About this role
Salary: £62,000 - 102,000 per year
Requirements: 5+ years in network security, SASE/SSE, identity security, or security engineering, or equivalent depthStrong understanding of Zero Trust principles, policy-based access, segmentation, and secure egressHands-on experience with proxy/gateway architectures, including forward proxy, reverse proxy, and IAP patterns, and secure internet access controlsDeep knowledge of SAML, OIDC, OAuth 2.0 concepts, and JWT, including signing, verification, JWKs, rotation, scopes/claims, and replay protectionDemonstrated experience leading effective use of approved AI-assisted software development tools, with the ability to set team expectations for validating AI outputs for correctness, performance, and securityStrong understanding of responsible AI use in engineering workflows, including data sensitivity considerations, secure handling of inputs/outputs, and adherence to resiliency and security expectationsDemonstrated experience delivering regional execution ownership in the US or North America for infrastructure and/or security platforms, including prioritization, cross-team coordination, and sustained accountability for operational and delivery outcomesExperience supervising engineers and delivering cross-team remediation, modernization, and platform programs with clear scope, dependency management, delivery milestones, and measurable outcomesStrong knowledge of network and perimeter security architecture and controls, including segmentation, routing and policy considerations, encryption and access control patterns, and defense-in-depth design principlesExperience designing, delivering, or operating proxy and/or SSE capabilities at enterprise scaleStrong experience translating security requirements into deployable edge and perimeter-adjacent connectivity patterns, including Cisco and Arista environmentsWorking knowledge of interconnect and colocation connectivity models, including Equinix Fabric, and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLink, with the ability to incorporate these into perimeter and egress designsExperience integrating US delivery requirements and stakeholder needs into global standards, reference architectures, and governance models while maintaining a consistent global risk postureExperience leading AI-threat-informed remediation programs, including adapting standards and engineering patterns to account for high-velocity reconnaissance, rapid technique iteration, and automation-driven exploitation attemptsExperience building enterprise-scale governance programs for security engineering, including controls-by-design, exception frameworks, audit-ready traceability, and measurable risk reduction reportingExperience with large-scale operations for externally facing or security enforcement services, including observability strategy, resilience testing, incident response alignment, and reduction of repeat incidents and client-impacting eventsExperience designing and operating hybrid edge architectures and cloud interconnect patterns across multiple cloud providersSecurity certifications such as CISSP, CCSP, or comparable credentials Responsibilities: Execute creative network security software solutions, including design, development, and technical troubleshooting, and solve technical problems beyond routine or conventional approachesDevelop secure, high-quality production code and review and debug code written by othersArchitect and implement Zero Trust Network Access patterns for user-to-app and user-to-internet access to minimize implicit trust and reduce lateral movementBuild and operate an Identity-Aware Proxy and policy enforcement point for web and application access, enforcing identity-, device-, and context-based policy decisionsImplement or integrate Secure Gateway and Secure Web Gateway capabilities, including URL filtering, TLS inspection where approved, malware protection, sandboxing, egress controls, and DNS securityUse approved AI-assisted engineering practices to improve code quality, delivery speed, and operational outcomes while establishing consistent validation standards and promoting reuse of effective patternsApply knowledge of Software Development Life Cycle toolchain tools, including enterprise-authorized AI-assisted development and automation capabilities, to improve the value realized by automationIdentify opportunities to eliminate or automate remediation of recurring issues to improve overall operational stability of software applications and systemsOwn the US perimeter, proxy, and SSE/SASE engineering roadmap and execution, including intake, prioritization, dependency management, delivery governance, and stakeholder alignment across cybersecurity, network services, operations, and application and platform teamsDefine and operationalize standards, reference architectures, and reusable engineering patterns for perimeter and egress controls, including forward proxy and secure web gateway patterns, access brokering, identity-aware access concepts, enterprise egress enforcement, segmentation and policy patterns, and design considerations such as TLS inspection and traffic steeringProvide engineering leadership across edge and connectivity adjacencies, including Cisco and Arista edge environments, colocation and interconnect ecosystems, and cloud adjacency patterns including AWS Direct Connect and AWS PrivateLinkEstablish and run governance mechanisms that accelerate remediation while preserving strong controls, including backlog governance, exception handling, risk acceptance and closure workflows, traceability and auditability requirements, and reporting tied to delivery milestones and risk reduction outcomesDrive operational excellence at scale for perimeter, proxy, and SSE services in the US, including incident, change, and problem management rigor, observability and resiliency validation practices, automation to improve repeatability and evidence quality, reduction of client and partner impact, and execution of Technology Lifecycle Management and modernization outcomes tied to stability and risk reduction Technologies: AIAWSArchitectCloudCiscoFabricSupportJWTNetworkOAuthSAMLSecurityWebHTTPMarketing More:
JPMorganChase is one of the oldest financial institutions, offering innovative financial solutions to millions of consumers, small businesses, and many of the worlds most prominent corporate, institutional, and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years, and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing, and asset management. We offer a competitive total rewards package with base salary determined by role, experience, skill set, and location, and eligible roles may also receive commission-based pay and/or discretionary incentive compensation. We also offer a range of benefits and programs, including comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching, and more. Our Global Technology Infrastructure group is a team of innovators who love technology and work in a stable, resilient, and secure operating environment. High Risk Roles are sensitive technology roles that require enhanced pre-hire screening, including criminal and credit background checks as allowed by law. We are committed to diversity and inclusion and provide reasonable accommodations for religious practices, beliefs, mental health, and physical disability needs. This is a full-time role.
last updated 36 week of 2026