JPMorgan Chase & Co.

Sr. Lead Cybersecurity Architect - Product Security Lead

JPMorgan Chase & Co. Jersey City, New Jersey, United States · $176K–$260K/yr

Financial Services · 10,001+ employees

4 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves driving product security initiatives by partnering with engineering teams to integrate security controls and design patterns throughout the product lifecycle. You will conduct threat modeling, vulnerability assessments, and provide security guidance to ensure compliance with firmwide technology standards.

What they look for

Cybersecurity architecture Product security Threat modeling Vulnerability assessment Secure development practices AWS GCP Java Python C/C++ DevSecOps NIST Cybersecurity Framework Risk assessment Cloud security Leadership Communication

Requirements

Candidates must have at least 5 years of experience in a product security role with strong knowledge of secure software development practices and common vulnerabilities. Proficiency in programming languages like Java or Python and experience with cloud platforms and security frameworks are required.

Benefits

Health care coverage Retirement savings plan Backup childcare Tuition reimbursement Mental health support Financial coaching On-site health and wellness centers

Full description

We are seeking an experienced Product Security Team Member to drive our product security initiatives. The ideal candidate is a hands-on expert in product security with a strong technical background and a deep understanding of secure development practices. You will collaborate with cross-functional teams to identify, assess, and mitigate security risks throughout the product lifecycle.

Job responsibilities

  • Partnering with the Engineering & Architecture teams to integrate security controls into platforms (e.g. AWS, GCP, etc. based public cloud platforms) and frameworks
  • Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
  • Assisting and guiding engineering teams in the secure development of infrastructure services and products
  • Ensure security considerations are delivered in compliance with firmwide technology controls from the start and throughout the Software Development Lifecycle.
  • Developing extensible security solutions aligned to the product strategy in future developments.
  • Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
  • Work with architects and developers to design and implement secure code practices, conduct code reviews, and ensure security is embedded in the design.
  • Knowledge of emerging security threats, vulnerabilities, and trends relevant to our products.
  • Drive security education and awareness across the organization, ensuring all employees understand their role in maintaining product security.
  • Provide regular security updates to senior management and stakeholders, translating technical security issues into business impact.
  • Improve security policies, standards, and guidelines related to product security.
  • Stay up-to-date with the latest security technologies, trends, and best practices.

Required qualifications, capabilities, and skills

  • Formal Training or certification with 5 + years of experience in a product security role with a track record of driving security initiatives.
  • Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
  • Experience with threat modeling, risk assessment, and vulnerability management.
  • Proficiency in programming languages (e.g., Java, Python, C/C++).
  • Familiarity with security frameworks (e.g., NIST Cybersecurity Framework) and industry regulations (e.g., GDPR, HIPAA).
  • Excellent leadership, communication, and interpersonal skills.
  • Security certifications such as CISSP, CISM, or relevant certifications are a plus.
  • Cloud Certifications such as AWS Solutions Architecture Associate/Professional, AWS Security Specialty
  • Experience with DevSecOps practices and tools is desirable.
  • Ability to lead and work effectively in a cross-functional team environment.
  • Strong problem-solving skills and the ability to think critically

Preferred qualifications , capabilities and skills

  • Security certifications (e.g., CISSP, CISM, CCSP) and/or cloud certifications (e.g., AWS Security Specialty, Solutions Architect).
  • Experience with DevSecOps and continuous compliance controls (policy-as-code, guardrails, automated evidence).

#CTC

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Similar roles