Security Engineer III - Offensive/Defensive Web Security
Chase
Security Engineer III
Your seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Security Engineer III at JPMorganChase within the Cybersecurity and Technology Controls Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm's business objectives.
Job Responsibilities
- Executes security solutions design, development, and technical troubleshooting with the ability to apply knowledge of existing security solutions to satisfy security requirements for internal clients (e.g., product, platform, application owners)
- Applies specialized tools (e.g., vulnerability scanner) to analyze and correlate incident data to identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilities
- Leads delivery of continuity-related awareness, training, educational activities, and exercises
- Manages and maintains security configuration baselines for web hosting and application server infrastructure assets including Apache Server, Apache Tomcat, Microsoft IIS, IBM Server, WebSphere Application Server, Nginx, and related technologies
- Coordinates with product engineering teams, application owners, and control domain stakeholders to define, implement, and monitor secure baseline configurations across multiple platforms.
- Conducts annual baseline recertification activities, mapping security controls to industry standards (CIS Benchmarks, STIGs) and coordinating material changes across engineering, monitoring, and customer communication teams
- Collaborates with configuration drift monitoring teams to develop, test, and maintain detection policies that ensure compliance with published security configuration standards
- Provides technical guidance and remediation support to application teams for security configuration findings
- Adds to team culture of diversity, opportunity, inclusion, and respect
Required Qualifications, Capabilities, and Skills
- Formal training or certification on security engineering concepts and 3+ years applied experience
- Experience developing security engineering solutions
- Proficient in coding in one or more languages
- Overall knowledge of the Software Development Life Cycle
- Solid understanding of agile methodologies such as CI/CD, application resiliency, and security
- Experience with security configuration management, baseline hardening, and compliance frameworks
- Strong analytical and problem-solving skills with ability to interpret technical security requirements and translate them into actionable controls
Preferred Qualifications, Capabilities, and Skills
- Experience with web server and application server technologies (Apache, Tomcat, IIS, WebSphere, Nginx)
- Familiarity with configuration drift monitoring tools and SIEM platforms
- Knowledge of industry security benchmarks and standards (CIS, DISA STIGs, NIST)
- Experience working with cross-functional teams including product engineering, SREs, and control domain stakeholders
- Understanding of cloud and container security configurations
- Strong written and verbal communication skills for technical documentation and stakeholder engagement
- Certifications such as OSCP or OSCE is a plus
About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
- ...Job Title Application Security Engineer Client Booz Allen Hamilton Govt Agency SEC Position Application Security Engineer... ...development, or Visual Studio ~ Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25 ~...WebContract workRemote work
- ...Vice President Drive the security of critical banking applications... ...platforms through hands-on offensive testing. As an Assessments... ...variety of environments, including web applications, APIs, cloud... ...). Experience in reverse engineering thick-client and mobile...Web
$102.94k - $171.57k
...for capturing and refining information security requirements and ensures their integration... ...: Develop and implement engineering's technical security policies and procedures... ...software weaknesses that impact cloud and web applications, beyond the Open Worldwide...WebWork experience placementWorldwide- ...Services: Right Team, Right Technology, Simple and Secure. Responsibilities The Senior Information Security Engineer is responsible for implementing and managing a... ...systems, endpoint protection systems, web application firewalls, vulnerability scanning...Web
$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help...SuggestedRemote work- ...Lead Security Engineer Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions... ...out critical technology solutions with tamper-proof, audit-defensible methods across multiple technical areas within various business...Work at office
$87.03k - $138.97k
...BUSINESS SYSTEMS ANALYST III - CM WHAT IS THE OPPORTUNITY? Support the Capital Markets Division and Partners to develop, test, implement... ...Writing Oracle Procedures & Views Experience with any web based loan origination workflow system (preferably FinanceCenter...WebWork experience placementRemote work- ...architectural doors, frames, hardware, specialty products, and complete security integration services. At CBX Solutions, trust and... ...teamwork are at the heart of everything we do. Physical Security Engineer will be responsible for high level configuration and...For contractors
- ...POA&M tracking activities, supporting remediation efforts and preparation of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating issues in accordance with defined processes. - Maintain and update incident...Minimum wageContract workTemporary workWork experience placementRemote work
- ...Security Engineer Client: Brokerage Firm Card Experience: 2 years Location: Wilmington DE Locals only, phone+ onsite interview must Visa: Any Pay Rate: $60 to $70/hr C2C all inclusive Candidates must be able to successfully pass 2 technical phone screens...Local area
- Bloxley is seeking a talented QA Engineer to ensure optimal user experiences across our mobile applications and web platforms. This remote full-time position involves performing comprehensive testing, developing test plans, and collaborating closely with development teams...WebRemote jobFull time
- ...National Minority Supplier Development Council and the Georgia Minority Supplier Development Council. Job Description We need a Security Engineer who can provide clear and concise security requirements that meet corporate direction. Additional Information All your...Worldwide
- ...10 and strong experience with at least 3 Pen Testing and application security testing Supporting bi-weekly code releases, primarily doing Penetration Testing, testing security controls, web / mobile interfaces, and doing manual testing Ability to look at code,...WebLocal area
- .../implementation of rules and regulations affecting the care and security of youths. Essential Functions Essential functions... ...from driving). JOB REQUIREMENTS for Youth Care Specialist III Applicants must have education, training and/or experience...Shift work
- ...A government contractor is seeking an Application Security Engineer for a remote role. The ideal candidate will have over 6 years of IT experience, with specific expertise in SAST, DAST, and securing enterprise applications. Candidates must understand compliance standards...For contractorsRemote work
$152k - $260k
Overview Contribute to leading-edge security and resilience efforts,... ...specialized in social engineering and assessments of critical business... ...perform and manage hands-on offensive security activities leveraging... ...such as firewalls, IDS/IPS, web proxies, and DLP Information...WebWorldwide$123k - $274.56k
...activities. As part of the first line of defense, supports risk management, compliance, and... ...position. Preferred Skills Agile Web Development, Business Requirements Documentation... ...(FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage...WebFull timeTemporary workPart timeWork experience placementWork at office- ...environments - Strong attention to detail and ability to work in structured, compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring - Experience or exposure to vulnerability management,...Minimum wageContract workTemporary workWork experience placementRemote work
- ...implementing and maintaining databases, ensuring data integrity, security, and performance, including optimizing SQL queries and... ...Continuous Learning: Staying updated with the latest Caspio features, web development trends, and best practices. Required Skills & Qualifications...WebFull timeRemote work
$100k - $172.5k
...Learn more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category:... ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ...Duties and Responsibilities: - Determines security requirements by assessing business... ...in information technology - Security Engineering or Security Architecture experience in a... ...Security Configuration Checklist Defense Information System Agency (DISA) Security...Minimum wageContract workTemporary workWork experience placementRemote work
$146.3k - $326.04k
...lifecycle. As part of the first line of defense, supports determination of risk appetite... ...this position. Preferred Skills Agile Web Development, Business Requirements... ...(FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing...WebFull timeTemporary workPart timeWork experience placementWork at office- Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of... ...firm’s internal team of highly skilled Offensive Security testers who conduct cybersecurity... ...vulnerabilities and exploitation techniques, and web application vulnerabilities and...Web
- ...Registered Nurse I-III (RN Investigator) The RN Investigator conducts investigations of incidents that cause harm or could cause harm to patients at the Delaware Psychiatric Center (DPC), provides findings that determine the cause, and makes recommendations for improvement...
- ...and participating in the discipline and security of an assigned post inside and/or outside... ...provided in the areas of inmate supervision, defensive tactics, riot control, weapons, report... ...visiting the Department of Human Resources web-site at State of Delaware - Delaware...WebPermanent employmentShift workDay shift
- ...Principal Security Controls Architect You have spent your career building security controls that scale, designing governance frameworks... ...that actually get adopted, and translating complex risk into engineering requirements that teams can act on. This role was built for...Immediate start
$105.72k - $132.14k
...and debugging of software using Java/J2EE Develop software using web presentation technologies such as AJAX, JSON, JavaScript, CSS... ...Microservices, Springboot, REST, SOAP, Web Services, Web Services Security, and Test-Driven Development with JUnit or equivalent tool Proficiency...WebFull timeTemporary workWork experience placementLocal areaImmediate startShift workDay shift- ...Expertise in Java/J2EE, Microservices, Java Persistence API (JPA), Model View Controller (MVC) architecture, Java Messaging Service (JMS), web services development using SOAP/REST, Cloud Foundry, Kubernetes, Apache Tomcat, Spring, Spring Boot Intellij, Junit, Agile practices,...Web
- ...Overview: DatamanUSA is looking for a Management Analyst III for our direct client based in DE. This is a great opportunity for someone who is a quick learner with excellent people skills. Job Details: Job Title: Management Analyst III Location: New Castle...Contract work
- ...Registered Nurse I-III (RN Investigator) The RN Investigator conducts investigations of incidents that cause harm or could cause harm to patients at the Delaware Psychiatric Center (DPC), provides findings that determine the cause, and makes recommendations for improvement...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer III - Offensive/Defensive Web Security. Be the first to apply!
- sr information security engineer Wilmington, DE
- senior application security engineer Wilmington, DE
- aws cloud security engineer Wilmington, DE
- senior cloud security engineer Wilmington, DE
- IT security engineer Wilmington, DE
- information technology security engineer Wilmington, DE
- network security engineer Wilmington, DE
- security engineer Wilmington, DE
- senior security operations engineer Wilmington, DE
- web design internship Wilmington, DE


