JPMorgan Chase
Posted 2mo ago

Lead Security Engineer - Cloud Proxy

JPMorgan Chase
Plano or Seattle or Palo Alto or Columbus
$152k-$215k/yrOnsiteFull Time
Responsibilities
  • designing solutions
  • managing infrastructure
  • troubleshooting connectivity
Requirements
  • 5+ years security
  • Software, or network engineering experience
  • Experience designing enterprise cloud security and network solutions
  • Production-quality coding, IaC
  • Automation, and strong communication skills
Technical tools mentioned
Infrastructure-as-Code (IaC)AWS ECSAWS EC2AWS LambdaAWS API GatewayAWS VPCAWS Transit GatewayAWS PrivateLinkEnvoyF5SquidTLS/SSLPKImTLS

Job description

Take on a crucial role where you'll be a key part of a high-performing team delivering secure, scalable cloud network perimeter solutions. Make a real impact as you help shape the future of cloud egress security at one of the world's largest and most influential companies.

As a Lead Security Engineer at JPMorganChase within the Cloud Edge Proxy team, you will help design, secure, and operate a critical cloud network perimeter platform that governs outbound cloud traffic at enterprise scale. You will work across engineering and business teams to ensure cloud connectivity is secure, reliable, and compliant — while enabling application teams to onboard and operate confidently.

 

Job Responsibilities

  • Designs, develops, and maintains secure software solutions for cloud network perimeter infrastructure, writing high-quality production code and reviewing code written by others across the full development lifecycle

     

  • Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.

  • Builds and manages infrastructure-as-code (IaC) to automate the provisioning, configuration, and scaling of cloud networking and proxy infrastructure in a consistent, repeatable, and auditable manner

  • Manages and operates enterprise-scale proxy infrastructure, ensuring high availability, performance, and security of egress traffic controls across cloud environments
  • Develops and maintains automation tooling to streamline network configuration, proxy onboarding workflows, certificate management, and policy enforcement
  • Troubleshoots complex network and proxy connectivity issues across cloud environments, applying structured diagnostic approaches to identify root cause and drive resolution
  • Collaborates with application teams, platform engineers, and architects to design secure and scalable network connectivity patterns that meet both technical and business requirements
  • Minimizes security vulnerabilities by following industry insights and evolving best practices, continuously improving network perimeter controls and validating their effectiveness
  • Adds to team culture of diversity, opportunity, inclusion, and respect
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.

 

Required Qualifications, Capabilities, and Skills

  • Formal training or certification in software engineering, security engineering, or network engineering concepts and 5+ years of applied experience in one or more of these disciplines
  • Skilled in planning, designing, and implementing enterprise-level security and/or network solutions within cloud environments
  • Develops secure and high-quality production code and reviews and debugs code written by others, with a focus on cloud network security automation and infrastructure-as-code
  • Minimizes security vulnerabilities by following industry insights and governmental regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls
  • Works with stakeholders and business leaders to understand secure connectivity requirements and recommend appropriate architectural patterns and modifications during periods of vulnerability or change
  • Experience with AWS services including serverless solutions, ECS, EC2, Lambdas, API Gateway, and networking services such as VPCs, Transit Gateway, and PrivateLink
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Good communication skills, teamwork capabilities, and a self-learning attitude

     

  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.

 

Preferred Qualifications, Capabilities, and Skills

  • Experience with forward or reverse proxy technologies and architectures at enterprise scale (e.g., F5, Squid, Envoy, or equivalent)
  • Hands-on experience with TLS/SSL certificate management, PKI, mTLS, and truststore configuration in cloud-native environments
  • Strong understanding of proxy protocols (HTTP CONNECT, HTTPS, SOCKS5), DNS-based routing, and network egress control patterns
  • Experience effectively communicating with senior business leaders
  • AWS Certifications (e.g., Solutions Architect, Security Specialty, Advanced Networking Specialty) 

About Company

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Company


JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

About JPMorgan Chase

Global financial services and investment banking firm.

Year founded
1799
Employees
323028
Organization type
Public
Latest investment
Post-IPO Debt (2026)
Headquarters
US

Similar jobs

Security Engineer roles near Plano, Texas
1d
Save
Mark Applied
Hide
LINCS Security Engineer
Temple or Papillion or Aurora or Garland or Huntsville or Houston
$162k-$227k/yr OnsiteFull Time
Meta
MetaNASDAQ: META: Builds technologies that help people connect, find communities, and grow businesses.
7+ YOEBachelor's degree or equivalent practical experience, 7+ years in network, infrastructure, or telecommunications security, security program ownership, and knowledge of network engineering and secure architectures.
TCP/IP, AI tools
1d
Save
Mark Applied
Hide
Security Engineer, Identity and Access Management
Dallas, Texas, United States
$159k-$202k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Multinational technology focused on e-commerce and cloud computing.
3+ YOEBachelor's degree in computer science or equivalent; 3+ years programming experience, 2+ years security code review and systems troubleshooting, networking knowledge, and security vulnerability remediation expertise.
Python, Ruby, Go, Swift, Java, .Net, C++, HTTP, DNS, TCP/IP, AWS, FIDO2, WebAuthn, Kerberos, Single Sign-On, OAuth 2.0, OpenID Connect, SAML, SAST, DAST
5d
Save
Mark Applied
Hide
Senior Security Engineer
Miami or Austin or Pecos or Denton or Muskogee or Grand Forks or Calvert City or Marble or Dalton or Auburn
RemoteFull Time
Core Scientific
Core ScientificNASDAQ: CORZ: Powered digital infrastructure for high-density computing
5+ YOEBachelor's degree preferred or 5+ years of information security experience; strong programming skills; extensive cloud, application, system, and network security experience; incident response and threat modeling expertise.
Python, Go, Java, C, C++, AWS, Azure, GCP, IAM, SASE, Zero Trust, VPN, CI/CD, IDS/IPS
5d
Save
Mark Applied
Hide
Security Engineer
Frisco or Eagan
$71k-$131k/yr HybridFull Time
Thomson Reuters
Thomson ReutersTSX, NASDAQ: TRI: Global provider of trusted information, software, and news.
3+ YOERequires 3+ years in security engineering, software development, systems administration, or DevSecOps; a bachelor's degree or equivalent experience; cloud and on-premises exposure; and knowledge of security principles, vulnerabilities, controls, and scripting.
AWS, Azure, GCP, OCI, CISA, CVSS, CISA KEV/EPSS, WAF, SAST, SCA
1w
Save
Mark Applied
Hide
Confluent - Staff Security Engineer I - Detection & Response
Poughkeepsie or Lowell or Rochester or Tucson or Research Triangle Park or Armonk or Boston or Bellevue or Atlanta or San Jose or Dallas or Austin or San Francisco or Seattle
$161k-$299k/yr RemoteFull Time
Confluent
ConfluentNASDAQ: CFLT: A data streaming platform designed to be the intelligent connective tissue enabling real-time data to stream across organizations.
8+ YOERequires a bachelor's degree and 8+ years in detection and response or security engineering, with expertise in cloud security, detection engineering, incident response, Python or Golang, and SIEM solutions.
Python, Golang, Kubernetes, AWS, GCP, Azure, SIEM, SOAR, ETL, IBM Cloud
1w
Save
Mark Applied
Hide
Technology Risk - Dallas - Security Engineering - Associate
Dallas, Texas, United States
OnsiteFull Time
Goldman Sachs
Goldman SachsNYSE: GS: Global investment banking, securities and investment management firm.
1+ YOERequires 1–4 years of cybersecurity experience, Python and PowerShell scripting, advanced Linux knowledge, cloud security, incident response, digital forensics, strong communication, and Level 2 investigation skills.
Windows, Linux, Python, PowerShell, Bash, Volatility, Rekall, The Sleuth Kit, Autopsy, EnCase, AWS, Google Cloud, Azure, MacOS, AI
1w
Save
Mark Applied
Hide
Technology Risk - Dallas - Security Engineering - Associate
Dallas, Texas, United States
OnsiteFull Time
Goldman Sachs
Goldman SachsNYSE: GS: Global investment banking, securities and investment management firm.
1+ YOERequires 1–4 years in security event triage, incident response, or digital forensics; Python and PowerShell; advanced Linux; cloud security; forensic toolkit experience; and strong English communication.
Windows, Linux, Python, PowerShell, Bash, Network security, standard deviation, simple matching, stack counting, outlier detection, regex, Volatility, Rekall, The Sleuth Kit, Autopsy, EnCase, AWS, Google Cloud, Azure, GNFA, GCFE, GCFA, CCFP, CFCE, ACE, OSCP, GCFR
1w
Save
Mark Applied
Hide
Lead Security Engineer | AirStrip
Dallas or El Segundo or San Antonio
$120k-$166k/yr OnsiteFull Time
AirStrip
AirStripOTC Markets: NHIQ: NantHealth is a public healthcare technology helping payers and providers exchange data and deliver evidence-based care.
8+ YOERequires 8+ years in IT, 5+ years in cybersecurity, cloud security expertise, incident response, threat hunting, security monitoring, IAM, compliance frameworks, and a related bachelor's degree preferred.
AWS, Azure, Identity and Access Management (IAM), SIEM, LogRhythm, Splunk, MITRE ATT&CK Framework, ITIL, Zero Trust, ISO 27001, NIST, HIPAA, HITRUST