Lead Cloud Security Engineer

Posted An Hour Ago
Be an Early Applicant
3 Locations
Hybrid
Entry level
Financial Services
We’re one of the world’s biggest technology-driven companies
The Role
Leads cloud security strategy and control design across AWS, Azure, and GCP. Establishes policy-as-code guardrails, secures infrastructure-as-code pipelines, manages cloud risk, and drives automation, governance, audit readiness, incident preparedness, and remediation. Partners with senior stakeholders, oversees security tooling and vendor evaluations, reports control effectiveness, and mentors a matrixed team of security engineers and risk analysts.
Summary Generated by Built In

Join us to make a meaningful impact on the security of our global cloud infrastructure. As a Lead Cloud Security Engineer, you will help shape the future of cybersecurity and technology controls at JPMorgan Chase & Co. You’ll collaborate with talented professionals, drive innovation, and advance your career in a dynamic environment. We value your expertise and commitment to continuous improvement. Experience the opportunity to lead, mentor, and influence the direction of cloud security.


As a Lead Cloud Security Engineer in the Cybersecurity & Technology Controls Product Security team aligned to the Azure Cloud programme, you will ensure public cloud adoption is secure and compliant. You will identify and manage risk-related issues, partner with senior leaders, and drive automation of controls. Your role is pivotal in keeping the firm protected, stable, and resilient. You will contribute to a culture of ownership and continuous improvement.

Job Responsibilities:

  • Contribute to the evolution of a multi-year information risk and control strategy for public cloud, setting vision, OKRs, and KRIs that align with enterprise risk appetite, policies, and regulatory expectations.
  • Use enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
  • Lead risk-based design and assessment of security controls across cloud services, platforms, and reference architectures; establish standardized control baselines and reusable patterns for AWS, Azure, and GCP.
  • Chair or co-chair governance forums, make informed risk acceptance decisions, and drive timely remediation, deviation tracking, and benefits realization.
  • Partner with senior leaders across engineering, product, and risk to embed “security by design,” ensuring deep integration with security operations, threat intelligence, IAM, network security, and data protection.
  • Set the operating model for infrastructure as code security: define guardrails, policy as code, and automated pre-commit/pre-deploy controls; oversee security reviews for Terraform and platform engineering pipelines.
  • Establish and maintain authoritative documentation, standards, and playbooks; implement agile delivery mechanisms for security programs at scale.
  • Build, mentor, and lead a high-performing matrixed team of security engineers and risk analysts; develop talent, clarify accountabilities, and cultivate a culture of ownership and continuous improvement.
  • Define and report control effectiveness and residual risk through executive-ready dashboards; brief senior stakeholders, audit, and regulators; ensure audit readiness and sustainable evidence practices.
  • Drive the tooling and automation strategy for cloud security, including build vs buy evaluations, vendor management, and integration with existing telemetry and SOAR platforms.
  • Strengthen cloud incident preparedness and response by leading threat modeling, tabletop exercises, and post-incident reviews that translate lessons learned into control enhancements.
  • Apply reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.

Required Qualifications, Capabilities, and Skills:

  • Formal training or certification on security engineering concepts and advanced applied experience.
  • Skilled in planning, designing, and implementing enterprise-level security solutions.
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Advanced in one or more programming languages.
  • Proficient across SDLC execution, including agile methodologies such as CI/CD, application resiliency, and security.
  • Experience with threat modeling, discovery, vulnerability, and penetration testing.

Preferred Qualifications, Capabilities, and Skills:

  • Deep expertise securing public cloud at scale, spanning identity and access management, network segmentation, data protection, logging/monitoring, and native cloud services across AWS, Azure, and/or GCP.
  • Proven leadership of cross-functional security programs with measurable outcomes; adept at influencing VP+ stakeholders and navigating complex prioritization across multiple platforms and business lines.
  • Exceptional executive communication and stakeholder management skills, including experience engaging internal audit and external regulators with clear narratives, metrics, and remediation roadmaps.
  • Demonstrated ability to translate policy and risk requirements into practical designs and policy as code guardrails that balance delivery velocity with control effectiveness.
  • Hands-on familiarity with Terraform and infrastructure as code security, DevSecOps and CI/CD concepts, and enforcement frameworks within modern development workflows.
  • Strong program execution under tight timelines; highly self-directed with a bias for action, ownership, and outcome orientation.
  • Advanced cloud and security certifications are a plus; experience deploying and operating CSPM/CIEM/CWPP solutions is advantageous.

 

About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Skills Required

  • Formal training or certification in security engineering concepts with advanced applied experience
  • Experience planning, designing, and implementing enterprise-level security solutions
  • Experience using enterprise-authorized AI capabilities in security engineering workflows with strong validation and data-sensitivity awareness
  • Ability to review and validate AI-assisted code and security recommendations before adoption
  • Advanced proficiency in one or more programming languages
  • Proficiency across SDLC execution, including agile methodologies, CI/CD, application resiliency, and security
  • Experience with threat modeling, discovery, vulnerability assessment, and penetration testing
  • Deep expertise securing public cloud environments at scale across identity, network segmentation, data protection, logging, monitoring, and native cloud services
  • Leadership experience managing cross-functional security programs with measurable outcomes and influencing senior stakeholders
  • Executive communication and stakeholder management experience with internal audit and external regulators
  • Ability to translate policy and risk requirements into practical designs and policy-as-code guardrails
  • Hands-on familiarity with Terraform, infrastructure-as-code security, DevSecOps, CI/CD, and enforcement frameworks
  • Strong program execution under tight timelines with self-direction, ownership, and outcome orientation
  • Advanced cloud and security certifications
  • Experience deploying and operating CSPM, CIEM, or CWPP solutions

JPMorganChase Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.

  • Healthcare Strength Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
  • Parental & Family Support Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
  • Retirement Support Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.

JPMorganChase Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
289,097 Employees
Year Founded: 1799

What We Do

JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.

Why Work With Us

Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.

Gallery

Gallery

Similar Jobs

Hybrid
2 Locations
289097 Employees

Pfizer Logo Pfizer

Sustainability Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
30 Locations
121990 Employees
112K-207K Annually

Pfizer Logo Pfizer

Energy & Utilities Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
Grange, Ballyboughal, Dublin, IRL
121990 Employees

ServiceNow Logo ServiceNow

Senior Director, CEG EMEA Field Ops Lead

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Dublin, IRL
29000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account