Sr Lead Security Engineer - Hsm Management

JPMorgan Chase JPMorgan Chase · Banking · Seattle, WA +1 · Corporate Sector

Sr Lead Security Engineer focused on Hardware Security Module (HSM) management and cryptographic infrastructure within a financial services company. The role involves designing, implementing, and maintaining secure, scalable, and resilient infrastructure for critical payment and cryptographic operations, with a strong emphasis on security, compliance, and business continuity. The role also involves using enterprise-authorized AI capabilities to assist in security risk analysis and documentation.

What you'd actually do

  1. Lead the architecture, design, and documentation of complex Hardware Security Module and cryptographic infrastructure, ensuring alignment with business, resiliency, and security requirements
  2. Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  3. Design and implement Hardware Security Module solutions, including deployment, configuration, integration, and full lifecycle management across Thales and FutureX platforms
  4. Develop and maintain detailed architectural diagrams, system documentation, and operational runbooks to support operational excellence and knowledge continuity
  5. Collaborate with cross-functional teams to define infrastructure standards, best practices, and security controls that align with firm-wide policies and industry regulations

Skills

Required

  • Formal training or certification on security engineering concepts
  • 5+ years applied experience in security engineering
  • 7 or more years of hands-on engineering experience with Hardware Security Modules
  • Expertise in architecture and system design of highly available infrastructure, disaster recovery, and business continuity strategies
  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Proficient technical troubleshooting skills
  • Strong Linux and Unix administration experience in enterprise environments
  • Strong understanding of cryptographic principles, key management, confidential computing, and secure hardware operations
  • Hands-on experience with OpenSSL and certificate-based authentication mechanisms
  • Expertise in public cloud key management services and cloud-based Hardware Security Module solutions
  • Proficiency in designing and documenting infrastructure architectures using industry-standard tools and methodologies
  • Experience with infrastructure automation tools such as Terraform for managing and scaling secure environments
  • Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Nice to have

  • Experience with network security, firewalls, and secure room operations and key ceremonies
  • Hands-on experience with Splunk or equivalent platforms for infrastructure monitoring and troubleshooting
  • Strong domain knowledge of payment processes and business resiliency applied to infrastructure design
  • Relevant Hardware Security Module platform certifications such as Thales or FutureX credentials
  • Familiarity with broader cybersecurity frameworks and their application to cryptographic and payment infrastructure environments
  • Ability to influence technical direction and drive alignment across organizational boundaries in a large, complex enterprise

What the JD emphasized

  • Hardware Security Module management
  • cryptographic infrastructure
  • secure systems and data
  • Payment Card Industry Data Security Standard
  • Federal Information Processing Standards