About the role
from listingDesign, implement, and secure cryptographic infrastructure as a Lead Security Engineer, protecting global financial systems.
Join a world-class cybersecurity team and make a lasting impact by safeguarding critical payment and cryptographic operations. Advance your career by collaborating with experts and driving innovation in secure infrastructure. As a Lead Security Engineer at JPMorgan Chase within the Cybersecurity & Technology Controls team, you will design, implement, and maintain secure, scalable, and resilient infrastructure solutions supporting critical payment and cryptographic operations. You will leverage deep expertise in Hardware Security Module management and infrastructure architecture to protect sensitive systems and data. You will collaborate with cross-functional teams to define standards, drive innovation, and ensure business continuity. You will thrive in complex, high-stakes environments and contribute to the forefront of cryptographic security. Job responsibilities Lead the architecture, design, and documentation of complex Hardware Security Module and cryptographic infrastructure, ensuring alignment with business, resiliency, and security requirements Design and implement Hardware Security Module solutions, including deployment, configuration, integration, and full lifecycle management across Thales and FutureX platforms Develop and maintain architectural diagrams, system documentation, and operational runbooks to support operational excellence and knowledge continuity Collaborate with cross-functional teams to define infrastructure standards, best practices, and security controls that align with firm-wide policies and industry regulations Oversee migration, upgrade, and consolidation of Hardware Security Module infrastructure, ensuring minimal disruption and maximum security throughout transitions Provide guidance on cryptographic key management, secure storage, confidential computing, and compliance with industry standards including Payment Card Industry Data Security Standard and Federal Information Processing Standards Troubleshoot and resolve infrastructure and Hardware Security Module-related issues, performing root cause analysis and implementing corrective actions using monitoring tools Participate in risk assessments, audits, and incident response activities related to infrastructure and Hardware Security Module environments Apply domain knowledge of payment processes and business resiliency to infrastructure design and operational decision-making Uses enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately. Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations. Required qualifications, capabilities and skills Formal training or certification on security engineering concepts and 5+ years applied experience Hands-on engineering experience with Hardware Security Modules, including expertise in architecture and system design of highly available infrastructure, disaster recovery, and business continuity strategies Experience with network security, firewalls, and secure room operations and key ceremonies Proficient technical troubleshooting skills with strong Linux and Unix administration experience in enterprise environments Proficiency in designing and documenting infrastructure architectures using industry-standard tools and methodologies Experience with infrastructure automation tools such as Terraform for managing and scaling secure environments Hands-on experience with OpenSSL and certificate-based authentication mechanisms Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity. Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations. Preferred qualifications, capabilities and skills Hands-on experience with Splunk or equivalent platforms for infrastructure monitoring and troubleshooting Strong domain knowledge of payment processes and business resiliency applied to infrastructure design Relevant Hardware Security Module platform certifications such as Thales or FutureX credentials Strong understanding of cryptographic principles, key management, confidential computing, and secure hardware operations