Security Engineer III - Offensive/Defensive Web Security
Chase
Security Engineer III
Your seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Security Engineer III at JPMorganChase within the Cybersecurity and Technology Controls Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm's business objectives.
Job responsibilities
- Executes security solutions design, development, and technical troubleshooting with the ability to apply knowledge of existing security solutions to satisfy security requirements for internal clients (e.g., product, platform, application owners)
- Applies specialized tools (e.g., vulnerability scanner) to analyze and correlate incident data to identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilities
- Leads delivery of continuity-related awareness, training, educational activities, and exercises
- Manages and maintains security configuration baselines for web hosting and application server infrastructure assets including Apache Server, Apache Tomcat, Microsoft IIS, IBM Server, WebSphere Application Server, Nginx, and related technologies
- Coordinates with product engineering teams, application owners, and control domain stakeholders to define, implement, and monitor secure baseline configurations across multiple platforms.
- Conducts annual baseline recertification activities, mapping security controls to industry standards (CIS Benchmarks, STIGs) and coordinating material changes across engineering, monitoring, and customer communication teams
- Collaborates with configuration drift monitoring teams to develop, test, and maintain detection policies that ensure compliance with published security configuration standards
- Provides technical guidance and remediation support to application teams for security configuration findings
- Adds to team culture of diversity, opportunity, inclusion, and respect
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 3+ years applied experience
- Experience developing security engineering solutions
- Proficient in coding in one of more languages
- Overall knowledge of the Software Development Life Cycle
- Solid understanding of agile methodologies such as CI/CD, application resiliency, and security
- Experience with security configuration management, baseline hardening, and compliance frameworks
- Strong analytical and problem-solving skills with ability to interpret technical security requirements and translate them into actionable controls
- Experience with web server and application server technologies (Apache, Tomcat, IIS, WebSphere, Nginx)
- Familiarity with configuration drift monitoring tools and SIEM platforms
- Knowledge of industry security benchmarks and standards (CIS, DISA STIGs, NIST)
- Experience working with cross-functional teams including product engineering, SREs, and control domain stakeholders
- Understanding of cloud and container security configurations
- Strong written and verbal communication skills for technical documentation and stakeholder engagement
- Certifications such as OSCP or OSCE is a plus
About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
$102.94k - $171.57k
...for capturing and refining information security requirements and ensures their integration... ...: Develop and implement engineering's technical security policies and procedures... ...software weaknesses that impact cloud and web applications, beyond the Open Worldwide...WebWork experience placementWorldwide- Job Title Application Security Engineer Client Booz Allen Hamilton Govt Agency SEC Position Application Security Engineer Location 100% Remote... ..., or Visual Studio Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25 Knowledge...WebContract workRemote work
$115k - $170k
...Senior Security Engineer Some security roles are about maintaining systems. This one is about outthinking adversaries. We're... ...Senior Security Engineer to join our Purple Team — where offensive and defensive security meet. You'll work at the intersection of attack...SuggestedCasual workWork from homeFlexible hours- ...Servicenow Technology Support Iii Propel operational success with your expertise in technology support and a commitment to continuous... .... ~ Experience with ServiceNow integrations, APIs, and web services. ~ Proficiency in ServiceNow scripting languages (JavaScript...WebWork at officeWeekend work
- ...Senior Information Security Engineer The Senior Information Security Engineer is responsible for implementing and managing a comprehensive... ...firewalls, intrusion detection systems, endpoint protection systems, web application firewalls, vulnerability scanning software,...Web
- ...productivity suites (e.g. Microsoft 365), and web‑based applications. Selective Requirement... ...implementing and ensuring compliance with security procedures and policies, purchasing... ...for Telecommunications/Network Technician III At least two years experience administering...WebCasual workSeasonal workRemote work
$85 per hour
...Description Job Title: Software Engineer III Location: Wilmington, DE Employment: Contract... ...requirements (performance, reliability, security, auditability). Review code and... ...experience in Designing and developing Fullstack web apps using .Net MVC, C#, SQL Server,...WebContract workTemporary workWorldwide$104k - $156k
...Posting Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate security controls that protect Relativity's employee endpoints and the enterprise systems they access. You will help...Remote work- ...Lead Security Engineer Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions... ...out critical technology solutions with tamper-proof, audit-defensible methods across multiple technical areas within various business...Work at office
- ...Physical Security Engineer Join CBX Solutions, the nation's leading provider of architectural doors, frames, hardware, specialty products, and complete security integration services. At CBX Solutions, trust and communication are the foundation of how we work. We foster...For contractors
- ...Security Engineer Client: Brokerage Firm Card Experience: 2 years Location: Wilmington DE Interview: Locals only, phone+ onsite interview must Visa: Any Pay Rate: $60 to $70/hr C2C all inclusive Please Note: Candidates must be able to successfully...Local area
- ...National Minority Supplier Development Council and the Georgia Minority Supplier Development Council. Job Description We need a Security Engineer who can provide clear and concise security requirements that meet corporate direction. Additional Information All your...Worldwide
- ...lectionnés utilisons des technologies et des outils de suivi (témoins) pour recueillir des renseignements sur votre utilisation de ce site Web. Les témoins essentiels soutiennent les fonctionnalités de base du site, la sécurité et la protection des renseignements personnels....WebContract workWork from home
$152k - $260k
Overview Contribute to leading-edge security and resilience efforts,... ...specialized in social engineering and assessments of critical business... ...perform and manage hands-on offensive security activities leveraging... ...such as firewalls, IDS/IPS, web proxies, and DLP Information...WebWorldwide- ...Registered Nurse I-III (RN Investigator) The RN Investigator conducts investigations of incidents that cause harm or could cause harm to patients at the Delaware Psychiatric Center (DPC), provides findings that determine the cause, and makes recommendations for improvement...
- ...implementing and maintaining databases, ensuring data integrity, security, and performance, including optimizing SQL queries and... ...Continuous Learning: Staying updated with the latest Caspio features, web development trends, and best practices. Required Skills & Qualifications...WebFull timeRemote work
$100k - $172.5k
...Learn more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category:... ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week$100k - $261.3k
...lifecycle. As part of the first line of defense, supports determination of risk appetite... ...this position. Preferred Skills Agile Web Development, Business Requirements... ...(FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing...WebFull timeTemporary workPart timeWork experience placementWork at office- Spearhead cutting-edge security strategies and resilience initiatives, shaping the future of... ...firm’s internal team of highly skilled Offensive Security testers who conduct cybersecurity... ...vulnerabilities and exploitation techniques, and web application vulnerabilities and...Web
- ...Overview: DatamanUSA is looking for a Management Analyst III for our direct client based in DE. This is a great opportunity for someone who is a quick learner with excellent people skills. Job Details: Job Title: Management Analyst III Location: New Castle...Contract work
- ...Principal Security Controls Architect You have spent your career building security controls that scale, designing governance frameworks... ...that actually get adopted, and translating complex risk into engineering requirements that teams can act on. This role was built for...Immediate start
$105.72k - $132.14k
...and debugging of software using Java/J2EE Develop software using web presentation technologies such as AJAX, JSON, JavaScript, CSS... ...Microservices, Springboot, REST, SOAP, Web Services, Web Services Security, and Test-Driven Development with JUnit or equivalent tool Proficiency...WebFull timeTemporary workWork experience placementLocal areaImmediate startShift workDay shift- ...Expertise in Java/J2EE, Microservices, Java Persistence API (JPA), Model View Controller (MVC) architecture, Java Messaging Service (JMS), web services development using SOAP/REST, Cloud Foundry, Kubernetes, Apache Tomcat, Spring, Spring Boot Intellij, Junit, Agile practices,...Web
- Tryfacta, Inc is looking for a Management Analyst III/Program Integrity Specialist in New Castle, Delaware. This temporary contract position requires conducting program integrity reviews to ensure compliance with grant requirements. Candidates should have strong skills...Temporary work
$55 - $60 per hour
...Job Description Our large technical manufacturing client is seeking a hands-on OT Security Engineer to support secure network operations, remote access deployments, and vulnerability management across enterprise and operational technology (OT) environments. This individual...Contract workRemote work- ...them . If you have the talent of sewing and the willingness to help others during a difficult time come be a part of our hospice organization. A member of the Volunteer Department will contact you shortly! For more information please visit our web site at...Web
- ...Bachelor's degree in Computer Science, Software Engineering or related technology discipline. Minimum of 3 years... ...Microservices, Azure and Kubernetes. Knowledge of security vulnerabilities in web applications and addressing them. Solid understanding...Web
- ...~ TypeScript ~ JavaScript Solid understanding of frontend architecture, state management, performance optimization, and web standards. Strong grasp of fundamental system design principles and application architecture. Ability to work independently...Web
- ...frameworks. The role requires strong backend engineering expertise, experience in distributed... ..., best practices, and application security guidelines. Collaborate with cross-functional... ...Stack REST API Development SOAP Web Services Secondary Skills (Good-to-...Web
- ...Wilmington, DE Full-time Opportunity Job Description: Technologies: • Required: Java, J2EE, Spring, Angular, Web Services, PL/SQL • Preferred: Cucumber, Cloud Technology Required Skills: • 8+ Years' experience in Agile software...WebFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer III - Offensive/Defensive Web Security. Be the first to apply!
- senior application security engineer Wilmington, DE
- sr information security engineer Wilmington, DE
- security engineer Wilmington, DE
- senior security operations engineer Wilmington, DE
- aws cloud security engineer Wilmington, DE
- network security engineer Wilmington, DE
- senior cloud security engineer Wilmington, DE
- IT security engineer Wilmington, DE
- information technology security engineer Wilmington, DE
- web analyst Wilmington, DE


