JPMorgan Chase
Posted 2w ago

Lead Security Engineer - Platform Engineer - Endpoint Security

JPMorgan Chase
Columbus, Ohio, United States
OnsiteFull Time
Responsibilities
  • designing software
  • operating platforms
  • mentoring engineers
Requirements
  • 5+ years applied security engineering experience
  • Advanced proficiency in compiled and scripting languages
  • Hands-on endpoint platform and container/cloud experience
  • Secure SDLC and CI/CD/GitOps expertise
  • Technical leadership and mentoring skills
Technical tools mentioned
PythonJavaJavaScript/TypeScriptGoRustC++DockerKubernetesGitOpsCI/CDpublic cloud platformsinfrastructure-as-code

Job description

Join a team that protects one of the world's most complex technology environments — not by writing policy, but by building the software and platforms that make security scale. At JPMorganChase, engineers like you have the opportunity to ship production code that runs at genuinely massive scale, solve hard problems across a global endpoint estate, and grow your craft alongside some of the most talented engineers in financial services.

As a Lead Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls — Employee Compute team, you will serve as the technical anchor for a portfolio of high-impact endpoint security platforms and automation programs spanning hundreds of thousands of Mac, Windows, Linux, and virtual desktop endpoints. You will set technical direction, drive day-to-day engineering execution, and raise the bar through design and code reviews — all while remaining hands-on in the code. This is a senior individual contributor role for an engineer who leads through technical excellence and delivery, not through a management hierarchy.

Our team lives at the intersection of DevOps, platform engineering, and full-stack development. You will build and operate systems that govern endpoint authentication, binary execution controls, and policy deployment automation — replacing brittle manual processes with auditable, resilient pipelines built on GitOps principles. If you want your work to matter and to run everywhere, this is the role for you.

Job responsibilities

  • Design, build, and ship production-quality software across Mac, Windows, Linux, and virtual desktop environments, serving as the primary technical contributor for a portfolio of endpoint security platforms
  • Architect and operate a managed binary allowlisting platform deployed via infrastructure-as-code in a private cloud environment, including automation that generates per-binary rules at application-packaging time
  • Develop and maintain cross-platform endpoint authentication tooling — written in a compiled language — that enables applications to authenticate through enterprise proxy infrastructure, including upcoming support for containerized deployment
  • Modernize system policy deployment across Windows and virtual desktop environments using GitOps principles, building automated pipelines that scan, grade, and deploy changes in a controlled, auditable manner
  • Drive technical direction and day-to-day execution across the team's engineering portfolio, ensuring delivery against milestones while maintaining high standards for code quality, security, and resilience
  • Conduct rigorous design and code reviews, mentoring associate engineers and elevating the technical capabilities of the team through hands-on guidance
  • Identify manual, high-overhead processes and architect automation solutions that eliminate operational toil and scale across the firm's endpoint estate
  • Collaborate cross-functionally with application teams, infrastructure, and security stakeholders to ensure platforms are consumable, audit-defensible, and aligned to enterprise standards
  • Apply secure development practices throughout the full software development lifecycle, designing controls that are tamper-resistant and hold up to regulatory scrutiny

 

Required qualifications, capabilities, and skills

  • Formal training or certification on security engineering concepts and 5+ years applied experience
  • Advanced proficiency in one or more major programming languages such as Python, Java, JavaScript/TypeScript, Go, Rust, or C++, with a demonstrated ability to build and ship production software
  • Hands-on enterprise experience managing at least two of the following endpoint platforms: Mac, Windows, virtual desktop infrastructure, or Linux
  • Proven experience with containers (Docker, Kubernetes), public cloud platforms, and infrastructure-as-code tooling
  • Proficiency across the full software development lifecycle, including CI/CD pipelines, GitOps workflows, and automated testing practices
  • Working knowledge of secure development practices with the ability to design, build, and operate controls that are audit-defensible and tamper-resistant
  • Demonstrated ability to decompose complex, ambiguous technical problems into clearly scoped, deliverable engineering work
  • Experience serving as a technical lead — driving execution, setting technical direction, and mentoring engineers through code reviews — while remaining hands-on in the codebase

 

Preferred qualifications, capabilities, and skills

  • Experience building security-focused or systems-level software on Mac, Windows, or Linux platforms
  • Familiarity with endpoint security concepts such as binary allowlisting, proxy and authentication flows, or system policy management
  • Experience implementing or evolving security controls within a large, regulated enterprise environment
  • Background in banking, financial services, or another highly regulated industry such as insurance or healthcare
  • Experience as a full-stack developer in a large enterprise environment, with comfort across both application and infrastructure layers
  • Experience responsibly using enterprise-authorized AI capabilities to accelerate development and validation, with strong habits around output validation and data sensitivity

     

#CTC

 

About Company

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Company


JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

About JPMorgan Chase

Global financial services firm providing banking and investment solutions.

Similar jobs

Security Engineer roles near Columbus, Ohio
6d
Save
Mark Applied
Hide
Sr. Security Engineer - Cloud Threat Detection
Charlotte or Columbus or Hartford or Chicago
$128k-$193k/yr HybridFull Time
The Hartford
The HartfordNYSE: HIG: Provides property and casualty insurance and financial products.
5+ YOERequires 5+ years of cybersecurity experience, hands-on AWS and GCP security operations, enterprise SIEM detection engineering, cloud telemetry analysis, documentation, and SOC analyst mentoring.
AWS, Google Cloud Platform (GCP), AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging, Identity and Access Management (IAM), Orca, CrowdStrike, Wiz, Splunk, Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, MITRE ATT&CK, Python, PowerShell, Bash, SentinelOne, Microsoft Defender XDR for Endpoint, SPL, SOAR
1w
Save
Mark Applied
Hide
Sr. Security Engineer - Cloud Threat Detection
Hartford or Charlotte or Columbus or Chicago
$128k-$193k/yr HybridFull Time
The Hartford
The HartfordNYSE: HIG: Provides business and personal insurance, group benefits, and investments.
5+ YOERequires 5+ years of cybersecurity experience, hands-on AWS and GCP security, enterprise SIEM detection development, cloud telemetry investigation, documentation, analyst mentoring, and US work authorization without sponsorship.
AWS, Google Cloud Platform (GCP), AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging, Identity and Access Management (IAM), Orca, CrowdStrike, Wiz, Splunk, Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, MITRE ATT&CK, SPL, Python, PowerShell, Bash, SOAR, SentinelOne, Microsoft Defender XDR for Endpoint
2mo
Save
Mark Applied
Hide
Senior Security Engineer
Dublin or Brooklyn
HybridFull Time
Medical Mutual
Medical Mutual: Provide health, dental, and vision insurance and Medicare plans.
7+ YOEHands-on experience securing infrastructure, identity, network, and endpoints; strong systems and network background; scripting/automation skills; experience troubleshooting complex security issues; bachelor’s or equivalent and multi-year IT security experience.
Active Directory, VPN, WAF, web proxy, DLP
2mo
Save
Mark Applied
Hide
Senior Security Engineer
Dublin or Brooklyn
HybridFull Time
Medical Mutual
Medical Mutual: Provides health, life, and disability insurance plans to members.
7+ YOE7+ years IT security experience, bachelor’s or equivalent, CRISC/CISSP preferred, strong systems/network background (Active Directory, servers, networking), scripting/automation, identity and endpoint security expertise.
Active Directory, VPN, WAF, web proxy, DLP, application firewall
3mo
Save
Mark Applied
Hide
Virtru Security Engineer
Fort Meade or Columbus or Ford Island or Hill AFB or Mechanicsburg or Pensacola or San Antonio or Scott AFB or Tinker AFB
$99k-$225k/yr HybridAll Commitments Available
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years in designing, deploying, and configuring data security solutions; experience with data security tools (e.g., Virtru); data-centric security models; IT security infrastructure; Kubernetes and Docker; data tagging/classification; Zero Trust knowledge; ability to travel up to 20%; Secret clearance; HS diploma or GED.
Terraform, Ansible, Kubernetes, Docker, Go, Python, Node.js, CNAP, SIEM, CSPM, CWPP
3mo
Save
Mark Applied
Hide
Virtru Security Engineer
Fort Meade or Pensacola or Mechanicsburg or Columbus or San Antonio or Ford Island or Scott AFB or Tinker AFB or Hill AFB
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years designing and deploying data security solutions; experience with data security tools (e.g., Virtru); security architecture and cloud knowledge; Kubernetes and Docker; data tagging/classification; Zero Trust concepts; ability to travel up to 20%; Secret clearance; HS diploma or GED.
Terraform, Ansible, Kubernetes, Docker, CI/CD, Vulnerability Scanning, CNAP, SIEM, CSPM, CWPP, Go, Python, Node.js
4mo
Save
Mark Applied
Hide
Security Engineer 2 - Cyber Security
Uniontown or Ann Arbor or Cincinnati or Columbus or Defiance or Fairmont or Findlay or Fort Wayne or Frankfort or Huntington or Indianapolis or Ironton or New Albany or Parkersburg or Pittsburgh or Toledo or Wheeling or Youngstown or Chattanooga or Franklin or Knoxville
RemoteFull Time
WesBanco
WesBancoNasdaq: WSBC: Regional bank providing personal, business, and investment services.
4+ YOEBachelor's in Information Security or related (or equivalent) plus 4 years' related experience; professional knowledge of network protocols and at least three tech areas (networking, Windows, security products, virtualization, cloud); change management experience.
Citrix, VMware, Nutanix, Azure, AWS, TCP/IP, SIEM, NIST, CIS, Microsoft, IPS, IDS, firewalls
4mo
Save
Mark Applied
Hide
Senior Security Engineer
San Mateo or Columbus or Austin or Remote
$165k-$228k/yr RemoteFull Time
Upstart
UpstartNasdaq: UPST: AI-powered lending marketplace for consumer and automotive loans.
Proven ownership of security initiatives end-to-end, design reviews, threat modeling, and AI-assisted tooling applications.