Head of Security Engineering & Products

JPMorgan Chase & Co.

Head of Security Engineering & Products

Salary Not Specified

JPMorgan Chase & Co., City of Westminster

  • Full time
  • Permanent
  • Onsite working

Posted 2 weeks ago, 3 May | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: a024b61e91a94ad6baa0054e2b37c82f

Full Job Description

As a Head of Security Engineering & Products at JPMorgan Chase you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects - and depending on your strengths and interests, you'll have the opportunity to move between them.

While we're looking for professional skills, culture is just as important to us. We understand that everyone's unique - and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference - on us as a company, and on our clients and business partners around the world,

  • Understand complex regulatory and internal security requirements and be able to advise on implementation options

  • Guide & defining the security practices & standards end-to-end, covering external connectivity and internal service communication

  • Interact with 3rd party vendors on security-related aspects during onboarding

  • Interact with senior internal stakeholders - internal auditors, firmwide controls, etc

  • Review & constantly improve existing security practices and standards

  • Provide security architecture review with focus on threat modelling

  • Embed threat modelling, solutions architecture, secure code review into product and application teams so they are secure from the start and compliant with risk policies and regulatory obligations., Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.

    Experience deploying and managing security tools

  • Experience understanding security requirements in order to set policies within security tools

  • Tool expertise:

  • + Container security
    + Vulnerability Management tools
    + SAST
  • Extensive experience in a technical security engineering role (encryption, cryptography authorization, authentication, etc)

  • Experience with at least one high-level programming language (Java, Python, etc)

  • Excellent knowledge of security best practices at different stages of the development lifecycle

  • Excellent knowledge of methods for authentication, authorization and encryption (AuthN/Z, JWT, RBAC, TLS, OAuth2)

  • Excellent knowledge of all of the above concepts in the context of at least one (ideally more!) public cloud provider (AWS,GCP,Azure)

  • Experience of procuring security vendors and lifecycle management

  • Understanding of modern SDLC practices and security aspects & tools of CI/CD pipelines (code scanning, container scanning)


  • #ICBCareer

    J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.