Sr Lead Security Engineer
Job Description
Work onsite in Jersey City, NJ and help shape how cybersecurity architecture is delivered across the Software Development Life Cycle (SDLC). In this Sr Lead Security Engineer role at JPMorganChase, you’ll provide technical direction, identify risk and practical mitigation options, and drive AI-assisted security validation while ensuring results are validated for security, resiliency, and auditability needs.
You will lead cybersecurity architecture efforts within Cybersecurity and Technology Controls, partnering with stakeholders and senior business leaders to improve control effectiveness, support decision-making, and influence adoption of leading-edge solutions grounded in established standards and frameworks.
Responsibilities
- Guide evaluation of current cybersecurity principles, processes, and controls, and lead assessments of new technology using existing standards and frameworks.
- Use enterprise-authorized AI capabilities to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements.
- Provide technical guidance and direction to support business units, technical teams, contractors, and vendors, serving as a function-wide subject matter expert for one or more focus areas.
- Work with stakeholders and senior business leaders to recommend business modifications during periods of vulnerability.
- Act as an engineering community advocate for firm-wide frameworks, tools, and Software Development Life Cycle (SDLC) practices.
- Drive reuse-first adoption of AI-assisted security validation within SDLC and toolchain routines to improve control testing, remediation quality, and traceability/auditability in line with resiliency expectations.
Requirements
- 5+ years of applied experience, supported by formal training or certification on cybersecurity architecture (NAMR/APAC: India, LATAM, Hong Kong).
- Formal training or certification on cybersecurity architecture concepts plus advanced applied experience (EMEA/LATAM-Brazil).
- Singapore-specific: follow local country guidance.
- Hands-on, practical experience delivering enterprise-level cybersecurity solutions and controls.
- Demonstrated experience using enterprise-authorized AI capabilities in cybersecurity architecture workflows, with strong validation habits and awareness of data sensitivity.
- Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring alignment with security, resiliency, and auditability expectations.
- Advanced expertise in one or more programming language(s) and/or applications, with advanced knowledge of cybersecurity architecture, applications, and technical processes within one or more technical disciplines (such as public cloud, AI/ML, or mobile).
- Ability to tackle design and functionality problems independently with little to no oversight.
- Ability to evaluate current and emerging technologies to recommend solutions for future-state architecture.
- Threat modeling skills using MITRE ATT&CK, STRIDE, PASTA, and related approaches.
- Experience with Security Architecture review and design.
Tech Stack
AI, MITRE ATT&CK, STRIDE, PASTA, SDLC, AI/ML, public cloud, mobile
Compensation: USD 175,750 - 260,000 per year.