
Lead Cloud Security Engineer
JPMorgan Chase15 hours ago
Dublin, IrelandStaff+
Responsibilities
- Develop the multi-year public-cloud information-risk and control strategy, including vision, OKRs, KRIs, policies, and regulatory alignment.
- Lead risk-based design and assessment of security controls and establish reusable baselines and patterns across AWS, Azure, and GCP.
- Chair governance forums, make risk-acceptance decisions, and drive remediation, deviation tracking, and benefits realization.
- Define infrastructure-as-code security guardrails, policy-as-code controls, and automated pre-commit and pre-deploy checks, including Terraform reviews.
- Build, mentor, and lead a matrixed team of security engineers and risk analysts.
- Define control-effectiveness and residual-risk reporting for senior stakeholders, audit, and regulators.
- Drive cloud-security tooling, automation, vendor, and integration strategies, including telemetry and SOAR platforms.
- Lead threat modeling, tabletop exercises, post-incident reviews, and resulting control improvements.
- Use and validate enterprise-authorized AI capabilities for threat modeling, vulnerability analysis, code/security recommendations, documentation, and control validation.
Requirements
- Formal training or certification in security engineering concepts with advanced applied experience.
- Experience planning, designing, and implementing enterprise-level security solutions.
- Experience using enterprise-authorized AI capabilities in security engineering workflows, with strong validation and data-sensitivity practices.
- Ability to review and validate AI-assisted code and security recommendations before adoption.
- Advanced proficiency in one or more programming languages.
- Proficiency across SDLC execution, application resiliency, security, and agile delivery practices.
- Experience with threat modeling, discovery, vulnerability analysis, and penetration testing.
- Deep public-cloud security expertise across identity and access management, network segmentation, data protection, logging and monitoring, and native cloud services.
- Experience leading cross-functional security programs and influencing VP-level and more senior stakeholders.
- Experience translating policy and risk requirements into practical designs and policy-as-code guardrails.
- Hands-on familiarity with Terraform, infrastructure-as-code security, DevSecOps, CI/CD concepts, and enforcement frameworks.
- Advanced cloud and security certifications are preferred, and experience deploying and operating CSPM, CIEM, or CWPP solutions is advantageous.
Benefits
- The role offers collaboration with senior leaders, audit, and regulators in a global financial-services environment.
- The position provides opportunities to lead, mentor, and influence the direction of cloud security and technology controls.
- J.P. Morgan is an equal opportunity employer that provides reasonable accommodations and emphasizes diversity and inclusion.
Tech Stack
Categories
About JPMorgan Chase
JPMorgan Chase provides consumer and commercial banking, payments, credit card, wealth management, and corporate and investment banking services to individuals, businesses, institutions, and governments. The public company (NYSE: JPM) earns revenue from interest, fees, trading, and asset management across operations in more than 100 markets. Headquartered in New York City with roots dating to 1799, it serves retail customers and prominent corporate and government clients through brands including Chase and J.P. Morgan.