Lead Security Engineer – Infrastructure, HSM
JPMorgan Chase & Co. Bengaluru, Karnataka, India
Financial Services · 10,001+ employees
About the role
You will lead the architecture, design, and lifecycle management of complex Hardware Security Module and cryptographic infrastructure to ensure secure payment operations. Additionally, you will collaborate with cross-functional teams to define security standards, perform risk assessments, and drive innovation in infrastructure resiliency.
What they look for
Requirements
The role requires 5+ years of applied experience in security engineering with hands-on expertise in Hardware Security Modules and enterprise Linux/Unix environments. Candidates must demonstrate proficiency in infrastructure automation, cryptographic principles, and the ability to validate AI-assisted security recommendations.
Full description
Join a world-class cybersecurity team and make a lasting impact by safeguarding critical payment and cryptographic operations. Advance your career by collaborating with experts and driving innovation in secure infrastructure.
As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity & Technology Controls team, you will design, implement, and maintain secure, scalable, and resilient infrastructure solutions supporting critical payment and cryptographic operations. You will leverage deep expertise in Hardware Security Module management and infrastructure architecture to protect sensitive systems and data. You will collaborate with cross-functional teams to define standards, drive innovation, and ensure business continuity. You will thrive in complex, high-stakes environments and contribute to the forefront of cryptographic security.
Job responsibilities
- Lead the architecture, design, and documentation of complex Hardware Security Module and cryptographic infrastructure, ensuring alignment with business, resiliency, and security requirements
- Design and implement Hardware Security Module solutions, including deployment, configuration, integration, and full lifecycle management across Thales and FutureX platforms
- Develop and maintain architectural diagrams, system documentation, and operational runbooks to support operational excellence and knowledge continuity
- Collaborate with cross-functional teams to define infrastructure standards, best practices, and security controls that align with firm-wide policies and industry regulations
- Oversee migration, upgrade, and consolidation of Hardware Security Module infrastructure, ensuring minimal disruption and maximum security throughout transitions
- Provide guidance on cryptographic key management, secure storage, confidential computing, and compliance with industry standards including Payment Card Industry Data Security Standard and Federal Information Processing Standards
- Troubleshoot and resolve infrastructure and Hardware Security Module-related issues, performing root cause analysis and implementing corrective actions using monitoring tools
- Participate in risk assessments, audits, and incident response activities related to infrastructure and Hardware Security Module environments
- Apply domain knowledge of payment processes and business resiliency to infrastructure design and operational decision-making
- Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
- Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
Required qualifications, capabilities and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Hands-on engineering experience with Hardware Security Modules, including expertise in architecture and system design of highly available infrastructure, disaster recovery, and business continuity strategies
- Experience with network security, firewalls, and secure room operations and key ceremonies
- Proficient technical troubleshooting skills with strong Linux and Unix administration experience in enterprise environments
- Proficiency in designing and documenting infrastructure architectures using industry-standard tools and methodologies
- Experience with infrastructure automation tools such as Terraform for managing and scaling secure environments
- Hands-on experience with OpenSSL and certificate-based authentication mechanisms
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
Preferred qualifications, capabilities and skills
- Hands-on experience with Splunk or equivalent platforms for infrastructure monitoring and troubleshooting
- Strong domain knowledge of payment processes and business resiliency applied to infrastructure design
- Relevant Hardware Security Module platform certifications such as Thales or FutureX credentials
- Strong understanding of cryptographic principles, key management, confidential computing, and secure hardware operations
Similar roles
-
Security Engineer (French Speaker) | BPCE-SI
Natixis in Portugal Portugal
-
OPERATIONAL SECURITY ENGINEER – NETWORK FILTERING
BE Bucharest, Romania
-
Cybersecurity Operations Engineer - Singpass
Assurity Trusted Solutions Singapore, Singapore
-
Lead Cybersecurity Analyst
TerraPay Bengaluru, Karnataka, India
-
Senior Cloud Security Engineer | Remote
Tasq Staffing Solutions, Inc. Philippines
-
Cybersecurity Senior Full-Stack Engineer (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany