JPMorgan Chase & Co.

Lead Cybersecurity Architect

JPMorgan Chase & Co. Bengaluru, Karnataka, India

Financial Services · 10,001+ employees

4 h ago
security Senior (5-10 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Cybersecurity Architect will design and deliver secure technology solutions while collaborating with engineering and business stakeholders. They are responsible for performing threat modeling, driving AI-assisted security validation, and managing technology risk in alignment with regulatory expectations.

What they look for

Cybersecurity Architecture Secure Design Threat Modeling DevSecOps Cloud Security Vulnerability Management Network Security Authentication Authorization Software Development SDLC Microservices APIs Identity Federation Risk Management AI-assisted Security

Requirements

Candidates must have 5+ years of applied experience in cybersecurity architecture and security engineering. Strong knowledge of DevSecOps, cloud security, and modern application architectures is required to ensure products are secure by design.

Full description

Join a team where your expertise in cybersecurity architecture shapes the future of secure technology solutions. Grow your career by collaborating with top engineering, product, and business professionals.

As a Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity and Technology Controls team, you will design and deliver high-quality cybersecurity solutions for software applications and platform products. You will partner with engineering, product, and business stakeholders to ensure solutions are secure by design, resilient, and aligned to regulatory and audit expectations. You will play a key role in supporting Chase UK and JPMorgan Personal Investing, contributing to a collaborative and innovative team culture. You will help drive impactful outcomes for the firm and its clients.

Job responsibilities

  • Perform secure design reviews and threat modeling with application teams to ensure products are secure by design.
  • Demonstrate deep understanding of product strategy, roadmap, and key investment programs.
  • Identify and learn unfamiliar technology components, capabilities, and business concepts, applying critical thinking to uncover hidden issues.
  • Leverages enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity architecture analysis and decisioning (e.g., risk identification and documentation), validating outputs and handling data according to sensitivity and security requirements.
  • Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing and remediation quality with traceability/auditability and resiliency expectations.
  • Share best practices and serve as the point of escalation and subject matter expert for Cybersecurity and Technology Controls.
  • Collaborate with product, technology, and business colleagues for audit, regulatory, risk, and project initiatives.
  • Work with Third Party Oversight teams to manage technology risk for vendors, focusing on cloud computing and emerging technologies.

Required qualifications, capabilities and skills

  • Formal training or certification on security engineering concepts and 5+ years applied experience
  • Advanced knowledge of cybersecurity architecture, applications, and technical processes with expertise in one or more technical disciplines
  • Ability to design and implement effective cybersecurity and technology controls
  • Strong knowledge of security best practices and DevSecOps methodologies
  • Experience with cloud security posture management and vulnerability management
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Understanding of network security, network design, segmentation, firewalls, and cloud networking patterns
  • Experience implementing and reviewing authentication and authorization controls and best practices
  • Hands-on experience in software development with strong understanding of SDLC and secure SDLC practices
  • Knowledge of modern application architectures including microservices, APIs, and event-driven patterns

Preferred qualifications, capabilities and skills

  • Experience with identity federation, least privilege, RBAC/ABAC concepts
  • Experience with cloud security technologies and emerging security trends
  • Ability to influence and partner across product supply chains
  • Experience working with Third Party Oversight teams and managing vendor technology risk

Similar roles