The role
From JPMorgan Chase's own posting.
Take on a pivotal role where your expertise in cloud security and platform engineering will directly protect one of the world's largest financial institutions. As a Lead Security Engineer on the Digital Forensics Platform Engineering team, you will design and deliver the next generation of enterprise forensic investigation platforms — driving innovation, automation, and resilience at global scale.
As a Lead Security Engineer at JPMorganChase within the Digital Forensics Platform Engineering team, you will own the design, deployment, and automation of secure, cloud-native forensic investigation platforms across multi-cloud environments. You will work alongside engineering, cybersecurity operations, and cloud infrastructure teams to deliver scalable, resilient platforms that power global incident response and digital investigations. Your work will directly strengthen the firm's ability to detect, investigate, and respond to cybersecurity threats — making a measurable impact on the security of millions of customers and employees worldwide.
Job responsibilities
Design, deploy, and maintain enterprise digital forensics platforms across AWS, Azure, GCP, and on-premises environments, ensuring security, scalability, and high availability
Develop and manage Infrastructure-as-Code using Terraform to provision secure, repeatable, and auditable cloud environments
Build and maintain continuous integration and delivery pipelines supporting infrastructure and platform releases across multi-cloud environments
Implement automation for platform deployment, configuration management, monitoring, and operational processes to drive efficiency and reliability
Perform functional, validation, failover, and production readiness testing to ensure platform integrity and operational resilience
Implement cloud networking, storage, identity and access management, encryption, and security controls aligned to compliance and regulatory standards
Collaborate with cybersecurity operations, engineering, and cloud service teams to enhance platform reliability, scalability, and incident response capabilities
Apply AI-assisted practices within the software development lifecycle to strengthen security testing, control validation, and threat modeling, ensuring traceability and alignment to resiliency expectations
Create and maintain technical documentation, architecture diagrams, runbooks, and operational procedures to support platform governance and knowledge sharing
Required qualifications, capabilities, and skills
Formal training or certification on security engineering concepts and 5+ years applied experience
Hands-on experience with AWS services including compute, networking, storage, identity management, and audit logging, with additional experience in Azure and/or Google Cloud Platform
Demonstrated experience with Terraform and Infrastructure-as-Code methodologies for provisioning and managing secure cloud environments
Experience building and maintaining continuous integration and delivery pipelines for infrastructure and platform releases
Proficiency in automation and scripting using Python, PowerShell, Bash, or similar languages to support platform operations and deployment workflows
Experience with Linux and Windows server administration in enterprise environments
Knowledge of cloud security principles including identity and access management, role-based access control, encryption, and compliance controls
Experience with source control management using Git, including branching strategies and code review practices
Demonstrated ability to review and validate AI-assisted code and security recommendations, ensuring outcomes align to security, resiliency, and auditability expectations
Preferred qualifications, capabilities, and skills
Experience with digital forensics platforms and cloud-based investigative solutions supporting incident response workflows
Familiarity with VMware virtualization environments including virtual machine lifecycle management and virtual desktop infrastructure
Experience with container-based architectures and cloud-native application development patterns
Knowledge of threat modeling, vulnerability assessment, and penetration testing methodologies
Experience supporting disaster recovery, high availability, and resiliency initiatives across distributed cloud platforms
#CTC