Lead Security Engineer - Cloud Proxy

JPMorgan Chase JPMorgan Chase · Banking · Plano, TX +1 · Corporate Sector

This role focuses on designing, securing, and operating a cloud network perimeter platform for outbound traffic at an enterprise scale. It involves building and managing infrastructure-as-code, automating processes, and troubleshooting network connectivity issues. The role also involves using enterprise-authorized AI capabilities to assist in security workflows like threat modeling and vulnerability analysis, with a strong emphasis on validating AI outputs and ensuring data sensitivity.

What you'd actually do

  1. Designs, develops, and maintains secure software solutions for cloud network perimeter infrastructure, writing high-quality production code and reviewing code written by others across the full development lifecycle
  2. Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
  3. Builds and manages infrastructure-as-code (IaC) to automate the provisioning, configuration, and scaling of cloud networking and proxy infrastructure in a consistent, repeatable, and auditable manner
  4. Manages and operates enterprise-scale proxy infrastructure, ensuring high availability, performance, and security of egress traffic controls across cloud environments
  5. Develops and maintains automation tooling to streamline network configuration, proxy onboarding workflows, certificate management, and policy enforcement

Skills

Required

  • Formal training or certification in software engineering, security engineering, or network engineering concepts and 5+ years of applied experience in one or more of these disciplines
  • Skilled in planning, designing, and implementing enterprise-level security and/or network solutions within cloud environments
  • Develops secure and high-quality production code and reviews and debugs code written by others, with a focus on cloud network security automation and infrastructure-as-code
  • Minimizes security vulnerabilities by following industry insights and governmental regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls
  • Works with stakeholders and business leaders to understand secure connectivity requirements and recommend appropriate architectural patterns and modifications during periods of vulnerability or change
  • Experience with AWS services including serverless solutions, ECS, EC2, Lambdas, API Gateway, and networking services such as VPCs, Transit Gateway, and PrivateLink
  • Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
  • Good communication skills, teamwork capabilities, and a self-learning attitude
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.

Nice to have

  • Experience with forward or reverse proxy technologies and architectures at enterprise scale (e.g., F5, Squid, Envoy, or equivalent)
  • Hands-on experience with TLS/SSL certificate management, PKI, mTLS, and truststore configuration in cloud-native environments
  • Strong understanding of proxy protocols (HTTP CONNECT, HTTPS, SOCKS5), DNS-based routing, and network egress control patterns
  • Experience effectively communicating with senior business leaders
  • AWS Certifications (e.g., Solutions Architect, Security Specialty, Advanced Networking Specialty)

What the JD emphasized

  • enterprise-scale cloud network perimeter solutions
  • enterprise-scale proxy infrastructure
  • enterprise-authorized AI capabilities