JPMorgan Chase & Co.

Sr Lead Cybersecurity Architect

JPMorgan Chase & Co. Columbus, Ohio, United States · $176K–$260K/yr

Financial Services · 10,001+ employees

12 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Lead Cybersecurity Architect will define and maintain secure-by-default baseline configurations and lead technology assessments across the endpoint security estate. They will also conduct proactive threat modeling and provide expert guidance to product teams to ensure operational resilience and compliance.

What they look for

Cybersecurity architecture Threat modeling Risk assessment Python PowerShell Bash Endpoint security Identity and access management Cloud security DevSecOps CI/CD pipelines NIST 800-53 AI/ML security Network security Secure design reviews Automation

Requirements

Candidates must have 5+ years of applied experience in cybersecurity architecture and hands-on expertise in threat modeling and secure design reviews. Proficiency in scripting languages and a deep understanding of enterprise security controls and risk management frameworks are required.

Benefits

Health care coverage Retirement savings plan Backup childcare Tuition reimbursement Mental health support Financial coaching Incentive compensation

Full description

Play a vital role in shaping the future of an iconic company and make a direct impact in a dynamic environment designed for top achievers.

As a Senior Lead Cybersecurity Architect at JPMorganChase within the Employee Compute Security Architecture (ECSA) team, you are an integral part of a team that enables endpoint security product teams to deliver secure-by-default, resilient services at speed. Drive significant business impact by embedding clear security standards, consumable security services, and expert guidance into the delivery lifecycle across the endpoint security estate. Apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains, from endpoint and identity to collaboration, virtualization, and cloud-delivered workplace services.

Our mission is to drive enterprise risk reduction and operational resilience by standardizing secure baseline configurations, integrating proactive threat modeling and consultative reviews, and producing control artifacts that simplify compliance and accelerate time to value.

Job responsibilities

  • Lead and own the evaluation of cybersecurity principles, processes, and controls across the endpoint security estate; drive technology assessments using established security standards and patterns, with the authority to influence peers and decision-makers to adopt leading-edge solutions.
  • Define, publish, and maintain secure-by-default baseline configurations and consumable security services that endpoint security product teams can adopt directly within their delivery lifecycle.
  • Conduct proactive threat modeling, security assessments, and technical risk assessments on design proposals from product and engineering teams, delivering consultative secure design reviews.
  • Leverage enterprise-authorized AI and machine learning capabilities to improve the efficiency, throughput, and quality of cybersecurity architecture work — including accelerating risk analysis and decisioning, automating threat modeling and secure design reviews, and generating control artifacts — while validating outputs and handling data according to sensitivity and security requirements.
  • Serve as a subject matter expert across ECSA and the broader cybersecurity organization, providing technical guidance and direction to technology teams, business partners, contractors, and vendors, and championing secure-by-design adoption at speed.
  • Work with stakeholders and senior business leaders to recommend risk mitigations and business modifications during periods of elevated risk, open vulnerability windows, or active risk acceptance decisions, and translate regulatory requirements into actionable technical controls.
  • Produce control artifacts and evidence that simplify compliance, streamline audits, and accelerate time to value for product teams.
  • Actively contribute to the engineering community as an advocate for firmwide frameworks, tools, and practices of the Software Development Life Cycle, integrating security into CI/CD pipelines and DevSecOps workflows.
  • Influence technology decisions by introducing improvements in implementation patterns and architectural design, and identify opportunities to eliminate or automate remediation of recurring issues.
  • Manage concurrent architecture engagements — balancing priorities, deadlines, and deliverables across multiple product teams — to ensure timely security design input and implementation support.
  • Add to team culture of diversity, equity, inclusion, and respect.

Required qualifications, capabilities, and skills

  • Formal training or certification on cybersecurity architecture and 5+ years applied experience
  • Hands-on practical experience delivering enterprise-level cybersecurity solutions and controls, including threat modeling, threat assessments, and secure design reviews.
  • Experience applying AI or machine learning tools to cybersecurity or technology workflows, with demonstrated ability to critically evaluate and validate AI-assisted outputs before adoption. Direct application within cybersecurity architecture workflows — such as AI-accelerated risk analysis, threat modeling, or control documentation — is strongly preferred and will characterize day-to-day work in this role.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Proficiency in scripting and automation languages (e.g., Python, PowerShell, or Bash), with solid knowledge of cybersecurity architecture, applications, and technical processes within one or more technical disciplines (e.g., public cloud, endpoint, identity, AI/ML, or mobile).
  • Experience securing endpoint or workplace-compute platforms (e.g., Windows/macOS, EDR, MDM, or virtualization); candidates are expected to bring demonstrated depth in at least one of these areas.
  • Experience in infrastructure or systems administration — such as enterprise systems engineering, OS deployment and hardening, or platform operations — and the secure software development lifecycle, including familiarity with automation, continuous delivery, and security integration into CI/CD pipelines.
  • Experience in security products, risk management, information security standards, security architecture principles, threat and vulnerability management, and incident response methodologies.
  • Working knowledge of enterprise networking concepts and network security controls — including network segmentation, firewall policy, secure access patterns, and DNS/proxy architecture — sufficient to assess and advise on network-layer design decisions within endpoint and workplace environments.
  • Understanding of enterprise Identity and Access Management concepts such as federated identity, SSO, OAuth/SAML, privileged access management, and RBAC.
  • Experience designing security controls aligned to a comprehensive control catalog (e.g., NIST 800-53), including control scoping, design, and the production of control artifacts and evidence that support compliance and audit readiness.
  • Ability to tackle design and functionality problems independently with little to no oversight.
  • Ability to evaluate current and emerging technologies to select or recommend the best solutions for the future-state architecture.
  • Excellent verbal and written communication skills, with the demonstrated ability to translate security concepts clearly for both technical and non-technical audiences — including executives, senior business leaders, and external partners.

Preferred qualifications, capabilities, and skills

  • Industry certifications such as CISSP, CCSP, SABSA, or equivalent cybersecurity architecture credentials.
  • Experience navigating cross-jurisdictional compliance complexity in a multi-national or global enterprise, including adapting security controls to meet region-specific regulatory requirements.
  • Familiarity with financial services compliance frameworks beyond NIST 800-53, such as SOC 2, PCI-DSS, NIST CSF 2.0, or the NIST AI Risk Management Framework.
  • Experience with zero-trust architecture principles and their practical application in hybrid or multi-cloud environments.
  • Experience with AI governance practices, MLSecOps, or enterprise AI security policy — such as model risk management, AI supply-chain security, or AI-specific control frameworks.
  • Experience securing AI/ML and agentic systems (e.g., threat modeling for prompt injection, data leakage, model extraction, and supply-chain exposure), and willingness to work on proofs of concept for new, innovative approaches.
  • Experience providing technical mentorship, conducting architectural guidance sessions, or leading communities of practice within a security or engineering organization.

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Similar roles