JP Morgan Chase & Co.

Sr Lead Security Engineer

JP Morgan Chase & Co.$120K — $150K *
Telecommunications & Hardware
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in hardware or firmware security evaluation, with formal training or certification.
  • Proven experience in Common Criteria projects, preferably as an evaluator or security consultant.
  • Familiarity with security evaluation projects involving ICs, server platforms, and network devices.
  • Proficiency in programming languages such as C and Python, and in reverse-engineering firmware.
  • Knowledge of cryptographic protocols and hands-on experience with Side-Channel Analysis and Fault Injection techniques.
  • Strong communication skills for stakeholder management and technical writing for security reports.
  • Experience using AI tools in security workflows with attention to data sensitivity.

Responsibilities

  • Lead and perform hardware and firmware security evaluations using methods like source code review and side-channel analysis.
  • Analyze hardware and firmware designs to identify vulnerabilities in various technologies including server platforms and IoT devices.
  • Detect Indicators of Compromise in enterprise infrastructure and provide detailed security assessment reports.
  • Coach colleagues in security evaluation and communicate risks to stakeholders effectively.
  • Drive R&D in security methodologies and collaborate with cross-functional teams to meet security requirements.
  • Ensure alignment of security architecture with business goals and regulatory standards.
  • Utilize AI capabilities to enhance security risk analysis and maintain the integrity of sensitive data.

Benefits

  • Collaborative team environment with opportunities for growth and mentorship.
  • Access to cutting-edge security evaluation tools and methodologies.
  • Support for ongoing education and certification in hardware and firmware security.
  • Engagement in innovative research and development projects in security testing.
Full Job Description
JOB DESCRIPTION

Job Responsibilities

  • Perform and lead hardware and firmware security evaluations using techniques such as source code review, fault injection, and side-channel analysis to validate product security posture. 
  • Understand and analyze complex hardware and firmware designs, locating weaknesses and vulnerabilities in AMD and Intel server platforms, network and DMZ devices, laptops, and IoT devices. Perform firmware security analysis and hardware bill of materials (BOM) content security analysis to identify supply chain risks and unauthorized modifications. 
  • Detect Indicators of Compromise (IOCs) in firmware and hardware components across the enterprise infrastructure. Advise internal product teams through critical parts of their lifecycle management, providing detailed security assessment reports and remediation guidance. 
  • Coach and mentor colleagues to grow as security evaluators and architects within the hardware security domain. Apply critical thinking to distinguish security-critical issues from lower-priority findings and communicate risk effectively to stakeholders. 
  • Drive internal research and development of new attack methodologies, security testing tools, and evaluation frameworks to advance the firm's hardware security capabilities. Collaborate with cross-functional teams including product delivery managers, security engineers, and other stakeholders to translate security requirements into technical designs. 
  • Ensure alignment of hardware and firmware security architecture with business goals, regulatory requirements, and industry certification standards (e.g., Common Criteria, EMVCo). 
  • Uses enterprise-authorized AI capabilities within the work environment to accelerate security risk analysis and documentation (e.g., synthesizing threat assessments), validating outputs and ensuring sensitive data is handled appropriately.
  • Applies reuse-first, AI-assisted practices within SDLC/toolchain routines to strengthen security testing and control validation, ensuring traceability/auditability and alignment to resiliency and security expectations

Required qualifications, capabilities, and skills

  • Formal training or certification with 5+ years of applied experience in hardware or firmware security evaluation. 
  • Proven experience in Common Criteria (CC) projects, preferably as an evaluator, or as a security consultant or developer of secure embedded products. 
  • Track record in CC or equivalent security evaluation projects involving ICs, server platforms, operating systems, TEE (Trusted Execution Environments), network devices, or IoT devices. 
  • Proficiency in programming languages relevant to hardware and firmware security (e.g., C, Python, Assembly, VHDL, Verilog). 

    Experience disassembling and reverse-engineering firmware for ARM, MIPS, or Intel architectures. 

  • Knowledge of cryptographic primitives and protocols including encryption algorithms, key exchange algorithms, hashing/message authentication algorithms, PKI, and random number generators. 

    Hands-on experience with Side-Channel Analysis (SCA) and Fault Injection (FI) techniques and tooling. 

  • Basic to advanced knowledge of electronics, embedded systems, chip design, and applied cryptography.  

    Ability to work independently and lead security assessments without close supervision. 

    Effective communication and stakeholder management across business and technology teams; strong technical writing abilities for producing detailed security evaluation reports. 

  • Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support security engineering workflows with strong validation habits and awareness of data sensitivity.
  • Ability to review and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align to security, resiliency, and auditability expectations.

Preferred qualifications, capabilities, and skills

  • Experience extracting and identifying firmware filesystems, reverse-engineering embedded binaries, emulating firmware for dynamic analysis, fuzzing parsers and scanning network services for vulnerability discovery, interfacing with hardware debug ports (JTAG/SWD) and flash memory for firmware extraction, and performing advanced physical attacks including side-channel analysis and fault injection.

  • Debugging and instrumentation experience for Android, iOS, or Linux on embedded platforms.

About JP Morgan Chase & Co.

JP Morgan Chase & Co. stands at the forefront of the global financial services industry. They offer an expansive array of products and services to a diverse clientele, including individuals, corporations, governments, and institutions. Ever since the merger of J.P. Morgan & Co. and Chase Manhattan Corporation in 2000, this industry-leading entity has become renowned for its comprehensive portfolio encompassing consumer and community banking, corporate and investment banking, commercial banking, as well as asset and wealth management. Headquartered in the vibrant city of New York, JP Morgan Chase & Co. boasts a formidable presence across over 100 countries worldwide.

Unveiling Employment Opportunities at JP Morgan Chase & Co.

Vacancies and Hiring Initiatives

JP Morgan Chase & Co. is continuously on the lookout for talented individuals eager to contribute to its legacy of excellence. The company's recruitment efforts are geared towards identifying candidates with the right blend of skills and qualifications to drive forward its various business segments. Whether you are a seasoned professional or a recent graduate, JP Morgan Chase offers a plethora of job openings across multiple disciplines.

High-Demand Positions

Among the myriad of roles, certain positions stand out for their attractive compensation packages and career advancement prospects. Notably, high-paying jobs at JP Morgan Chase & Co. include Relationship Manager, Branch Manager, and Software Engineer. These roles are critical to the firm's operations and offer lucrative opportunities for those with the requisite expertise.

Navigating the Job Market at JP Morgan Chase & Co.

Leveraging Job Portals and Job Alerts

For job seekers aiming to tap into the opportunities at JP Morgan Chase, staying updated through job portals and subscribing to job alerts is crucial. These tools can provide timely information about job openings, job fairs, and recruitment events, enabling candidates to apply promptly and prepare adequately for interviews.

Preparing Your Job Application

Your job application, comprising your resume and cover letter, is your ticket to securing an interview at JP Morgan Chase. Highlight your qualifications, skills, and experiences that align with the job listing, ensuring you stand out in the competitive job market.

Acing the Interview

Preparation is key to succeeding in your interview with JP Morgan Chase. Familiarize yourself with the company's business segments, values, and recent achievements. Demonstrating how your background and aspirations match the company's goals can significantly increase your chances of employment. A World of Job Opportunites in the Financial Services Industry JP Morgan Chase & Co. offers a world of job opportunities for those seeking to make their mark in the financial services industry. With competitive salaries, comprehensive benefits, and endless possibilities for growth, positions at JP Morgan Chase are highly coveted. By staying informed through job sites, tailoring your applications, and preparing thoroughly for interviews, you can enhance your prospects of joining the esteemed ranks of JP Morgan Chase employees. Explore the job board, seize the job opportunities, and embark on a rewarding career journey with one of the world's leading financial institutions.
Learn more about JP Morgan Chase & Co.
Size
661 employees
Market Cap
$384.5 billion
Industry
Net Income
$29.1 billion
Founded
1823
5 Year Trend
+0.7%
Revenue
$261.5 million
NASDAQ

Similar Jobs

More Jobs at JP Morgan Chase & Co.

More Telecommunications & Hardware Jobs

Find similar Sr Lead Security Engineer jobs: