Description
Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies.
As a Lead Security Engineer at JPMorgan Chase within the CTC CyberOps EDR Engineering team, you are an integral part of team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for developing and delivering out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions.
Job responsibilities
Conducts discovery, vulnerability, penetration testing, and threat scenarios on multiple organizational assets to identify and assess if vulnerabilities are present, and executes threat modeling for multiple applications including external applications interacting with the internal JPMorgan Chase network
Collaborates with multiple teams to understand platform requirements and streamline engineering and deployment processes
Supports Cyber Security Operations Center (SOC) and Attack Analysis teams in identifying and mitigating threats to digital assets
Assists Vulnerability Management teams in evaluating the impact of vulnerabilities on organizational assets
Partners with RED and PenTest teams to assess and enhance the security posture of the firm by enabling them to leverage features of Endpoint Detection and Response (EDR) platforms
Partners with Threat Intelligence teams to enable them to correlate threat data with endpoint security controls, facilitating prioritized remediation efforts
Integrates EDR solutions with several allied systems including SIEM platforms in the firm to ensure ingestion of detections, logs, telemetry
Partners with platform Engineering teams to Integrate EDR products in various disparate build pipelines in the firm across various operating systems and cloud platforms
Collaborates with product owners and stakeholders to gather requirements, design solutions, and implement software through CI/CD pipelines
Provides Level 3 Support for thorough investigations and issue resolution on target endpoints
Engages in Proof of Concepts (PoCs) to evaluate new features and capabilities for expanding the Endpoint Visibility Program
Required qualifications, capabilities, and skills
Formal training or certification on Security Engineering concepts and 5+ years applied experience
Skilled in planning, designing, and implementing enterprise level security solutions
Advanced in one or more programming language(s) such as Python, Shell, PowerShell, Ansible, React
Proficient in all aspects of the Software Development Life Cycle and advanced understanding of agile methodologies such as CI/CD, application resiliency, and security
Experience with threat modeling, discovery, vulnerability, and penetration testing
Expertise in orchestration and automation platforms such as SCCM, Puppet or similar
Expertise in cyber security endpoint security and vulnerability management domains
In-depth understanding of and experience in public cloud technology such as AWS, Azure, GCP and in Virtualization, APIs
In-depth expertise in AWS development and Infrastructure track and tech stack such as networking, EC2, Lambdas, server-less solutions, VPC, routes53, auto scaling, Transit Gateway, API Gateway, Step Functions, secrets manager and storage services
In-depth knowledge of the financial services industry and their IT systems
Ability to collaborate with different roles and personas to achieve common goals
Preferred qualifications, capabilities, and skills
Experience effectively communicating with senior business leaders
Experience in products such as CrowdStrike Falcon XDR and Palo Alto Cortex XDR