Jobs / JPMorgan Chase / Lead Security Engineer - Threat modeling

Lead Security Engineer - Threat modeling

JPMorgan Chase · ✓ Verified company
📍 Bengaluru, Karnataka, India · On-site · Full-time

About the role

We have an exciting and rewarding opportunity for you to advance your security engineering career. Join a team where your expertise shapes the future of cybersecurity. As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity and Technology Controls team, you design and deliver trusted cybersecurity architecture solutions for software applications and platforms. You collaborate with cross-functional teams to implement technology solutions and communicate risk and mitigation options using best practices in support of the firm’s business objectives. You play a key role in protecting the firm’s data and infrastructure. Job responsibilities - Perform analysis and reporting against security risks to protect data, applications, and infrastructure using modern tools - Conduct reviews on existing security controls with minimal oversight - Identify gaps in network architecture and create documentation of threats and mitigations for small software applications - Create secure and high-quality production code and maintain algorithms that run synchronously with appropriate systems - Produce architecture and design artifacts for complex applications, ensuring design constraints are met by software code development - Gather, analyze, synthesize, and develop visualizations and reporting from large, diverse data sets in service of continuous improvement of software applications and systems - Proactively identify hidden problems and patterns in data and use these insights to drive improvements to coding hygiene and system architecture - Contribute to software engineering communities of practice and events that explore new and emerging technologies - Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately. - Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations   Required qualifications, capabilities and skills - Formal training or certification on security engineering concepts and 5+ years applied experience - Experience creating cybersecurity solutions based on existing security parameters - Ability to evaluate current cybersecurity technologies to recommend ways to optimize architecture - Hands-on practical experience in system design, application development, testing, and operational stability - Proficient in coding in one or more languages - Strong working knowledge of information and network security, IT risk management, and architectural concepts and patterns - Hands-on practical experience performing threat modeling for software applications and systems - CISSP or CCSP certification - Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity. - Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. - Demonstrated knowledge of software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)   Preferred qualifications, capabilities and skills - Familiarity with modern front-end technologies - Exposure to cloud technologies - AWS or GCP