Security Engineer III - Offensive/Defensive Web Security
Chase
Security Engineer III
Your seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Security Engineer III at JPMorganChase within the Cybersecurity and Technology Controls Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm's business objectives.
Job Responsibilities
- Executes security solutions design, development, and technical troubleshooting with the ability to apply knowledge of existing security solutions to satisfy security requirements for internal clients (e.g., product, platform, application owners)
- Applies specialized tools (e.g., vulnerability scanner) to analyze and correlate incident data to identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilities
- Leads delivery of continuity-related awareness, training, educational activities, and exercises
- Manages and maintains security configuration baselines for web hosting and application server infrastructure assets including Apache Server, Apache Tomcat, Microsoft IIS, IBM Server, WebSphere Application Server, Nginx, and related technologies
- Coordinates with product engineering teams, application owners, and control domain stakeholders to define, implement, and monitor secure baseline configurations across multiple platforms.
- Conducts annual baseline recertification activities, mapping security controls to industry standards (CIS Benchmarks, STIGs) and coordinating material changes across engineering, monitoring, and customer communication teams
- Collaborates with configuration drift monitoring teams to develop, test, and maintain detection policies that ensure compliance with published security configuration standards
- Provides technical guidance and remediation support to application teams for security configuration findings
- Adds to team culture of diversity, opportunity, inclusion, and respect
Required Qualifications, Capabilities, and Skills
- Formal training or certification on security engineering concepts and 3+ years applied experience
- Experience developing security engineering solutions
- Proficient in coding in one or more languages
- Overall knowledge of the Software Development Life Cycle
- Solid understanding of agile methodologies such as CI/CD, application resiliency, and security
- Experience with security configuration management, baseline hardening, and compliance frameworks
- Strong analytical and problem-solving skills with ability to interpret technical security requirements and translate them into actionable controls
Preferred Qualifications, Capabilities, and Skills
- Experience with web server and application server technologies (Apache, Tomcat, IIS, WebSphere, Nginx)
- Familiarity with configuration drift monitoring tools and SIEM platforms
- Knowledge of industry security benchmarks and standards (CIS, DISA STIGs, NIST)
- Experience working with cross-functional teams including product engineering, SREs, and control domain stakeholders
- Understanding of cloud and container security configurations
- Strong written and verbal communication skills for technical documentation and stakeholder engagement
- Certifications such as OSCP or OSCE is a plus
About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
$277.6k
Offensive Security Engineer, Agent Products Security - San Francisco, New York City, Seattle, Washington... ...OpenAI’s agent‑powered products, including web applications, APIs, cloud services,... ...threat models, mitigations, and defensive coverage. You might thrive in this role...WebRemote work$277.6k
OpenAI is seeking a Principal Offensive Security Engineer focused on hands-on penetration testing of agent-powered products, including web applications and cloud services. The ideal candidate has over 7 years of experience in security assessment, with expertise in finding...WebRemote job$165k - $242k
...Offensive Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is... ...curious about evolving attack vectors and defense strategies. You're an expert in... ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv...SuggestedPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$135k - $236.25k
...About The Role Rippling is looking for a hands-on Security Engineer - Offensive Security to join our growing security team. In this role,... ...execute offensive security initiatives that challenge our defenses, shape detection capabilities, and strengthen the resilience...SuggestedWork at office3 days per week$217k - $255k
...standards, clear accountability, and a strong focus on security and ethics in everything we build! The Red Team's... ...by simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across...SuggestedWork at officeShift work3 days per week$165k - $242k
...You'll Do: The Enterprise Security team at CoreWeave is... ...Role: As a Senior Security Engineer, Enterprise Security , you'll... ...products (e.g., ZTNA, secure web gateways, or identity-aware proxies... ...resident (green card holder), (iii) refugee under 8 U.S.C. § 1157...WebPermanent employmentTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours- ...reports for review by Leadership and Engineers • Collaborate and build... ...vulnerabilities identified during application security assessments, cloud infrastructure... ...dvanced knowledge of SAST, DAST, OSS, web-app pen-test, and offensive security assessment tools • Experience...Web
$168k - $210k
...Security Engineer Specializing In Penetration Testing At Remitly, we believe everyone deserves... ...passionate about penetration testing, offensive security, secure design, and continuous... ...Perform penetration tests against web applications, APIs, mobile applications...WebWork at officeWorldwideFlexible hours3 days per week$110k - $130k
...Perform risk and security assessments, design secure infrastructure... ...opening for a Senior Security Engineer(Penetration Testing/GRC... ...assessments using a wide range of offensive security tools and methodologies... ...application layer testing, web application assessments (...WebTemporary workWork at officeImmediate startRemote workVisa sponsorshipAfternoon shift- Seattle Hiring Event - Security Architecture & Engineering - June 15th/16th 2026 Seattle, WA, United States... ...Development, Cloud, Infrastructure, Mobile, Offensive Security, or Vulnerability... ...IriusRisk, and PASTA. Experience with web, API, and microservices technologies...WebFull timeFor contractors
- ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Seattle, Washington; Jacksonville, Florida; Charlotte, North Carolina; Jersey City, New Jersey; Boston, Massachusetts; Washington, District of Columbia; Chicago, Illinois To proceed with your application...Work at officeRemote workShift workDay shift
- ...Role TwelveLabs is looking for a Staff Security Engineer to join our security team, working directly... ...protocols Proven experience with web application security assessments and penetration... ...visibility Have hands‑on offensive security or red team experience Have worked...WebWork at officeWorldwideFlexible hoursShift work
- A leading technology company is seeking a hands-on Security Engineer - Offensive Security in Seattle. This role involves designing and executing offensive security operations, conducting threat emulations, and influencing security investment across various teams. Candidates...
- Information Assurance System Security Engineer We are looking to fill this position... ...) supporting Department of Defense (DoD) agencies, such as HQ... ...security, and Apache/IIS Web server security Experience: 1... ...Information Assurance Manager Level III or Information Assurance...WebWork at office
- ...Description At Staris AI we believe human-based cyber defense is dead and the dream of security automation is finally within reach. Staris AI is a... ...applications into a new era of security. As an Offensive Security Engineer at Staris AI, you'll be at the vanguard of the...Remote work
- ...Security Engineer -Level L2 Arete Technologies, Inc. offers a set of innovative consulting and outsourcing services, bridging the gap between... ...of staff augmentation, IT consultancy, software development, web development providing unexcelled services and focusing on both...WebWorldwide
$164.65k - $230.51k
...strategies. We are seeking a Software Engineer III to design and develop technology... ...Python, and Typescript Design and build web interfaces in frameworks such as React and... ...Check Required for Certain Job Profiles: Defense Biometric Identification System (DBIDS)...WebPermanent employmentTemporary workLocal areaRelocation- ...Experience conducting end to end privacy reviews and DPIA updates Preferred privacy knowledge of consumer areas such as web or advertising and generative experiences Preferred familiarity with Customer privacy standards and systems including 1CS SNOW...Web
- ...Job Title: Sr. Security Engineer Location: Remote (PST) Duration: 6+ Contract Role Summary We are looking for a senior security... ...video streaming services • Familiarity with mobile and web player security • Knowledge of anti-piracy mechanisms and...WebContract workRemote work
$136.16k - $170.2k
...and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking... ...Software Engineers with a passion in Security to help us scale. Come be part of the Security... ...of the stack, from infrastructure to web application security, as well as mobile...WebHourly payWork at officeLocal area3 days per week$218.5k - $273.13k
...Senior Security Engineer (Product) New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United... ...knowledge of the role of security in engineering systems and web architecture. Final rounds: You'll meet several more team members...WebWork from homeFlexible hours- ...Introduction As a Security Engineer/Tester, you will be responsible for performing authorized security testing on complex, large-scale,... ...testing on software applications. ~ Deep understanding of web application technologies, web protocols ( and browser technologies...WebContract workWork experience placementImmediate start
$63.91 - $108.82 per hour
...Description Senior Security Engineer IS – Identity & Access Management We are seeking a highly motivated Senior Security Engineer with... ...countermeasures for operating systems, databases, applications, Web services, user devices, and wireless networks. Preferred...WebMinimum wageFull timeWork at officeRemote workFlexible hoursShift workWeekend work- ...Security Engineer/Tester Location: Seattle, Washington (Onsite) Employment Type: Contract Contract Duration: 12 months Role Overview... ...and automated software testing. Deep understanding of web application technologies, web protocols ( and browser technologies...WebContract workWork experience placement
$188k - $275k
...Staff Network Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave... ...Security Engineer to architect the defense of our global backbone, edge, and... ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv)...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$56.34 - $70.42 per hour
NextDeavor is seeking a WAF Adversarial Engineer to validate and harden web application firewall security by conducting adversarial testing. You'll run test campaigns, build a WAF bypass library, and work with edge security teams. Requirements include experience with commercial...WebRemote jobHourly pay$182k - $202k
...world's largest community of security researchers to continuously discover... ..., and the U.S. Department of Defense, trust HackerOne to safeguard... ...in the security industry. Offensive security is no longer... ...accountability. Senior Security Engineer, Detection and ResponseRemote...ApprenticeshipLocal areaRemote workFlexible hoursShift work$18k
...ITSM IT Security Engineer III - WA ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management...For contractorsWork experience placementWork at officeLocal areaImmediate start- ...Amsterdam. The mission of Plaid's Product Security Team is "Improve our customer's trust by... .... As an Experienced Product Security Engineer at Plaid, you'll be a trusted advisor,... ...application security concepts, including API, web, and mobile app security. ~ Ability to...WebWork experience placementLocal area
$150k - $185k
...DC 20534 (On-site) Employment Type: Full-Time | Positions: 1 Position Overview Innosoft Corporation is seeking a Cloud Security Engineer / DevSecOps III to serve as a hands-on AWS security engineer supporting the Bureau of Prisons (BOP) cloud environment. This role...Full timeContract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer III - Offensive/Defensive Web Security. Be the first to apply!
- sr information security engineer Seattle, WA
- security engineer intern Seattle, WA
- senior application security engineer Seattle, WA
- principal security engineer Seattle, WA
- security engineering manager Seattle, WA
- aws cloud security engineer Seattle, WA
- sr security engineer Seattle, WA
- senior cloud security engineer Seattle, WA
- cloud security engineer Seattle, WA
- IT security engineer Seattle, WA

