Security Engineer III - Offensive/Defensive Web Security
Chase
Security Engineer III
Your seniority as a security engineer puts you in the ranks of the top talent in your field. Play a critical role at one of the world's most iconic financial institutions where security is vital.
As a Security Engineer III at JPMorganChase within the Cybersecurity and Technology Controls Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm's business objectives.
Job responsibilities
- Executes security solutions design, development, and technical troubleshooting with the ability to apply knowledge of existing security solutions to satisfy security requirements for internal clients (e.g., product, platform, application owners)
- Applies specialized tools (e.g., vulnerability scanner) to analyze and correlate incident data to identify, interpret, and summarize the probability and impact of threats when determining specific vulnerabilities
- Leads delivery of continuity-related awareness, training, educational activities, and exercises
- Manages and maintains security configuration baselines for web hosting and application server infrastructure assets including Apache Server, Apache Tomcat, Microsoft IIS, IBM Server, WebSphere Application Server, Nginx, and related technologies
- Coordinates with product engineering teams, application owners, and control domain stakeholders to define, implement, and monitor secure baseline configurations across multiple platforms.
- Conducts annual baseline recertification activities, mapping security controls to industry standards (CIS Benchmarks, STIGs) and coordinating material changes across engineering, monitoring, and customer communication teams
- Collaborates with configuration drift monitoring teams to develop, test, and maintain detection policies that ensure compliance with published security configuration standards
- Provides technical guidance and remediation support to application teams for security configuration findings
- Adds to team culture of diversity, opportunity, inclusion, and respect
Required qualifications, capabilities, and skills
- Formal training or certification on security engineering concepts and 3+ years applied experience
- Experience developing security engineering solutions
- Proficient in coding in one of more languages
- Overall knowledge of the Software Development Life Cycle
- Solid understanding of agile methodologies such as CI/CD, application resiliency, and security
- Experience with security configuration management, baseline hardening, and compliance frameworks
- Strong analytical and problem-solving skills with ability to interpret technical security requirements and translate them into actionable controls
- Experience with web server and application server technologies (Apache, Tomcat, IIS, WebSphere, Nginx)
- Familiarity with configuration drift monitoring tools and SIEM platforms
- Knowledge of industry security benchmarks and standards (CIS, DISA STIGs, NIST)
- Experience working with cross-functional teams including product engineering, SREs, and control domain stakeholders
- Understanding of cloud and container security configurations
- Strong written and verbal communication skills for technical documentation and stakeholder engagement
- Certifications such as OSCP or OSCE is a plus
About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
$277.6k
Offensive Security Engineer, Agent Products Security - San Francisco, New York City, Seattle, Washington... ...OpenAI’s agent‑powered products, including web applications, APIs, cloud services,... ...threat models, mitigations, and defensive coverage. You might thrive in this role...WebRemote work- ...AVAILABLE Employer: AMAZON.COM SERVICES LLC Offered Position: Security Engineer III Job Location: Seattle, Washington Job Number: AMZ908135... .../Authorization (SAML/OIDC) protocols and network and web protocols (TCP/IP, UDP, IPSEC, and (5) experience in threat...Web
$277.6k
OpenAI is seeking a Principal Offensive Security Engineer focused on hands-on penetration testing of agent-powered products, including web applications and cloud services. The ideal candidate has over 7 years of experience in security assessment, with expertise in finding...WebRemote job$165k - $242k
...Offensive Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is... ...curious about evolving attack vectors and defense strategies. You're an expert in... ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv...SuggestedPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$135k - $236.25k
...About The Role Rippling is looking for a hands-on Security Engineer - Offensive Security to join our growing security team. In this role,... ...execute offensive security initiatives that challenge our defenses, shape detection capabilities, and strengthen the resilience...SuggestedWork at office3 days per week$217k - $255k
...standards, clear accountability, and a strong focus on security and ethics in everything we build! The Red Team's... ...by simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across...Work at officeShift work3 days per week- ...Description At Staris AI we believe human-based cyber defense is dead and the dream of security automation is finally within reach. Staris AI is a... ...applications into a new era of security. As an Offensive Security Engineer at Staris AI, you'll be at the vanguard of the...Remote work
$178.4k - $226.7k
...Come help us conduct sophisticated offensive security operations targeting emerging threats across... ...work closely with security leadership, engineering teams, and researchers to validate... ...improvements in our security posture. Amazon Web Services (AWS) Identity and Governance...WebFlexible hours$178.4k - $226.7k
...The Ads Security organization at Amazon is dedicated to creating innovative... ...a talented Senior Security Engineer to join our team, where you... ...to contribute to securing web applications and services... ...analysis, incident response, and defensive architecture. You understand...WebFlexible hours$165k - $242k
...You'll Do: The Enterprise Security team at CoreWeave is... ...Role: As a Senior Security Engineer, Enterprise Security , you'll... ...products (e.g., ZTNA, secure web gateways, or identity-aware proxies... ...resident (green card holder), (iii) refugee under 8 U.S.C. § 1157...WebPermanent employmentTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours- ...reports for review by Leadership and Engineers • Collaborate and build... ...vulnerabilities identified during application security assessments, cloud infrastructure... ...dvanced knowledge of SAST, DAST, OSS, web-app pen-test, and offensive security assessment tools • Experience...Web
- ...Security Engineer Specializing In Penetration Testing At Remitly, we believe everyone deserves... ...passionate about penetration testing, offensive security, secure design, and continuous... ...Perform penetration tests against web applications, APIs, mobile applications...WebWork at officeWorldwide3 days per week
$178.4k - $226.7k
...of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other... .... A solid foundation in web application security is required, including... ...pattern recognition, and DDoS defense strategies is essential. Hands-on experience...WebImmediate startFlexible hours$110k - $130k
...Perform risk and security assessments, design secure infrastructure... ...opening for a Senior Security Engineer(Penetration Testing/GRC... ...assessments using a wide range of offensive security tools and methodologies... ...application layer testing, web application assessments (...WebTemporary workWork at officeImmediate startRemote workVisa sponsorshipAfternoon shift$178.4k - $226.7k
...Description Amazon's Internal Audit Security team is seeking a Security Engineer III to join our mission of protecting customer data and keeping Amazon secure... ...scalable, reusable security frameworks and tools Web service assessment experience with authentication...WebInternshipFlexible hours- Seattle Hiring Event - Security Architecture & Engineering - June 15th/16th 2026 Seattle, WA, United States... ...Development, Cloud, Infrastructure, Mobile, Offensive Security, or Vulnerability... ...IriusRisk, and PASTA. Experience with web, API, and microservices technologies...WebFull timeFor contractors
- ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Boston, Massachusetts; Washington, District of Columbia; Chicago, Illinois; Jacksonville, Florida To proceed...Work at officeRemote workShift workDay shift
- ...Role TwelveLabs is looking for a Staff Security Engineer to join our security team, working directly... ...protocols Proven experience with web application security assessments and penetration... ...visibility Have hands‑on offensive security or red team experience Have worked...WebWork at officeWorldwideFlexible hoursShift work
$180k - $247.5k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...this mission. If you are too, let's talk. Join Okta's Defensive Cyber Engineering team as a Staff Engineer responsible for safeguarding Okta...Local areaWorldwideFlexible hours- A leading technology company is seeking a hands-on Security Engineer - Offensive Security in Seattle. This role involves designing and executing offensive security operations, conducting threat emulations, and influencing security investment across various teams. Candidates...
- Information Assurance System Security Engineer We are looking to fill this position... ...) supporting Department of Defense (DoD) agencies, such as HQ... ...security, and Apache/IIS Web server security Experience: 1... ...Information Assurance Manager Level III or Information Assurance...WebWork at office
$148.01k - $207.22k
Software Engineer III page is loaded## Software Engineer IIIlocations:... ...commercial, civil, national security, and human spaceflight.This role... ...schedulers (SLURM, PBS).* Web application development experience... ...for Certain Job Profiles: Defense Biometric Identification System...WebPermanent employmentTemporary workLocal area- ...Security Engineer -Level L2 Arete Technologies, Inc. offers a set of innovative consulting and outsourcing services, bridging the gap between... ...of staff augmentation, IT consultancy, software development, web development providing unexcelled services and focusing on both...WebWorldwide
- ...Experience conducting end to end privacy reviews and DPIA updates Preferred privacy knowledge of consumer areas such as web or advertising and generative experiences Preferred familiarity with Customer privacy standards and systems including 1CS SNOW...Web
- F5 Networks, Inc. is seeking a Security Support Engineer III in Seattle, WA. This role involves assisting customers with diverse and complex security issues, coordinating with engineering teams, and developing solutions. The ideal candidate will have a Bachelor's degree...Remote job
$136k - $184k
...Description At Amazon Healthcare Security, we are on a mission to make healthcare secure... ...convenient. We are looking for a Security Engineer to join our team. As a Security... ...Science, or a related field ~2+ years of web protocols, common security attacks, and remediation...WebTemporary workInternshipFlexible hours$136k - $184k
...As a Product Security Engineer at Amazon Payments Security, you'll be at the forefront of protecting systems that handle financial transactions... ...architecture reviews, threat modelling and code reviews on web applications, mobile applications and other relevant services....WebTemporary workFlexible hours$136k - $184k
...AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every investigation into an opportunity... ...leads. BASIC QUALIFICATIONS - 2+ years of web protocols, common security attacks, and remediation...WebInternshipImmediate startFlexible hours- ...Job Title: Sr. Security Engineer Location: Remote (PST) Duration: 6+ Contract Role Summary We are looking for a senior security... ...video streaming services • Familiarity with mobile and web player security • Knowledge of anti-piracy mechanisms and...WebContract workRemote work
$218.5k - $273.13k
...Senior Security Engineer (Product) New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United... ...knowledge of the role of security in engineering systems and web architecture. Final rounds: You'll meet several more team members...WebWork from homeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer III - Offensive/Defensive Web Security. Be the first to apply!
- staff security engineer Seattle, WA
- senior application security engineer Seattle, WA
- sr information security engineer Seattle, WA
- security engineering manager Seattle, WA
- cloud security engineer Seattle, WA
- endpoint security engineer Seattle, WA
- physical security engineer Seattle, WA
- product security engineer Seattle, WA
- principal security engineer Seattle, WA
- security engineer Seattle, WA


