LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Sr Lead Security Engineer

ExperiencedNo visa sponsorship
J.P. Morgan logo

at J.P. Morgan

Bulge Bracket Investment Banks

Posted 9 days ago

No clicks

**Senior Lead Security Engineer (Hardware)** - **Location:** Plano, TX, USA - **Key Responsibilities:** Lead firmware & hardware security evaluations, analyze complex designs, detect Indicators of Compromise (IOCs), mentor colleagues, advance security testing tools, align security with business goals. - **Required Skills/Experience:** 5+ years in hardware/firmware security, Common Criteria (CC) project experience, proficiency in C, Python, Assembly, VHDL, Verilog. Knowledge of cryptographic primitives, side-channel analysis, fault injection. Ability to work independently and effectively communicate with stakeholders. - **Technologies/Skills:** Firmware security analysis, hardware bill of materials (BOM) analysis, side-channel analysis, fault injection, AI-assisted risk analysis, common security standards (Common Criteria, EMVCo).

Compensation
Not specified

Currency: Not specified

City
Plano
Country
United States

Full Job Description

Location: Plano, TX, United States

Job Responsibilities 

  • Perform and lead hardware and firmware security evaluations using techniques such as source code review, fault injection, and side-channel analysis to validate product security posture. 
  • Understand and analyze complex hardware and firmware designs, locating weaknesses and vulnerabilities in AMD and Intel server platforms, network and DMZ devices, laptops, and IoT devices. Perform firmware security analysis and hardware bill of materials (BOM) content security analysis to identify supply chain risks and unauthorized modifications. 
  • Detect Indicators of Compromise (IOCs) in firmware and hardware components across the enterprise infrastructure. Advise internal product teams through critical parts of their lifecycle management, providing detailed security assessment reports and remediation guidance. 
  • Coach and mentor colleagues to grow as security evaluators and architects within the hardware security domain. Apply critical thinking to distinguish security-critical issues from lower-priority findings and communicate risk effectively to stakeholders. 
  • Drive internal research and development of new attack methodologies, security testing tools, and evaluation frameworks to advance the firm's hardware security capabilities. Collaborate with cross-functional teams including product delivery managers, security engineers, and other stakeholders to translate security requirements into technical designs. 
  • Ensure alignment of hardware and firmware security architecture with business goals, regulatory requirements, and industry certification standards (e.g., Common Criteria, EMVCo). 
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations

Required qualifications, capabilities, and skills 

  • Formal training or certification with 5+ years of applied experience in hardware or firmware security evaluation. 
  • Proven experience in Common Criteria (CC) projects, preferably as an evaluator, or as a security consultant or developer of secure embedded products. 
  • Track record in CC or equivalent security evaluation projects involving ICs, server platforms, operating systems, TEE (Trusted Execution Environments), network devices, or IoT devices. 
  • Proficiency in programming languages relevant to hardware and firmware security (e.g., C, Python, Assembly, VHDL, Verilog). 

    Experience disassembling and reverse-engineering firmware for ARM, MIPS, or Intel architectures. 

  • Knowledge of cryptographic primitives and protocols including encryption algorithms, key exchange algorithms, hashing/message authentication algorithms, PKI, and random number generators. 

    Hands-on experience with Side-Channel Analysis (SCA) and Fault Injection (FI) techniques and tooling. 

  • Basic to advanced knowledge of electronics, embedded systems, chip design, and applied cryptography.  

    Ability to work independently and lead security assessments without close supervision. 

    Effective communication and stakeholder management across business and technology teams; strong technical writing abilities for producing detailed security evaluation reports. 

  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Preferred qualifications, capabilities, and skills 

  • Experience extracting and identifying firmware filesystems, reverse-engineering embedded binaries, emulating firmware for dynamic analysis, fuzzing parsers and scanning network services for vulnerability discovery, interfacing with hardware debug ports (JTAG/SWD) and flash memory for firmware extraction, and performing advanced physical attacks including side-channel analysis and fault injection. 

  • Debugging and instrumentation experience for Android, iOS, or Linux on embedded platforms. 

  • Experience with security testing tools and methodologies for embedded and IoT devices. 

  • Experience extracting and identifying firmware filesystems, reverse-engineering embedded binaries, emulating firmware for dynamic analysis, fuzzing parsers and network services for vulnerability discovery, interfacing with hardware debug ports (JTAG/SWD) and flash memory for firmware extraction, and performing advanced physical attacks such as side-channel analysis and fault injection. 

  • Prior experience in the banking or financial services industry. 

  • Understanding of regulatory requirements and compliance standards applicable to payment and financial hardware security. 

As a Senior Lead Hardware Security Engineer within JPMorganChase's Cybersecurity & Technology Controls group, you lead the evaluation and validation of firmware and hardware security across AMD and Intel distributed servers, network and DMZ devices, laptops, and IoT devices. You apply deep technical expertise in firmware security analysis, hardware bill of materials (BOM) content security analysis, side-channel analysis, and fault injection to discover product risk profiles and ensure the security of the firm's physical and embedded technology assets.

Sr Lead Security Engineer

Compensation

Not specified

City: Plano

Country: United States

J.P. Morgan logo
Bulge Bracket Investment Banks

9 days ago

No clicks

at J.P. Morgan

ExperiencedNo visa sponsorship

**Senior Lead Security Engineer (Hardware)** - **Location:** Plano, TX, USA - **Key Responsibilities:** Lead firmware & hardware security evaluations, analyze complex designs, detect Indicators of Compromise (IOCs), mentor colleagues, advance security testing tools, align security with business goals. - **Required Skills/Experience:** 5+ years in hardware/firmware security, Common Criteria (CC) project experience, proficiency in C, Python, Assembly, VHDL, Verilog. Knowledge of cryptographic primitives, side-channel analysis, fault injection. Ability to work independently and effectively communicate with stakeholders. - **Technologies/Skills:** Firmware security analysis, hardware bill of materials (BOM) analysis, side-channel analysis, fault injection, AI-assisted risk analysis, common security standards (Common Criteria, EMVCo).

Full Job Description

Location: Plano, TX, United States

Job Responsibilities 

  • Perform and lead hardware and firmware security evaluations using techniques such as source code review, fault injection, and side-channel analysis to validate product security posture. 
  • Understand and analyze complex hardware and firmware designs, locating weaknesses and vulnerabilities in AMD and Intel server platforms, network and DMZ devices, laptops, and IoT devices. Perform firmware security analysis and hardware bill of materials (BOM) content security analysis to identify supply chain risks and unauthorized modifications. 
  • Detect Indicators of Compromise (IOCs) in firmware and hardware components across the enterprise infrastructure. Advise internal product teams through critical parts of their lifecycle management, providing detailed security assessment reports and remediation guidance. 
  • Coach and mentor colleagues to grow as security evaluators and architects within the hardware security domain. Apply critical thinking to distinguish security-critical issues from lower-priority findings and communicate risk effectively to stakeholders. 
  • Drive internal research and development of new attack methodologies, security testing tools, and evaluation frameworks to advance the firm's hardware security capabilities. Collaborate with cross-functional teams including product delivery managers, security engineers, and other stakeholders to translate security requirements into technical designs. 
  • Ensure alignment of hardware and firmware security architecture with business goals, regulatory requirements, and industry certification standards (e.g., Common Criteria, EMVCo). 
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations

Required qualifications, capabilities, and skills 

  • Formal training or certification with 5+ years of applied experience in hardware or firmware security evaluation. 
  • Proven experience in Common Criteria (CC) projects, preferably as an evaluator, or as a security consultant or developer of secure embedded products. 
  • Track record in CC or equivalent security evaluation projects involving ICs, server platforms, operating systems, TEE (Trusted Execution Environments), network devices, or IoT devices. 
  • Proficiency in programming languages relevant to hardware and firmware security (e.g., C, Python, Assembly, VHDL, Verilog). 

    Experience disassembling and reverse-engineering firmware for ARM, MIPS, or Intel architectures. 

  • Knowledge of cryptographic primitives and protocols including encryption algorithms, key exchange algorithms, hashing/message authentication algorithms, PKI, and random number generators. 

    Hands-on experience with Side-Channel Analysis (SCA) and Fault Injection (FI) techniques and tooling. 

  • Basic to advanced knowledge of electronics, embedded systems, chip design, and applied cryptography.  

    Ability to work independently and lead security assessments without close supervision. 

    Effective communication and stakeholder management across business and technology teams; strong technical writing abilities for producing detailed security evaluation reports. 

  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Preferred qualifications, capabilities, and skills 

  • Experience extracting and identifying firmware filesystems, reverse-engineering embedded binaries, emulating firmware for dynamic analysis, fuzzing parsers and scanning network services for vulnerability discovery, interfacing with hardware debug ports (JTAG/SWD) and flash memory for firmware extraction, and performing advanced physical attacks including side-channel analysis and fault injection. 

  • Debugging and instrumentation experience for Android, iOS, or Linux on embedded platforms. 

  • Experience with security testing tools and methodologies for embedded and IoT devices. 

  • Experience extracting and identifying firmware filesystems, reverse-engineering embedded binaries, emulating firmware for dynamic analysis, fuzzing parsers and network services for vulnerability discovery, interfacing with hardware debug ports (JTAG/SWD) and flash memory for firmware extraction, and performing advanced physical attacks such as side-channel analysis and fault injection. 

  • Prior experience in the banking or financial services industry. 

  • Understanding of regulatory requirements and compliance standards applicable to payment and financial hardware security. 

As a Senior Lead Hardware Security Engineer within JPMorganChase's Cybersecurity & Technology Controls group, you lead the evaluation and validation of firmware and hardware security across AMD and Intel distributed servers, network and DMZ devices, laptops, and IoT devices. You apply deep technical expertise in firmware security analysis, hardware bill of materials (BOM) content security analysis, side-channel analysis, and fault injection to discover product risk profiles and ensure the security of the firm's physical and embedded technology assets.