
Senior Lead Cybersecurity Architect - Platform Security
JPMorgan Chase16 hours ago
London, United KingdomStaff+
Responsibilities
- Design and improve security architecture for CI/CD pipelines and DevOps toolchains, embedding automated security checks throughout the delivery lifecycle.
- Lead threat modeling using approaches such as STRIDE-LM and conduct architecture reviews for pipelines, microservices, and cloud-native applications.
- Design and deploy preventive and detective security guardrails across pipelines, cloud environments, and SaaS environments.
- Champion Infrastructure-as-Code, Security-as-Code, Policy-as-Code, security linting, and automated compliance validation.
- Integrate DevSecOps tooling for application, container, image, secrets, and infrastructure security scanning.
- Implement and manage SBOMs to track third-party risk and software supply-chain security.
- Partner with engineering, product, business, vendor, audit, regulatory, and risk stakeholders on security and control initiatives.
- Provide developer-friendly tooling, training, reusable secure patterns, and security culture enablement.
- Use and validate enterprise-authorized AI capabilities for cybersecurity risk analysis and security-control assessment.
- Serve as an escalation point for DevSecOps, change management, IT risk, and cybersecurity issues.
Requirements
- Advanced threat modeling experience for DevOps/CICD pipelines and toolchains, including approaches such as STRIDE-LM.
- Expertise advising on secure pipeline architecture with Policy-as-Code and automated gates.
- Hands-on security experience with AWS and GCP.
- Experience creating reference architectures and engineering patterns.
- Experience designing and deploying automated preventive and detective guardrails at scale.
- Expertise using Infrastructure-as-Code scanning across Terraform and Kubernetes manifests.
- Experience integrating DevSecOps tooling including SAST, SCA, RASP, IAST, container and image scanning, secrets detection, and AI-powered DAST.
- Experience implementing and managing SBOMs for internal, third-party, and supply-chain risk.
- Ability to solve design and functionality problems independently and influence peers and stakeholders.
- Experience using and validating enterprise-authorized AI capabilities in cybersecurity architecture workflows while handling sensitive data appropriately.
- Preferred: mentoring developers, shift-left security evangelism, and translating policy and regulatory requirements into engineering controls.
- Preferred certifications include AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, CISSP, CKS, and OSCP.
- Preferred experience includes regulated organizations using a 3LoD model and financial-services or Fintech consumer businesses.
Benefits
- JPMorganChase describes a dynamic environment for professional growth and collaboration with cybersecurity and engineering talent.
- The role offers global collaboration and exposure to audit, regulatory, risk, cloud, and emerging-technology initiatives.
Categories
About JPMorgan Chase
JPMorgan Chase provides consumer and commercial banking, payments, credit card, wealth management, and corporate and investment banking services to individuals, businesses, institutions, and governments. The public company (NYSE: JPM) earns revenue from interest, fees, trading, and asset management across operations in more than 100 markets. Headquartered in New York City with roots dating to 1799, it serves retail customers and prominent corporate and government clients through brands including Chase and J.P. Morgan.