NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
9 days ago
Apply with autofill
Apply with autofill
JPMorgan Chase·BFSI·9 days ago
9 days ago

Lead Security Engineer - Cloud Threat Hunting

OH, United StatesFull-timeMid · 5+ yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at JPMorgan Chase

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

Must-have skills for this role

  • aws
  • azure
  • google cloud
  • threat hunting

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Partner with stakeholders across product, engineering, and risk and controls teams to understand firm control requirements, recommend implementations across a broad range of cloud architectures, and ensure secure-by-design principles are embedded throughout
  • Develop, plan, and execute hypothesis-driven, cloud-focused threat hunts, translating findings into actionable security outcomes including detection rules, alert tuning, and compensating controls
  • Apply specialized tooling to query, analyze, correlate, and interpret large datasets to identify potential threats and emerging risk patterns
  • Deliver threat models and risk-based assessments of cloud services, cloud platforms, and cloud-based applications to inform architecture and engineering decisions
  • Perform security reviews of infrastructure-as-code for cloud platform development, ensuring alignment with firm standards and industry best practices
  • Develop preventive and detective controls to enforce control requirements across cloud environments at enterprise scale
  • Interface with broader cybersecurity teams to ensure platform integration with security operations, threat intelligence, and incident response — operationalizing detections, improving triage playbooks, and supporting cloud threat investigations
  • Provide expert guidance on the cloud threat landscape, adversary tradecraft, and emerging risks to inform strategic security decisions
  • Contribute to documentation and agile processes in support of security programs, driving consistency and repeatability across the team

What they're looking for

  • Formal training or certification on cybersecurity concepts and 5+ years applied experience (e.g., Security+, CEH, CCSP, CISSP, or equivalent)
  • Hands-on cloud-native experience across one or more major cloud platforms (AWS, Azure, or Google Cloud), including relevant cloud security certification
  • Demonstrated experience with threat modeling methodologies and delivering risk-based security assessments
  • Experience with cloud security posture management tooling (e.g., Wiz, Prisma Cloud, CrowdStrike Falcon, or equivalent)
  • Knowledge of infrastructure-as-code frameworks (e.g., Terraform, CloudFormation, or equivalent) and their security implications
  • Ability to lead cross-functional security initiatives and drive outcomes without direct authority
  • Strong prioritization skills with a risk-based approach to decision-making across competing demands
  • Ability to think beyond conventional approaches to build innovative solutions and break down complex technical problems

Nice to have

  • Experience in offensive security disciplines including penetration testing, red teaming, or purple teaming
  • Proficiency with at least one query language used for threat detection and hunting (e.g., KQL, Splunk SPL, or SQL), with comfort working across large and complex datasets
  • Experience working within agile delivery frameworks and contributing to security program documentation at an enterprise level

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

JPMorganChase is one of the world's leading financial services firms, with assets exceeding $2 trillion and operations spanning more than 60 countries. We are a global leader in investment banking, consumer and commercial banking, financial transaction processing, and asset management. At JPMorganChase, technology and security aren't just support functions — they are core to how we serve clients, protect the firm, and drive innovation at scale.

As a Lead Cybersecurity Architect at JPMorganChase within the Cybersecurity & Technology Controls group, you will be at the forefront of securing the firm's public cloud adoption — ensuring that cloud platforms, services, and applications are designed, deployed, and operated in a secure and compliant manner. You will partner across engineering, product, and risk teams to embed security into the fabric of cloud architecture, translating complex threat landscapes into actionable, scalable controls. This is a high-impact role where your expertise will directly shape the firm's cloud security posture and resilience.

The Cybersecurity & Technology Controls group proactively and strategically partners with all lines of business to enable them to design, adopt, and integrate appropriate controls — delivering processes and solutions that are efficient, consistent, and automated. Our number one priority is to keep the firm protected, stable, and resilient while enabling the business to move forward with confidence.


Job responsibilities

  • Partner with stakeholders across product, engineering, and risk and controls teams to understand firm control requirements, recommend implementations across a broad range of cloud architectures, and ensure secure-by-design principles are embedded throughout
  • Develop, plan, and execute hypothesis-driven, cloud-focused threat hunts, translating findings into actionable security outcomes including detection rules, alert tuning, and compensating controls
  • Apply specialized tooling to query, analyze, correlate, and interpret large datasets to identify potential threats and emerging risk patterns
  • Deliver threat models and risk-based assessments of cloud services, cloud platforms, and cloud-based applications to inform architecture and engineering decisions
  • Perform security reviews of infrastructure-as-code for cloud platform development, ensuring alignment with firm standards and industry best practices
  • Develop preventive and detective controls to enforce control requirements across cloud environments at enterprise scale
  • Interface with broader cybersecurity teams to ensure platform integration with security operations, threat intelligence, and incident response — operationalizing detections, improving triage playbooks, and supporting cloud threat investigations
  • Provide expert guidance on the cloud threat landscape, adversary tradecraft, and emerging risks to inform strategic security decisions
  • Contribute to documentation and agile processes in support of security programs, driving consistency and repeatability across the team

Required qualifications, capabilities, and skills

  • Formal training or certification on cybersecurity concepts and 5+ years applied experience (e.g., Security+, CEH, CCSP, CISSP, or equivalent)
  • Hands-on cloud-native experience across one or more major cloud platforms (AWS, Azure, or Google Cloud), including relevant cloud security certification
  • Demonstrated experience with threat modeling methodologies and delivering risk-based security assessments
  • Experience with cloud security posture management tooling (e.g., Wiz, Prisma Cloud, CrowdStrike Falcon, or equivalent)
  • Knowledge of infrastructure-as-code frameworks (e.g., Terraform, CloudFormation, or equivalent) and their security implications
  • Ability to lead cross-functional security initiatives and drive outcomes without direct authority
  • Strong prioritization skills with a risk-based approach to decision-making across competing demands
  • Ability to think beyond conventional approaches to build innovative solutions and break down complex technical problems

Preferred qualifications, capabilities, and skills

  • Experience in offensive security disciplines including penetration testing, red teaming, or purple teaming
  • Proficiency with at least one query language used for threat detection and hunting (e.g., KQL, Splunk SPL, or SQL), with comfort working across large and complex datasets
  • Experience working within agile delivery frameworks and contributing to security program documentation at an enterprise level


#CTC

BFSI

Company

JPMorgan ChaseBFSI
OH, United States

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from JPMorgan Chase's careers site·first seen 11 Sept 2026·last verified 11 Sept 2026·How we source jobs

Similar jobs

  • Staff Security Engineer at robotsandpencilsUS - Remote–match not yet calculated
  • IT Security Engineer at zollChelmsford, United States of America–match not yet calculated
  • Cybersecurity Summer 2027 Intern (Undergraduate) at centeneRemote-MO–match not yet calculated
  • AI Security Engineer at trimbleUS - Remote, CO–match not yet calculated
  • Medical Device Cybersecurity Co-Op at Johnson & JohnsonDanvers, United States of America–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom