At a Glance
- Tasks: Join our Purple Team to analyse, design, and deliver cybersecurity solutions.
- Company: Be part of JPMorgan Chase, a global tech leader investing over $9.5B annually in innovation.
- Benefits: Enjoy competitive health coverage, retirement plans, wellness programs, and opportunities for professional growth.
- Why this job: Work on the front lines of cybersecurity, making a real impact in a dynamic environment.
- Qualifications: Requires a BS/BA degree, 3+ years in cloud security, and knowledge of cybersecurity practices.
- Other info: Access to High Security Access systems may be required, subject to background checks.
The predicted salary is between 48000 - 72000 ÂŁ per year.
Job Summary
Working in Cybersecurity takes pure passion for technology, speed, a constant desire to learn, and above all, vigilance in keeping every last asset safe and sound. You\’ll be on the front lines of innovation, working with a highly-motivated team laser-focused on analyzing, designing, developing and delivering solutions built to stop adversaries and strengthen our operations. Your research and work will ensure stability, capacity and resiliency of our products and emerging industry trends. Working in tandem with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop adversaries and strengthen our data. JPMC\’s Assurance Operations organization is looking to expand its Purple Team with an experienced Purple Team Operator with particular specialties in supporting \”Purple Team\” engagements and operating in \”cloud-based\” environments.
Role Focus
The primary focus of this role will be to jointly collaborate with the firm\’s Cybersecurity Operations Center (SOC) to perform hands‑on offensive activities and research as part of \”Purple Team\” engagements. The successful candidate will have a proven track record in conducting network exploitation operations, to include Red Team and Purple Team assessments. Additionally, the candidate will be able to demonstrate in-depth knowledge and experience around computer networking fundamentals, modern threats and vulnerabilities, attack methodologies, incident response, threat hunting, and penetration testing tools. This position is anticipated to require the use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
Key Qualifications & Experience
- BS/BA degree or equivalent experience.
- Excellent command of Cybersecurity organization practices, operations risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies.
- Ability to analyze vulnerabilities, threats, designs, procedures and architectural design, producing reports and sharing intelligence.
- 3+ years of Information Security experience in cloud-based environments (Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) in both private and public (AWS, Azure) environments) and in one or more of the following verticals: network penetration testing, application (web, mobile) penetration testing, Red Team/Purple Team operations, application security assessments, and network exploitation operations. Candidate should have the ability to perform targeted, covert penetration tests with vulnerability identification, exploitation, and post‑exploitation activities with no or minimal use of automated tools.
- Strong understanding of the following: Windows/Linux/Unix/Mac operating systems; OS and software vulnerability and exploitation techniques; commercial or open‑source offensive security tools for reconnaissance, scanning, exploitation, and post‑exploitation (e.g. Cobalt Strike, Metasploit, Burp Suite); networking fundamentals (all OSI layers, protocols); Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) providers in both private and public (AWS, Azure) environments; DevOps; incident response; threat hunting; and familiarity with interpreting log output from networking devices, operating systems, and infrastructure services.
- Preferred qualifications include: Intelligence Community/Security Services background, relevant certifications such as those offered by Offensive Security (OSCP, OSEP, OSED, OSEE, OSCE), CREST (Certified Simulated Attack Specialist, Registered Penetration Tester, Certified Infrastructure Tester), SANS (GPEN, GXPN, GWAPT), knowledge of malware packing, obfuscation, persistence, exfiltration techniques, and understanding of financial sector or other large security and IT infrastructures.
- Technical knowledge or experience developing proof‑of‑concept exploits and in‑house scripting, using interpreted languages such as Python, Ruby, or Perl, compiled languages such as C, C++, C#, or Java, and security tools or technology such as Firewalls, IDS/IPS, Web Proxies, DLP and the ability to articulate and visually present complex penetration testing and Red Team/Purple Team results is highly desirable.
- Ability to collaborate with high‑performing teams and individuals throughout the firm to accomplish common goals.
- Experience with Agile and can work with at least one of the common frameworks is highly desired.
Company & Benefits
When you work at JPMorgan Chase & Co., you\’re not just working at a global financial institution. You\’re an integral part of one of the world\’s biggest tech companies. In 14 technology hubs worldwide, our team of 40,000+ technologists design, build and deploy everything from enterprise technology initiatives to big data and mobile solutions, as well as innovations in electronic payments, cybersecurity, machine learning, and cloud development. Our $9.5B+ annual investment in technology enables us to hire people to create innovative solutions that will not only transform the financial services industry, but also change the world. At JPMorgan Chase & Co. we value the unique skills of every employee, and we\’re building a technology organization that thrives on diversity. We encourage professional growth and career development, and offer competitive benefits and compensation. If you\’re looking to build your career as part of a global technology team tackling big challenges that impact the lives of people and companies all around the world, we want to meet you.
#J-18808-Ljbffr
Purple Team Senior Operator employer: Jpmorgan Chase & Co.
Contact Detail:
Jpmorgan Chase & Co. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Purple Team Senior Operator
✨Tip Number 1
Familiarise yourself with the latest trends in cybersecurity, especially in cloud environments like AWS and Azure. This knowledge will not only help you during interviews but also demonstrate your passion for the field.
✨Tip Number 2
Engage with online communities and forums related to Purple Team operations. Networking with professionals in the field can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Consider participating in Capture The Flag (CTF) competitions or similar challenges that focus on penetration testing and threat hunting. These experiences can enhance your skills and make you stand out as a candidate.
✨Tip Number 4
Stay updated on the latest security tools and techniques used in Red and Purple Team assessments. Being knowledgeable about current tools will show your commitment to continuous learning and improvement.
We think you need these skills to ace Purple Team Senior Operator
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, particularly in Purple Team operations and cloud security. Use specific examples to demonstrate your skills in network exploitation and incident response.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for technology and your understanding of the role. Mention your experience with offensive activities and how you can contribute to the Purple Team's objectives.
Highlight Relevant Certifications: If you have any security certifications like OSCP or CREST, be sure to mention them prominently in your application. These credentials can set you apart from other candidates.
Showcase Your Collaborative Skills: Since the role involves working within Agile frameworks, include examples of past teamwork experiences. Highlight how you’ve successfully collaborated with others in high-pressure environments.
How to prepare for a job interview at Jpmorgan Chase & Co.
✨Showcase Your Technical Skills
Make sure to highlight your experience with cloud security, penetration testing, and Red/Purple Team operations. Be prepared to discuss specific tools and techniques you've used in past roles, as this will demonstrate your hands-on expertise.
✨Understand the Company’s Cybersecurity Landscape
Research JPMorgan Chase & Co.'s approach to cybersecurity and their recent initiatives. This knowledge will help you tailor your responses and show that you're genuinely interested in contributing to their mission.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Practice articulating how you would handle specific threats or vulnerabilities, as this will showcase your analytical thinking and practical experience.
✨Emphasise Collaboration and Agile Experience
Since the role involves working within Agile frameworks, be ready to discuss your experience collaborating with teams. Highlight any projects where you successfully worked with others to achieve a common goal, especially in high-pressure situations.