Lead Cloud Security Engineer
JPMorgan Chase · Dublin, Ireland
About The Role
Join us to make a meaningful impact on the security of our global cloud infrastructure. As a Lead Cloud Security Engineer, you will help shape the future of cybersecurity and technology controls at JPMorgan Chase & Co. You’ll collaborate with talented professionals, drive innovation, and advance your career in a dynamic environment. We value your expertise and commitment to continuous improvement. Experience the opportunity to lead, mentor, and influence the direction of cloud security.
As a Lead Cloud Security Engineer in the Cybersecurity & Technology Controls Product Security team aligned to the Azure Cloud programme, you will ensure public cloud adoption is secure and compliant. You will identify and manage risk-related issues, partner with senior leaders, and drive automation of controls. Your role is pivotal in keeping the firm protected, stable, and resilient. You will contribute to a culture of ownership and continuous improvement.
Job Responsibilities
- Contribute to the evolution of a multi-year information risk and control strategy for public cloud, setting vision, OKRs, and KRIs that align with enterprise risk appetite, policies, and regulatory expectations.
- Use enterprise-authorized AI capabilities within the work environment to accelerate threat modeling, vulnerability analysis synthesis, and security documentation, validating outputs and ensuring sensitive data is handled appropriately.
- Lead risk-based design and assessment of security controls across cloud services, platforms, and reference architectures; establish standardized control baselines and reusable patterns for AWS, Azure, and GCP.
- Chair or co-chair governance forums, make informed risk acceptance decisions, and drive timely remediation, deviation tracking, and benefits realization.
- Partner with senior leaders across engineering, product, and risk to embed “security by design,” ensuring deep integration with security operations, threat intelligence, IAM, network security, and data protection.
- Set the operating model for infrastructure as code security: define guardrails, policy as code, and automated pre-commit/pre-deploy controls; oversee security reviews for Terraform and platform engineering pipelines.
- Establish and maintain authoritative documentation, standards, and playbooks; implement agile delivery mechanisms for security programs at scale.
- Build, mentor, and lead a high-performing matrixed team of security engineers and risk analysts; develop talent, clarify accountabilities, and cultivate a culture of ownership and continuous improvement.
- Define and report control effectiveness and residual risk through executive-ready dashboards; brief senior stakeholders, audit, and regulators; ensure audit readiness and sustainable evidence practices.
- Drive the tooling and automation strategy for cloud security, including build vs buy evaluations, vendor management, and integration with existing telemetry and SOAR platforms.
- Strengthen cloud incident preparedness and response by leading threat modeling, tabletop exercises, and post-incident reviews that translate lessons learned into control enhancements.
- Apply reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations.
Required Qualifications, Capabilities, and Skills
- Formal training or certification on security engineering concepts and advanced applied experience.
- Skilled in planning, designing, and implementing enterprise-level security solutions.
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted code/security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.
- Advanced in one or more programming languages.
- Proficient across SDLC execution, including agile methodologies such as CI/CD, application resiliency, and security.
- Experience with threat modeling, discovery, vulnerability, and penetration testing.
Preferred Qualifications, Capabilities, and Skills
- Deep expertise securing public cloud at scale, spanning identity and access management, network segmentation, data protection, logging/monitoring, and native cloud services across AWS, Azure, and/or GCP.
- Proven leadership of cross-functional security programs with measurable outcomes; adept at influencing VP+ stakeholders and navigating complex prioritization across multiple platforms and business lines.
- Exceptional executive communication and stakeholder management skills, including experience engaging internal audit and external regulators with clear narratives, metrics, and remediation roadmaps.
- Demonstrated ability to translate policy and risk requirements into practical designs and policy as code guardrails that balance delivery velocity with control effectiveness.
- Hands-on familiarity with Terraform and infrastructure as code security, DevSecOps and CI/CD concepts, and enforcement frameworks within modern development workflows.
- Strong program execution under tight timelines; highly self-directed with a bias for action, ownership, and outcome orientation.
- Advanced cloud and security certifications are a plus; experience deploying and operating CSPM/CIEM/CWPP solutions is advantageous.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
