JPMorganChase is one of the world's leading financial services firms, with assets exceeding $2 trillion and operations spanning more than 60 countries. We are a global leader in investment banking, consumer and commercial banking, financial transaction processing, and asset management. At JPMorganChase, technology and security aren't just support functions — they are core to how we serve clients, protect the firm, and drive innovation at scale.
As a Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity & Technology Controls group, you will be at the forefront of securing the firm's public cloud adoption — ensuring that cloud platforms, services, and applications are designed, deployed, and operated in a secure and compliant manner. You will partner across engineering, product, and risk teams to embed security into the fabric of cloud architecture, translating complex threat landscapes into actionable, scalable controls. This is a high-impact role where your expertise will directly shape the firm's cloud security posture and resilience.
The Cybersecurity & Technology Controls group proactively and strategically partners with all lines of business to enable them to design, adopt, and integrate appropriate controls — delivering processes and solutions that are efficient, consistent, and automated. Our number one priority is to keep the firm protected, stable, and resilient while enabling the business to move forward with confidence.
Job responsibilities
- Partner with stakeholders across product, engineering, and risk and controls teams to understand firm control requirements, recommend implementations across a broad range of cloud architectures, and ensure secure-by-design principles are embedded throughout
- Develop, plan, and execute hypothesis-driven, cloud-focused threat hunts, translating findings into actionable security outcomes including detection rules, alert tuning, and compensating controls
- Apply specialized tooling to query, analyze, correlate, and interpret large datasets to identify potential threats and emerging risk patterns
- Deliver threat models and risk-based assessments of cloud services, cloud platforms, and cloud-based applications to inform architecture and engineering decisions
- Perform security reviews of infrastructure-as-code for cloud platform development, ensuring alignment with firm standards and industry best practices
- Develop preventive and detective controls to enforce control requirements across cloud environments at enterprise scale
- Interface with broader cybersecurity teams to ensure platform integration with security operations, threat intelligence, and incident response — operationalizing detections, improving triage playbooks, and supporting cloud threat investigations
- Provide expert guidance on the cloud threat landscape, adversary tradecraft, and emerging risks to inform strategic security decisions
- Contribute to documentation and agile processes in support of security programs, driving consistency and repeatability across the team
Required qualifications, capabilities, and skills
- Formal training or certification on cybersecurity concepts and 5+ years applied experience (e.g., Security+, CEH, CCSP, CISSP, or equivalent)
- Hands-on cloud-native experience across one or more major cloud platforms (AWS, Azure, or Google Cloud), including relevant cloud security certification
- Demonstrated experience with threat modeling methodologies and delivering risk-based security assessments
- Experience with cloud security posture management tooling (e.g., Wiz, Prisma Cloud, CrowdStrike Falcon, or equivalent)
- Knowledge of infrastructure-as-code frameworks (e.g., Terraform, CloudFormation, or equivalent) and their security implications
- Ability to lead cross-functional security initiatives and drive outcomes without direct authority
- Strong prioritization skills with a risk-based approach to decision-making across competing demands
- Ability to think beyond conventional approaches to build innovative solutions and break down complex technical problems
Preferred qualifications, capabilities, and skills
- Experience in offensive security disciplines including penetration testing, red teaming, or purple teaming
- Proficiency with at least one query language used for threat detection and hunting (e.g., KQL, Splunk SPL, or SQL), with comfort working across large and complex datasets
- Experience working within agile delivery frameworks and contributing to security program documentation at an enterprise level
#CTC
About UsWe offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Skills Required
- Formal cybersecurity training or certification, such as Security+, CEH, CCSP, CISSP, or equivalent
- 5+ years of applied cybersecurity experience
- Hands-on cloud-native experience with AWS, Azure, or Google Cloud
- Relevant cloud security certification
- Experience with threat modeling methodologies and risk-based security assessments
- Experience with cloud security posture management tools such as Wiz, Prisma Cloud, or CrowdStrike Falcon
- Knowledge of infrastructure-as-code frameworks such as Terraform or CloudFormation and their security implications
- Ability to lead cross-functional security initiatives without direct authority
- Strong prioritization and risk-based decision-making skills
- Ability to develop innovative solutions and solve complex technical problems
- Experience in penetration testing, red teaming, or purple teaming
- Proficiency with a threat detection and hunting query language such as KQL, Splunk SPL, or SQL
- Experience with agile delivery frameworks and enterprise security program documentation
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery








