About JPMorganChase and the Team
JPMorganChase is a global leader in financial services, serving millions of clients and many of the world's most prominent corporate, institutional, and government clients. Protecting the firm, its customers, and the integrity of the global financial system is a foundational priority, and the Cybersecurity Operations organization is central to that mission. Within it, the Detection and Response team serves as the front line of the firm's cyber defense, operating a global "follow-the-sun" model that delivers 24/7 monitoring, detection, and response across regions. The London SOC is a critical hub anchoring coverage across EMEA, working seamlessly with partner centers worldwide to ensure continuous, uninterrupted protection.
Role Overview
This is a hands-on detection and response role at the core of the firm's cyber defense operations. The analyst will primarily triage security alerts and investigate cases end-to-end, while contributing to threat hunting, detection engineering, and the adoption of AI-assisted tooling to improve investigative efficiency and accuracy. The position suits a technically strong practitioner who thrives in a fast-paced, high-stakes environment and is motivated by continuous improvement.
Working Model and Schedule
The team operates a follow-the-sun model to guarantee continuous global coverage. Analysts work standard weekday business hours, for the most part, with weekend shift coverage required on a rotational basis approximately once every five (5) weeks. This rotation ensures uninterrupted monitoring and response capability across all time zones and handoff points.
Key Responsibilities
- Triage and analyze security alerts from SIEM, EDR, and other detection tooling, prioritizing based on severity, risk, and business impact.
- Investigate security incidents and cases end-to-end, from initial detection through containment, eradication, and documented resolution.
- Conduct proactive threat hunting across endpoints, networks, cloud, and identity telemetry to identify undetected threats and emerging adversary behavior.
- Contribute to detection engineering: develop, tune, and refine detection rules, use cases, and correlation logic to reduce false positives and improve coverage.
- Leverage AI and automation tooling (e.g., AI-assisted triage, enrichment, and summarization) to accelerate investigations and improve analyst efficiency.
- Document findings, maintain accurate case records, and produce clear incident reports and post-incident reviews.
- Collaborate with global SOC teams, threat intelligence, incident response, and engineering functions to ensure seamless handoffs under the follow-the-sun model.
- Contribute to continuous improvement of SOC playbooks, runbooks, and standard operating procedures.
- Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices.
Required Qualifications, Capabilities, and Skills
- Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ years).
- Solid understanding of security monitoring and investigation across SIEM, EDR/XDR, and network security tooling.
- Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework.
- Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows, Linux).
- Experience investigating alerts across endpoint, network, cloud, and identity/authentication logs.
- Ability to analyze logs, correlate events across multiple data sources, and reconstruct incident timelines.
- Strong written and verbal communication skills for clear documentation and stakeholder updates.
- Ability to work under pressure, prioritize effectively, and participate in weekend shift rotation (approximately once every five weeks).
Preferred Qualifications, Capabilities, and Skills
- Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent).
- Hands-on threat hunting experience using hypothesis-driven methodologies.
- Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling.
- Experience defending large, complex enterprise or financial-services environments.
- Exposure to cloud security monitoring (AWS, Azure, or GCP).
- Knowledge of threat intelligence concepts and integration into detection and response workflows.
Education and Certifications
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- Industry certifications are advantageous, such as: CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA, GDAT), Blue Team Level 1/2 (BTL1/BTL2), CEH, or cloud security certifications (AWS/Azure/GCP security).
Skills Required
- 2+ years of experience in a SOC, incident response, or security analyst role
- Experience with security monitoring and investigation using SIEM, EDR/XDR, and network security tooling
- Knowledge of common attack techniques, the cyber kill chain, and MITRE ATT&CK
- Understanding of TCP/IP, DNS, HTTP/S, proxies, firewalls, Windows, and Linux
- Experience investigating endpoint, network, cloud, and identity or authentication logs
- Ability to analyze logs, correlate events, and reconstruct incident timelines
- Strong written and verbal communication skills
- Ability to work under pressure and participate in weekend shift rotation approximately once every five weeks
- Experience with detection engineering and detection content such as Sigma, YARA, KQL, or SPL
- Hands-on threat hunting experience using hypothesis-driven methodologies
- Familiarity with SOAR platforms, scripting or automation, and AI-assisted security tooling
- Experience defending large, complex enterprise or financial-services environments
- Exposure to AWS, Azure, or GCP security monitoring
- Knowledge of threat intelligence concepts and detection and response integration
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience
- Industry certifications such as CompTIA Security+, CompTIA CySA+, GIAC, BTL1/BTL2, CEH, or cloud security certifications
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery

.png)





