) and/or cloud certifications (e.g., AWS Security Specialty, Solutions Architect).
  • Experience with DevSecOps and continuous compliance controls (policy-as-code, guardrails, automated evidence).

 

#CTC

Drive significant business impact and tackle cybersecurity architecture challenges across software applications and platforms

Sr. Lead Cybersecurity Architect - Product Security Lead

Compensation

Not specified

City: Not specified

Country: United States

J.P. Morgan logo
Bulge Bracket Investment Banks

12 days ago

No clicks

at J.P. Morgan

ExperiencedNo visa sponsorship

**Senior Lead Cybersecurity Architect - Product Security Lead** Direct software security initiatives in Jersey City, NJ. Collaborate cross-functionally to mitigate risks throughout the product lifecycle. Key responsibilities include integrating security controls into AWS/GCP-based platforms, creating security design patterns, assisting engineering teams in secure development, and leading security assessments. Proficient in secure software development practices, threat modeling, and risk assessment. Proficiency in Java, Python, and C/C++, along with knowledge of industry regulations. Lead cross-functional teams, manage stakeholders, and drive security policies. Preferred candidates hold CISSP/CISM certifications and experience with DevSecOps. Track record of driving security initiatives.

Full Job Description

Location: Jersey City, NJ, United States

We are seeking an experienced Product Security Team Member to drive our product security initiatives. The ideal candidate is a hands-on expert in product security with a strong technical background and a deep understanding of secure development practices. You will collaborate with cross-functional teams to identify, assess, and mitigate security risks throughout the product lifecycle.

 

       Job responsibilities

  • Partnering with the Engineering & Architecture teams to integrate security controls into platforms (e.g. AWS, GCP, etc. based public cloud platforms) and frameworks
  • Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
  • Assisting and guiding engineering teams in the secure development of infrastructure services and products
  • Ensure security considerations are delivered in compliance with firmwide technology controls from the start and throughout the Software Development Lifecycle.
  • Developing extensible security solutions aligned to the product strategy in future developments.
  • Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
  • Work with architects and developers to design and implement secure code practices, conduct code reviews, and ensure security is embedded in the design.
  • Knowledge of emerging security threats, vulnerabilities, and trends relevant to our products.
  • Drive security education and awareness across the organization, ensuring all employees understand their role in maintaining product security.
  • Provide regular security updates to senior management and stakeholders, translating technical security issues into business impact.
  • Improve security policies, standards, and guidelines related to product security.
  • Stay up-to-date with the latest security technologies, trends, and best practices.

 

 

 

       Required qualifications, capabilities, and skills

 

  • Formal Training or certification with 5 + years of experience in a product security role with a track record of driving security initiatives.
  • Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
  • Experience with threat modeling, risk assessment, and vulnerability management.
  • Proficiency in programming languages (e.g., Java, Python, C/C++).
  • Familiarity with security frameworks (e.g., NIST Cybersecurity Framework) and industry regulations (e.g., GDPR, HIPAA).
  • Excellent leadership, communication, and interpersonal skills.
  • Security certifications such as CISSP, CISM, or relevant certifications are a plus.
  • Cloud Certifications such as AWS Solutions Architecture Associate/Professional, AWS Security Specialty
  • Experience with DevSecOps practices and tools is desirable.
  • Ability to lead and work effectively in a cross-functional team environment.
  • Strong problem-solving skills and the ability to think critically

    Preferred qualifications , capabilities and skills

  • Security certifications (e.g., CISSP, CISM, CCSP) and/or cloud certifications (e.g., AWS Security Specialty, Solutions Architect).
  • Experience with DevSecOps and continuous compliance controls (policy-as-code, guardrails, automated evidence).

 

#CTC

Drive significant business impact and tackle cybersecurity architecture challenges across software applications and platforms