Senior Devsecops Architect

JPMorgan Chase JPMorgan Chase · Banking · LONDON, United Kingdom · Corporate Sector

Senior DevSecOps Architect role focused on designing and implementing security architecture for CI/CD pipelines and DevOps toolchains within a financial services context. Responsibilities include threat modeling, security-as-code, automated guardrails, and stakeholder partnership to ensure secure product development.

What you'd actually do

  1. Pipeline Security Architecture - Design, implement, and continuously improve security architecture for CI/CD pipelines and DevOps toolchains, ensuring automated security checks are embedded at every stage from code commit to production deployment.
  2. Security-as-Code Leadership - Champion Infrastructure as Code (IaC) and Security-as-Code practices, including policy enforcement, security linting, and automated compliance validation across cloud environments.
  3. Threat Modeling & Architecture Reviews - Lead advanced threat modeling (e.g., STRIDE-LM) for pipelines, microservices, and cloud-native applications, and conduct architecture reviews to drive adoption of secure design patterns.
  4. Automated Guardrails at Scale - Design and deploy automated preventive and detective guardrails to proactively reduce risk across CICD pipelines, cloud and SaaS environments.
  5. Security Culture & Enablement - Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate rather than hinder delivery.

Skills

Required

  • Advanced threat modeling experience (e.g., STRIDE-LM) for DevOps/CICD Pipelines and toolchains.
  • Expert ability to advise and influence secure pipeline architecture using Policy-as-Code and automated gates.
  • Hands-on security expertise in AWS and GCP.
  • Practical experience creating reference architectures and patterns for engineering teams.
  • Proven ability to design and deploy automated preventive and detective guardrails at scale.
  • Expertise in leveraging IaC scanning to detect misconfigurations and compliance violations across Terraform and Kubernetes manifests
  • Hands-on experience in integrating a comprehensive DevSecOps tooling stack, including SAST, SCA, RASP, IAST, container and image scanning, secrets detection, and AI-powered DAST solutions
  • Experience implementing and managing SBOMs to track internal, third-party risk and supply chain security.
  • Ability to solve design and functionality problems independently.
  • Strong written and verbal communication skills.
  • Demonstrated success in influencing peers and stakeholders.
  • Ability to evaluate and recommend emerging technologies for future state architecture.

Nice to have

  • Shift-Left/Start-Left Evangelism - A proven track record of mentoring developers and fostering a culture where security is a shared responsibility
  • Relevant certifications: AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, CISSP, CKS, OSCP.
  • Experience operating in regulated organizations with a 3LoD model.
  • Willingness to challenge existing processes respectfully.
  • Experience translating policy and regulatory requirements into control design for engineers and architects.
  • Proven ability to upskill and learn modern technologies.
  • Experience in financial services consumer businesses or Fintech organizations.

What the JD emphasized

  • Advanced threat modeling experience
  • Expert ability to advise and influence secure pipeline architecture
  • Hands-on security expertise in AWS and GCP
  • Proven ability to design and deploy automated preventive and detective guardrails at scale
  • Hands-on experience in integrating a comprehensive DevSecOps tooling stack
  • Experience operating in regulated organizations