At a Glance
- Tasks: Lead security initiatives, ensuring secure product development and risk reduction.
- Company: Join JPMorgan Chase's innovative team focused on customer-centric products.
- Benefits: Competitive salary, skill development, and a diverse, collaborative culture.
- Why this job: Make a real impact in fintech while working with cutting-edge technology.
- Qualifications: Experience in security engineering and a passion for collaboration.
- Other info: Dynamic environment with opportunities for growth and learning.
The predicted salary is between 36000 - 60000 £ per year.
Originating from Chase in 2021, we are a team dedicated to creating customer-centric products. Our success relies on collaboration, curiosity, and commitment, nurtured in an environment promoting skill development. As a Lead Security Engineer at JPMorgan Chase within the accelerator program, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects – and depending on your strengths and interests, you'll have the opportunity to move between them. While we’re looking for professional skills, culture is just as important to us. We understand that everyone's unique – and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference – on us as a company, and on our clients and business partners around the world.
Job responsibilities
- Cultivate security culture
- Work with Product and Engineering colleagues, be the security champion that strives to prioritize sustainable controls and driving real risk reduction outcomes.
- Build secure products ensure security is considered throughout the Product and Software Development Life Cycle.
- Provide security best practice, build security design patterns, complete security architecture reviews, threat models and risk assessments.
- Help solve engineering problems by implementing technical controls to mitigate risk.
- Ensure security thought leadership
- Keep up on security best practice and be a continuous learner.
- Guide and define our security practices and standards end-to-end, be recognized as a point of escalation and subject matter expert for IT Risk and Cyber domains.
- Work together with product and engineering, help to solve problems and not just calling out issues.
- Operate within a larger business and align with the wider security function across JPMC.
- Ensure we are deploying products into a secure environment aligning with the FIRM control requirements, supporting ongoing business-as-usual, vulnerability management, internal security consultancy, audit and regulatory engagements, risk activities and project initiatives.
- Work closely with Third Party Oversight teams to ensure effective technology risk management, with a focus on Cloud computing / emerging technologies.
Required qualifications, capabilities and skills
- Formal training or certification on security engineering concepts and applied experience
- Extensive experience in an engineering role with heavy focus on security.
- Excellent knowledge of best-practices for securing Micro-service architectures.
- Excellent knowledge of securing Kubernetes environments.
- Excellent knowledge of methods for authentication, authorization (ODIC, OAuth 2, FIDO 2 .etc..)
- Excellent knowledge of modern SDLC practices with a focus on embedding security into CI/CD pipelines.
- Excellent knowledge of all of the above concepts in the context of at least one (ideally more!) public cloud provider (AWS,GCP,Azure)
- A desire to teach others and share knowledge.
- We aren’t looking for hero engineers, we look for team players. We want you to coach other team members on security coding practices, design principles, and implementation patterns.
- Comfortable in uncharted waters. We are building something new. Things change quickly. We need you to learn technologies and patterns quickly.
- Ability to see the long term. We don’t want you to sacrifice the future for the present. We want you to choose technologies and approaches based on the end goals.
- Clarity of thought. We operate quickly and efficiently, and we value people who are economical with their time and clear with their opinions.
Preferred qualifications, capabilities and skills
- Understanding of applied cryptography - symmetric/asymmetric cryptography, Certificate management.
- Knowledge of offensive security, Application and Infrastructure penetration testing (OWASP top 10, OWASP ASVS)
- Understanding of security vulnerabilities and remediation options in codebases (Java/Kotlin/etc) & containers
- Excellent knowledge of security/identity SaaS vendors (Auth0, Forgerock, Keycloak)
Product Security Lead Software Engineer employer: Jpmorgan Chase & Co.
Contact Detail:
Jpmorgan Chase & Co. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Product Security Lead Software Engineer
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the fintech space. Attend meetups, webinars, or even just grab a coffee with someone in the industry. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering. This gives potential employers a taste of what you can do and how you think, which is super important in a collaborative environment.
✨Tip Number 3
Prepare for interviews by diving deep into the company’s culture and values. Understand their approach to security and product development. When you can speak their language and align your experiences with their goals, you’ll stand out as a candidate who truly gets it.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search. So, get that application in and let’s make some magic happen!
We think you need these skills to ace Product Security Lead Software Engineer
Some tips for your application 🫡
Show Your Passion for Security: When writing your application, let your enthusiasm for security shine through! Share specific examples of how you've championed security in past projects and how you stay updated with the latest trends. We love candidates who are genuinely curious and eager to learn.
Tailor Your Application: Make sure to customise your application to highlight your experience with micro-service architectures and Kubernetes environments. We want to see how your skills align with our needs, so don’t be shy about showcasing relevant projects or achievements!
Be Clear and Concise: We appreciate clarity in communication, so keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to see your qualifications and experiences at a glance. Remember, less is often more!
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team!
How to prepare for a job interview at Jpmorgan Chase & Co.
✨Know Your Stuff
Make sure you brush up on your security engineering concepts and best practices. Familiarise yourself with securing micro-service architectures and Kubernetes environments, as well as authentication methods like OAuth 2 and FIDO 2. Being able to discuss these topics confidently will show that you're not just a candidate, but a potential security champion.
✨Show Your Collaborative Spirit
Since the role emphasises teamwork, be ready to share examples of how you've worked in squads or tribes before. Highlight your experiences where you’ve solved problems collaboratively, rather than just pointing out issues. This will demonstrate that you’re a team player who aligns with their culture of collaboration.
✨Embrace Continuous Learning
The company values a curious mindset, so come prepared to discuss how you keep up with the latest security trends and technologies. Mention any recent courses, certifications, or projects that showcase your commitment to learning and adapting in the fast-paced world of fintech.
✨Think Long-Term
During the interview, articulate your vision for security in product development. Discuss how you would choose technologies and approaches based on long-term goals rather than short-term fixes. This clarity of thought will resonate well with their desire for candidates who can see the bigger picture.