Lead Security Engineer - Platform Engineer - Endpoint Security
Join a team that protects one of the world's most complex technology environments — not by writing policy, but by building the software and platforms that make security scale. At JPMorganChase, engineers like you have the opportunity to ship production code that runs at genuinely massive scale, solve hard problems across a global endpoint estate, and grow your craft alongside some of the most talented engineers in financial services.
As a Lead Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls — Employee Compute team, you will serve as the technical anchor for a portfolio of high-impact endpoint security platforms and automation programs spanning hundreds of thousands of Mac, Windows, Linux, and virtual desktop endpoints. You will set technical direction, drive day-to-day engineering execution, and raise the bar through design and code reviews — all while remaining hands-on in the code. This is a senior individual contributor role for an engineer who leads through technical excellence and delivery, not through a management hierarchy.
Our team lives at the intersection of DevOps, platform engineering, and full-stack development. You will build and operate systems that govern endpoint authentication, binary execution controls, and policy deployment automation — replacing brittle manual processes with auditable, resilient pipelines built on GitOps principles. If you want your work to matter and to run everywhere, this is the role for you.
Job responsibilities
- Design, build, and ship production-quality software across Mac, Windows, Linux, and virtual desktop environments, serving as the primary technical contributor for a portfolio of endpoint security platforms
- Architect and operate a managed binary allowlisting platform deployed via infrastructure-as-code in a private cloud environment, including automation that generates per-binary rules at application-packaging time
- Develop and maintain cross-platform endpoint authentication tooling — written in a compiled language — that enables applications to authenticate through enterprise proxy infrastructure, including upcoming support for containerized deployment
- Modernize system policy deployment across Windows and virtual desktop environments using GitOps principles, building automated pipelines that scan, grade, and deploy changes in a controlled, auditable manner
- Drive technical direction and day-to-day execution across the team's engineering portfolio, ensuring delivery against milestones while maintaining high standards for code quality, security, and resilience
- Conduct rigorous design and code reviews, mentoring associate engineers and elevating the technical capabilities of the team through hands-on guidance
- Identify manual, high-overhead processes and architect automation solutions that eliminate operational toil and scale across the firm's endpoint estate
- Collaborate cross-functionally with application teams, infrastructure, and security stakeholders to ensure platforms are consumable, audit-defensible, and aligned to enterprise standards
- Apply secure development practices throughout the full software development lifecycle, designing controls that are tamper-resistant and hold up to regulatory scrutiny
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 5+ years applied experience
- Advanced proficiency in one or more major programming languages such as Python, Java, JavaScript/TypeScript, Go, Rust, or C++, with a demonstrated ability to build and ship production software
- Hands-on enterprise experience managing at least two of the following endpoint platforms: Mac, Windows, virtual desktop infrastructure, or Linux
- Proven experience with containers (Docker, Kubernetes), public cloud platforms, and infrastructure-as-code tooling
- Proficiency across the full software development lifecycle, including CI/CD pipelines, GitOps workflows, and automated testing practices
- Working knowledge of secure development practices with the ability to design, build, and operate controls that are audit-defensible and tamper-resistant
- Demonstrated ability to decompose complex, ambiguous technical problems into clearly scoped, deliverable engineering work
- Experience serving as a technical lead — driving execution, setting technical direction, and mentoring engineers through code reviews — while remaining hands-on in the codebase
Preferred qualifications, capabilities, and skills
- Experience building security-focused or systems-level software on Mac, Windows, or Linux platforms
- Familiarity with endpoint security concepts such as binary allowlisting, proxy and authentication flows, or system policy management
- Experience implementing or evolving security controls within a large, regulated enterprise environment
- Background in banking, financial services, or another highly regulated industry such as insurance or healthcare
- Experience as a full-stack developer in a large enterprise environment, with comfort across both application and infrastructure layers
Experience responsibly using enterprise-authorized AI capabilities to accelerate development and validation, with strong habits around output validation and data sensitivity
#CTC