Senior Lead Security Controls Engineer

Senior Lead Security Controls Engineer

Chase

Columbus, OH • Hybrid

$107K - $146.70K/yr

Other

This job posting has expired and is no longer accepting applications. Check out similar jobs


JPMorgan Chase & Co. rating

8.1

Company rating: 8.1 out of 10

Based on 466 frontline employees who took The Breakroom Quiz

46th of 141 rated banks


Job description

Senior Lead Security Engineer

Join a team where your engineering expertise directly shapes how Technology/Cyber controls are built, governed, and scaled across a global technology organization. Here, you will make a direct and meaningful impact, contributing to work that matters at every level of the firm.

As a Senior Lead Security Engineer at JPMorganChase within CTO Global Technology Asset Management, you will be a technical leader responsible for engineering scalable technology controls while also strengthening technology asset governance so that control applicability, evidence, and reporting are consistent and auditable across hybrid environments. Your work will directly influence how the firm manages risk and maintains trust across its global technology infrastructure.

Job responsibilities

  • Design and implement a technology asset governance framework: taxonomy standards, mandatory metadata, ownership and attestation model, lifecycle states, stewardship expectations, and adoption mechanisms
  • Define and maintain asset classification and criticality rules (e.g., tiering, criticality, environment, data sensitivity, internet exposure) and map them to control applicability and required evidence
  • Lead the design and implementation of reusable control patterns
  • Define and advance technology asset taxonomy and mandatory metadata standards
  • Establish pragmatic asset governance mechanisms aligned to engineering and risk requirements
  • Engineer automated evidence collection and continuous monitoring pipelines
  • Translate threat models and risk requirements into testable control requirements and enforceable governance rules
  • Partner with Risk, Compliance, and Audit to ensure controls and governance are auditable by design
  • Contribute to a team culture of diversity, opportunity, inclusion, and respect

Required qualifications, capabilities, and skills

  • 5 years of experience in security engineering, IT asset management, or risk and technology controls, with demonstrated end-to-end delivery ownership
  • Demonstrated experience designing and implementing technology controls at scale
  • Experience building or operationalizing asset governance and asset management capabilities
  • Practical experience with modern engineering practices including CI/CD pipelines, infrastructure-as-code, and automated testing frameworks
  • Translate threat models and attack surface analysis into actionable control requirements and auditable governance standards
  • Ability to communicate clearly with senior stakeholders and drive alignment across engineering, cybersecurity, and risk partners

Preferred qualifications, capabilities, and skills

  • Product mindset (roadmaps, KPIs, adoption) and experience partnering with product owners and managers
  • Experience supporting audits and exams with high-quality, repeatable evidence and well-governed exception processes
  • Familiarity mapping controls and governance requirements to common frameworks such as NIST, ISO 27001, or CIS Controls

What JPMorgan Chase & Co. employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom




Frequently asked questions

Q: What skills or qualities help someone succeed as a Senior Security Engineer?

A: To succeed as a Senior Security Engineer, key technical skills include expertise in security protocols (e.g., SSL/TLS, VPN), threat analysis and mitigation, and proficiency in security frameworks (e.g., NIST, ISO 27001). Soft skills such as strong communication, problem-solving, and leadership abilities are also crucial, as Senior Security Engineers often collaborate with cross-functional teams and make strategic security decisions. By combining these technical and soft skills, Senior Security Engineers can effectively protect their organization's assets, drive security innovation, and advance their careers through leadership opportunities and industry recognition.

Q: What is the career path for a Senior Security Engineer?

A: A Senior Security Engineer's typical career progression involves starting as a Security Analyst or Junior Security Engineer, progressing to a Security Engineer or Mid-Level Security Engineer role, and eventually becoming a Senior Security Engineer or Lead Security Engineer. Key opportunities for skill development and professional growth include staying up-to-date with emerging threats and technologies, developing expertise in security frameworks and compliance regulations, and honing leadership and communication skills to effectively manage security teams and projects. Long-term career prospects for Senior Security Engineers may include transitioning into executive roles such as Chief Information Security Officer (CISO) or Chief Technology Officer (CTO), or pursuing specialized roles like Security Consultant or Cybersecurity Architect.