Aumni - Manager of Security Engineering

Salt Lake City, UT, United States

JPMorgan Chase & Co.

View company page

It is your time to step up as a leader of talented security teams at one of the world's largest and most influential companies.

As a Manager of Security Engineering at JPMorgan Chase within the Aumni line of business, you are an integral part of team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions. 

The Aumni Information Technology & Security department is responsible for maintaining the IT operations and security of Aumni’s systems and data. We collaborate with all other departments in various capacities with an emphasis on reducing friction where possible while maintaining security.  

Our mission statement is:  

To deliver stronger, smarter security solutions, provide peace of mind for the venture  

capital ecosystem, and enable the success of our customers, employees, and investors.  

If you do not have experience in each area listed below, do not let that discourage you  

from applying. We are looking for an individual with a solid foundation, an aptitude to  

learn, and the ability to ask good questions.  

Job responsibilities

  • Build an application security program that encompasses secure development throughout the SDLC
  • Partner with engineering management to ensure products are developed securely   
  • Educate our software engineers on secure coding practices and even build out a robust security champions program  
  • Assist our customers with their SSO configurations, identify product roadmap  
  • features that require a security eye, review API security configuration  
  • Co-manage our vulnerability scanning tools with our Cloud Security Engineer  
  • Inform the strategy for future headcount and budget in the application security engineering domain  

Required qualifications, capabilities, and skills

 

  • 2+ years of people management experience.  
  • 4+ years of application security experience.   
  • Strong understanding of security principles, protocols, and best practices.   
  • Capable of devising long-term security strategies and roadmaps for the Aumni application.   
  • Must be a team player who is eager to share domain knowledge with the team and eager to learn from others as well. 
  • Knowledge of Secure Software Development Lifecycle Frameworks.  
  • SCA & OSS License Scanning  
  • High Risk Code Review/Testing  
  • Helping Developers Follow Security Best Practices  
  • Vulnerability Remediation Support 
  • Experience with various threat modeling tools and methodologies (STRIDE, OWASP Top 10, Threat Dragon) 
Preferred qualifications, capabilities, and skills  
  • Knowledgeable of Security Frameworks (ASVS, NIST CSF)  
  • Hands on experience implementing & managing various SAST, SCA & Secret scanning tools 
  • Hands on experience investigating & prioritizing vulnerabilities discovered by third party security tools. (Identifying false positives, out of scope items, adjusting CVSS severity of vulnerability to business context, etc.)  
  • Hands on experience with DAST tools 
  • Knowledge of CI/CD tools and how to integrate security into the pipeline
  • Experience with scripting languages (Bash, Python, etc.) 
  • Knowledge of SDET tools and writing security test cases
  • Experience securing various layers of the OSI model
  • Experience configuring and maintaining a Content Security Policy & other HTTP Security Headers
  • Experience with cloud platforms and securing them
  • Configuring Secret Scanning  
 

JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, we offer discretionary incentive compensation which may be awarded in recognition of firm performance and individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: APIs Application security Banking Bash CI/CD Cloud CVSS DAST NIST OWASP Python SAST Scripting SDLC SSO Strategy Vulnerabilities

Perks/benefits: Competitive pay Health care Wellness

Region: North America
Country: United States
Job stats:  6  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.