Search Jobs

Search by job, company or skills

Senior Lead Cybersecurity Architect - Threat Modelling, Security Architecture and Design

Senior Lead Cybersecurity Architect - Threat Modelling, Security Architecture and Design

JP Morgan Chase & Co.
Fresher
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Join a dynamic team where your expertise shapes the future of an iconic company. Grow your career by making a direct impact in a high-achieving environment.


As a Senior Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity & Technology Controls team, you are an integral part of a group that develops high-quality cybersecurity solutions for software applications and platform products. You drive significant business impact through your capabilities and contributions, applying deep technical expertise and problem-solving skills to tackle diverse cybersecurity challenges across multiple technology domains. We value your ability to influence, innovate, and collaborate in a fast-paced setting.

Job responsibilities

  • Guide evaluation of current cybersecurity principles, processes, and controls, and lead assessment of new technology using existing standards and frameworks, influencing peers and decision-makers to adopt leading-edge solutions.
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements.
  • Provide technical guidance and direction to support business and technical teams, contractors, and vendors, serving as a subject matter expert in areas of focus.
  • Work with stakeholders and senior business leaders to recommend business modifications during periods of vulnerability.
  • Advocate firm-wide frameworks, tools, and practices of the Software Development Life Cycle within the engineering community.
  • Drives reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations.

Required qualifications, capabilities and skills

  • Formal training or certification on cybersecurity architecture and 5+ years applied experience
  • Hands-on practical experience delivering enterprise-level cybersecurity solutions and controls
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Advanced expertise in programming languages and applications, with deep knowledge of cybersecurity architecture and technical processes across domains such as public cloud, AI/ML, and mobile.
  • Demonstrable scripting and programming experience in modern languages including Python, Ruby, Javascript, NodeJS, Java, C#, C++, and Bash.
  • Ability to independently solve design and functionality problems, and evaluate emerging technologies to recommend optimal solutions for future state architecture.
  • Professional experience with public and private cloud platforms (AWS, GCP, Azure), containerization and orchestration (Kubernetes), microservice architectures, and relevant cloud certifications (AWS Solutions Architect Associate/Professional, AWS Security Specialty, GCP/Azure equivalents).
  • Experience in roles such as Security Architect, IT Risk Manager, DevOps/DevSecOps Engineer, or Cloud Security Engineer
  • Strong understanding of secure software design principles, common attack patterns, OWASP top 10 risks, vulnerabilities, solutions, and frameworks.
  • Expertise in Identity and Access Management for enterprise and hybrid environments, including SSO, OAuth, SAML, AD & ADFS, Privileged Access Management, RBAC, and knowledge of Threat Intelligence, APT groups, malware analysis, and MITRE ATT&CK framework.

Preferred qualifications, capabilities and skills

  • Demonstrable experience in information security in operations, engineering, or architect roles preferably within regulated financial services environments.
  • Knowledge in Agile and ability to work with at least one common framework
  • Breadth of experience across domains such as enterprise security architecture, compute services, storage, networking, virtualization, data center, integration architecture (API), orchestration technologies (Openstack/Cisco), application development lifecycle management (DevOps, CI/CD), and service delivery
  • Conduct manual, language-agnostic code review to identify security-related vulnerabilities

More Info