Security Engineer [multiple Positions Available]

JPMorgan Chase JPMorgan Chase · Banking · Plano, TX +1 · Corporate Sector

This role focuses on designing and implementing enterprise cybersecurity controls across cloud and hybrid environments, securing CI/CD pipelines, automating security and compliance policies, and developing automation for vulnerability remediation and monitoring. It requires experience with various security tools and frameworks to assess and improve risk posture.

What you'd actually do

  1. Design enterprise cybersecurity controls across cloud and hybrid environments.
  2. Secure CI/CD pipelines and containerized applications.
  3. Automate runtime security and compliance policies for serverless applications.
  4. Implement infrastructure as code practices to support scalable and secure deployments.
  5. Lead security integrations into centralized monitoring systems and build real-time threat correlation rules.

Skills

Required

  • designing and enforcing security controls
  • network segmentation
  • automated compliance using CNAP platforms including Wiz.io in a public cloud environment
  • conducting threat modeling and risk assessment using ThreatModeler to identify attack vectors, quantify business impact, and define mitigation strategies before deployment
  • performing threat hunting and developing custom detection rules using CrowdStrike EDR and NG-SIEM to protect advanced users and close visibility gaps across endpoints, networks, and cloud workloads
  • implementing vulnerability management using Tenable agents to triage, prioritize, and remediate critical flaws in cloud environments to meet SLAs and minimize exposure windows
  • designing data pipelines for SIEM ingestion
  • performing security metric analytics to report MTTD and MTTR across detection and response functions
  • designing automation workflows using Jenkins to embed security into CI/CD pipeline scans, enforce quality gates, and automate drift detection before deployments

What the JD emphasized

  • designing and enforcing security controls
  • network segmentation
  • automated compliance using CNAP platforms including Wiz.io in a public cloud environment
  • conducting threat modeling and risk assessment using ThreatModeler to identify attack vectors, quantify business impact, and define mitigation strategies before deployment
  • performing threat hunting and developing custom detection rules using CrowdStrike EDR and NG-SIEM to protect advanced users and close visibility gaps across endpoints, networks, and cloud workloads
  • implementing vulnerability management using Tenable agents to triage, prioritize, and remediate critical flaws in cloud environments to meet SLAs and minimize exposure windows
  • designing data pipelines for SIEM ingestion
  • performing security metric analytics to report MTTD and MTTR across detection and response functions
  • designing automation workflows using Jenkins to embed security into CI/CD pipeline scans, enforce quality gates, and automate drift detection before deployments