Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer - Cryptographic Libraries & TLS

$152k - $215k

JPMorgan Chase Bank, N.A.

Take on a crucial role where you'll be a key part of a high-performing team building and maintaining foundational cryptographic infrastructure. Make a real impact as you help shape the way secure communications are configured, tested, and deployed across the enterprise at one of the world's largest and most influential companies.

As a Lead Security Engineer at JPMorgan Chase within the CTC Emerging Technologies Security group, you will own and evolve a TLS abstraction layer that provides a unified interface for TLS stack configuration across Java, Python, and Node.js runtimes. You will serve as both a hands-on developer and a subject-matter expert at the intersection of network security protocols and polyglot software engineering. You will be responsible for ensuring that the library remains secure, performant, well-tested, and aligned with evolving TLS standards and enterprise security policy.


Job Responsibilities

  • Design, implement, debug, and extend the TLS abstraction layer, ensuring consistent TLS configuration and behavior across Java (JSSE/Bouncy Castle), Python (ssl/OpenSSL bindings), and Node.js (built-in TLS/OpenSSL) runtimes.
  • Serve as the team's subject-matter expert on TLS 1.2 and 1.3 handshake mechanics, cipher suite negotiation, certificate validation, key exchange algorithms, and session resumption - and translate that expertise into library design decisions.
  • Architect clean, well-documented APIs that decouple application-level TLS intent (e.g., minimum protocol version, allowed cipher suites, certificate pinning, mutual TLS) from the platform-specific implementation details of each runtime's TLS stack.
  • Build and maintain comprehensive test suites - including unit, integration, interoperability, and protocol-conformance tests - that verify correct TLS behavior across all supported runtimes and configurations. Develop test harnesses that exercise edge cases such as certificate chain validation failures, protocol downgrade scenarios, and cipher suite mismatches.
  • Design, maintain, and improve CI/CD pipelines for the library, including automated builds, multi-runtime test matrices, static analysis, dependency scanning, and artifact publishing across all supported language ecosystems (Maven/Gradle, PyPI, npm).
  • Triage and resolve complex TLS-related issues reported by consuming applications, including handshake failures, performance regressions, certificate trust-store misconfigurations, and runtime-specific behavioral differences.
  • Monitor developments in TLS standards (IETF RFCs), cryptographic library updates (OpenSSL, Bouncy Castle), and runtime release notes to proactively assess impact on the library and plan necessary updates.
  • Produce clear integration guides, migration documentation, and configuration references so that consuming teams can adopt and configure the library with minimal friction.
  • Work with application teams, platform engineering, and enterprise security policy owners to gather requirements, communicate breaking changes, and align library capabilities with organizational security mandates.
  • Contribute to a team culture of diversity, equity, inclusion, and mutual respect.
Required Qualifications, Capabilities, and Skills
  • Bachelor's degree in Computer Science, Computer Engineering, or a related field; 7+ years of software development experience, with at least 3 years focused on security-sensitive or infrastructure-level library development.
  • Strong hands-on development skills in at least two of Java, Python, and Node.js/TypeScript, with a willingness and ability to work across all three. Experience with each language's native TLS/cryptographic APIs (e.g., JSSE, Python ssl module, Node.js tls module).
  • Deep understanding of TLS 1.2 and 1.3 - including handshake flows, key exchange mechanisms (ECDHE, DHE), certificate authentication (X.509, chain-of-trust, Certificate Verify), cipher suite semantics, ALPN/SNI, and session management. Familiarity with underlying cryptographic primitives (AES-GCM, ChaCha20-Poly1305, RSA, ECDSA, EdDSA, HKDF).
  • Demonstrated experience designing, versioning, and maintaining libraries or SDKs consumed by other engineering teams, including thoughtful API surface design, semantic versioning, and backward-compatibility management.
  • Proven experience building multi-dimensional test strategies for security-critical software, including protocol-conformance testing, cross-platform interoperability testing, and negative/adversarial test cases.
  • Hands-on experience designing and maintaining CI/CD pipelines (e.g., Jenkins, GitHub Actions, or equivalent), including multi-language build matrices, automated security scanning (SAST, dependency vulnerability checks), and artifact publication.
  • Strong diagnostic skills for network-level issues - comfortable using tools like Wireshark, OpenSSL CLI ( s_client , s_server ), keytool , and language-specific debuggers to trace TLS handshake failures and certificate issues.
  • Solid understanding of agile development methodologies, including iterative delivery, code review discipline, and application resiliency principles.
Preferred Qualifications, Capabilities, and Skills
  • Experience with cryptographic library internals such as OpenSSL, Bouncy Castle, or LibreSSL.
  • Familiarity with FIPS 140-2/140-3 compliance requirements and their impact on TLS configuration and cryptographic provider selection.
  • Experience with mutual TLS (mTLS) at scale, including certificate lifecycle management and automated rotation.
  • Knowledge of PKI systems, HSMs, or key management infrastructure.
  • Experience with container-based build and test environments (Docker, Kubernetes) and cloud platforms (AWS).
  • Familiarity with performance profiling of TLS handshakes and bulk-encryption throughput across runtimes.
  • Experience using AI-assisted development tools (e.g., GitHub Copilot, Claude Code ) to accelerate library development and test generation.
  • Relevant certifications such as CISSP, CCSP, or vendor-specific security credentials are a plus but not required.

#CTC

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.


We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.


We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.


JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

Base Pay/Salary
Palo Alto,CA $152,000.00 - $215,000.00 / year; Seattle,WA $152,000.00 - $215,000.00 / year
Vacancy posted 6 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer - Cryptographic Libraries & TLS in Palo Alto, CA vacancy
  •  ...Lead Security Engineer Take on a crucial role where you'll be a key part...  ...and maintaining foundational cryptographic infrastructure. Make a real...  ...you will own and evolve a TLS abstraction layer that provides...  ...for ensuring that the library remains secure, performant,... 
    Suggested

    Chase

    Palo Alto, CA
    3 days ago
  • $15.36k - $23.04k

     ...Lead Security Engineer (AI) – Product Security USA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our... 
    Suggested
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Nubank

    Palo Alto, CA
    5 days ago
  • $200k - $250k

     ...Security Engineering Lead The most important scientific discoveries of our time won't happen in a traditional lab. We're an AI and physical sciences company building state-of-the-art models to accelerate breakthroughs across materials, energy, and beyond. Backed by... 
    Suggested
    Remote work
    Visa sponsorship
    Flexible hours

    Periodic Labs

    Menlo Park, CA
    4 days ago
  • $172k - $312k

     ...cars. We are looking for a highly motivated engineer who truly believes in security as a first principle. Companies have talked...  ...cryptography and common attacks against modern cryptographic algorithms (encryption at rest, TLS, hashing, etc.) Compensation and... 
    Suggested
    Hourly pay
    Full time
    Temporary work
    Remote work
    Flexible hours

    Tesla

    Palo Alto, CA
    4 days ago
  •  ...Citizens only due to national security regulations. Manager Updates...  ..., involving validation of cryptographic modules, working with labs etc...  ...'s Degree in Electrical Engineering, Computer/Information Science...  ...their design (i.e., SSH, IPsec, TLS, etc.) Be highly proficient... 
    Suggested
    Remote work

    The Fountain Group

    Mountain View, CA
    5 days ago
  • $205.5k - $310.2k

    Senior Principal Security Software Engineer - C and Cryptographic Systems Join us to do the best work of your career and make a profound social impact as a Senior...  ...Policy 15 Understanding of Transport Layer Security (TLS) and Key Management/Data At Rest Encryption (DARE)... 
    Relocation

    Dell Technologies

    Santa Clara, CA
    3 days ago
  • $185k - $205k

     ...is moving towards instant digital payments and TabaPay is leading the way. We help thousands of Fintechs in the US and Canada...  ...learn more visit Position Summary The Lead Cloud & Security Operations Engineer is a senior-level, hands-on technical role responsible for... 
    Work at office
    Remote work
    Flexible hours

    Taba Pay Inc

    Palo Alto, CA
    2 days ago
  • $165k - $242k

     ...Senior Security Engineer, PKI & Secrets Livingston, NJ / New York, NY...  ...with confidence. Trusted by leading AI labs, startups, and global...  ...PKI & Secrets team owns the cryptographic infrastructure underpinning...  ...supporting workload identity, mutual TLS, and hardware attestation.... 
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    5 days ago
  •  ...for all business systems. By combining ServiceNow's leading workflow automation with Moveworks' Reasoning Engine and natural language capabilities, we deliver the...  ...world work better for everyone. The Moveworks Security team at ServiceNow is not looking for a traditional... 
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Mountain View, CA
    4 days ago
  • $176k - $253k

     ...Senior Anti-Abuse Security Engineer At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don't just use tools;... 
    Flexible hours

    Streamlit

    Menlo Park, CA
    5 days ago
  • $113.4k - $252k

     ...The Senior Product Security Engineer will be responsible for securing Navan products, by identifying...  ...You'll Do: Act as the tech lead for high-priority product security...  ...application & network protocols, cryptographic primitives, authentication & authorization... 
    Shift work

    Navan

    Palo Alto, CA
    4 days ago
  • $162k - $260k

     ...LinkedIn. Aurora's Product Security team's mission is to...  ...contributing and documenting security engineering processes and the resulting...  ..., offensive security or cryptographic protocols and concepts ~ Experience...  ...empathy and our ability to lead effectively. As a result, we... 
    Work experience placement
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    Mountain View, CA
    5 days ago
  •  ...We're a team of engineers, clinicians, and innovators...  ...responsible for the security lifecycle of medical...  ...and knowledge of cryptographic tools and libraries. The candidate can review...  ...(15%) Assist in leading and overseeing...  ...firewalls, load-balancing, TLS, switching and... 
    Local area
    Worldwide
    Flexible hours

    Intuitive

    Sunnyvale, CA
    3 days ago
  • $140.6k - $175.8k

     ...diverse, but our team shares a love of the outdoors and a desire to protect it for future generations. Role Summary As a Security Engineer at Rivian, you will spearhead the adversarial evaluation of our AI-enabled features and internal platforms. This role will operate... 
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Shift work

    Rivian

    Palo Alto, CA
    5 days ago
  •  ...Lead Software Engineer Be an integral part of an agile team that's constantly pushing the envelope...  ...Design and develop scalable, secure services using Java Spring Boot, TypeScript...  ..., Canton) Understanding of cryptographic protocols, smart contracts and key management... 

    Chase

    Palo Alto, CA
    5 days ago
  • $130k - $150k

     ...with the ultimate goal of enabling human life on Mars. SECURITY SOFTWARE ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink...  ...of the security design of today’s Internet, including the cryptographic primitives involved. You see the big picture, prioritize... 
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Palo Alto, CA
    4 days ago
  •  ...Senior/Staff Security Engineer About Zettabyte At Zettabyte , we’re building the infrastructure layer for the AI-first world. Our mission...  ...chain , from CI/CD pipelines to container admission Lead threat modeling and security design reviews for new platform... 

    Zettabyte

    Palo Alto, CA
    1 day ago
  • $140k - $240k

     ...approach allows Cerebras to deliver industry-leading training and inference speeds and...  ...Role In this role, you will be the security czar for the Cerebras's AI cluster product...  ...principles, best practices, security-first based engineering. Cerebras cluster involves complex HW... 

    CEREBRAS SYSTEMS INC.

    Sunnyvale, CA
    4 days ago
  • $130.3k - $179.2k

     ...Company Description Guardant Health is a leading precision oncology company focused on guarding wellness and giving every person...  ...) and Facebook. Position Summary: The Senior Security Engineer, reporting to the Associate Director of Security Engineering,... 
    Work at office
    Work from home

    Guardant Health

    Palo Alto, CA
    5 days ago
  •  ...Role: AWS Security Engineer Location: Mountain View, CA (Day one onsite) Duration: Fulltime only Job Description: Basic Qualifications: • Bachelor's degree in Information Security, Computer Science, Risk Management, Engineering,... 
    Full time

    Zortech Solutions

    Mountain View, CA
    1 day ago
  • $209k - $313k

     ...Snapchat and other services; and its AR glasses, Spectacles. Snap Security teams protect the trust and safety of our global community by...  ...privacy at the forefront. We’re looking for a Senior Security Engineer to join our Detection and Response (D&R) team! What you’ll do:... 
    Live in
    Work at office
    Local area

    Snap

    Palo Alto, CA
    2 days ago
  • $216k - $264k

     ...Senior Security Engineer Fortinet (NASDAQ: FTNT) is a worldwide provider of network security appliances...  ...the Vulnerability Management program Lead the internal Fortinet products...  ...related protocols (e.g., TCP/IP, UDP, IPSEC, TLS, DNS, DHCP NetFlow, BGP, OSPF, IPv6 etc.... 
    Full time
    Work experience placement
    Flexible hours

    Edelman

    Sunnyvale, CA
    2 days ago
  • $180k - $258k

     ...Senior Security Engineer We're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our platforms are resilient against all threats while meeting compliance requirements... 
    Flexible hours

    Candid Health

    Menlo Park, CA
    5 days ago
  •  ...Remote Network Security Engineer Position March 15, 2026 In today's increasingly connected world, robust network security is not just a feature...  ...plans and oversee their implementation. Incident Response: Lead and participate in the response to security incidents,... 
    Remote work

    Ip Check

    Palo Alto, CA
    3 days ago
  • Junior-Level Security Engineer Client is seeking a US-based, junior-level security engineer with a generalist skill set in application and cloud security, strong coding abilities (especially Python), and a proactive, ownership-driven mindset.
    Remote work

    Insight Global

    Mountain View, CA
    2 days ago
  • $185k - $210k

     ...The Opportunity We are seeking an experienced Security Engineer to join our team and help secure Otter's cloud infrastructure and the...  ...continuously improve detection quality and reduce noise. Lead incident response for cloud security events and help mature... 
    Permanent employment

    Otter.ai

    Mountain View, CA
    2 days ago
  • $60 per hour

     ...FocusKPI is seeking a Senior Offensive Security Engineer (Web & AI systems) to join one of our clients, a high-tech SaaS company.  Team is...  ...to raise the security bar across the organization. You will lead complex penetration tests, design novel attack techniques for... 
    Contract work
    Work at office

    FocusKPI Inc.

    Mountain View, CA
    1 day ago
  •  ...Role: Zscaler DLP Security Engineer (Zscaler Data Loss Prevention) Location: Mountain View CA / San Diego CA / Plano TX (Min 3 days/week) Job Overview We value the security of customer and employee data, across multiple enterprise platforms, against insider... 
    3 days per week

    United IT Solutions

    Mountain View, CA
    5 days ago
  • $118k - $176k

     ...and other services; and its AR glasses, Spectacles ( . Snap Security teams protect the trust and safety of our global community by securing...  ...privacy at the forefront. We are looking for a Security Engineer to join our Enterprise Infrastructure Security (EIS) team!... 
    Live in
    Work at office
    Local area

    Snap

    Palo Alto, CA
    6 days ago
  • $157k - $185k

     ...performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Engineering team builds systems and practices that help protect Robinhood’s platform, infrastructure, and customers at scale. The team... 
    Permanent employment
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Menlo Park, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer - Cryptographic Libraries & TLS. Be the first to apply!