Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer Cryptographic Libraries & TLS

Chase

Lead Security Engineer

Take on a crucial role where you'll be a key part of a high-performing team building and maintaining foundational cryptographic infrastructure. Make a real impact as you help shape the way secure communications are configured, tested, and deployed across the enterprise at one of the world's largest and most influential companies.

As a Lead Security Engineer at JPMorgan Chase within the CTC Emerging Technologies Security group, you will own and evolve a TLS abstraction layer that provides a unified interface for TLS stack configuration across Java, Python, and Node.js runtimes. You will serve as both a hands-on developer and a subject-matter expert at the intersection of network security protocols and polyglot software engineering. You will be responsible for ensuring that the library remains secure, performant, well-tested, and aligned with evolving TLS standards and enterprise security policy.

Job Responsibilities

  • Design, implement, debug, and extend the TLS abstraction layer, ensuring consistent TLS configuration and behavior across Java (JSSE/Bouncy Castle), Python (ssl/OpenSSL bindings), and Node.js (built-in TLS/OpenSSL) runtimes.
  • Serve as the team's subject-matter expert on TLS 1.2 and 1.3 handshake mechanics, cipher suite negotiation, certificate validation, key exchange algorithms, and session resumption — and translate that expertise into library design decisions.
  • Architect clean, well-documented APIs that decouple application-level TLS intent (e.g., minimum protocol version, allowed cipher suites, certificate pinning, mutual TLS) from the platform-specific implementation details of each runtime's TLS stack.
  • Build and maintain comprehensive test suites — including unit, integration, interoperability, and protocol-conformance tests — that verify correct TLS behavior across all supported runtimes and configurations. Develop test harnesses that exercise edge cases such as certificate chain validation failures, protocol downgrade scenarios, and cipher suite mismatches.
  • Design, maintain, and improve CI/CD pipelines for the library, including automated builds, multi-runtime test matrices, static analysis, dependency scanning, and artifact publishing across all supported language ecosystems (Maven/Gradle, PyPI, npm).
  • Triage and resolve complex TLS-related issues reported by consuming applications, including handshake failures, performance regressions, certificate trust-store misconfigurations, and runtime-specific behavioral differences.
  • Monitor developments in TLS standards (IETF RFCs), cryptographic library updates (OpenSSL, Bouncy Castle), and runtime release notes to proactively assess impact on the library and plan necessary updates.
  • Produce clear integration guides, migration documentation, and configuration references so that consuming teams can adopt and configure the library with minimal friction.
  • Work with application teams, platform engineering, and enterprise security policy owners to gather requirements, communicate breaking changes, and align library capabilities with organizational security mandates.
  • Contribute to a team culture of diversity, equity, inclusion, and mutual respect.

Required Qualifications, Capabilities, and Skills

  • Bachelor's degree in Computer Science, Computer Engineering, or a related field; 7+ years of software development experience, with at least 3 years focused on security-sensitive or infrastructure-level library development.
  • Strong hands-on development skills in at least two of Java, Python, and Node.js/TypeScript, with a willingness and ability to work across all three. Experience with each language's native TLS/cryptographic APIs (e.g., JSSE, Python ssl module, Node.js tls module).
  • Deep understanding of TLS 1.2 and 1.3 — including handshake flows, key exchange mechanisms (ECDHE, DHE), certificate authentication (X.509, chain-of-trust, Certificate Verify), cipher suite semantics, ALPN/SNI, and session management. Familiarity with underlying cryptographic primitives (AES-GCM, ChaCha20-Poly1305, RSA, ECDSA, EdDSA, HKDF).
  • Demonstrated experience designing, versioning, and maintaining libraries or SDKs consumed by other engineering teams, including thoughtful API surface design, semantic versioning, and backward-compatibility management.
  • Proven experience building multi-dimensional test strategies for security-critical software, including protocol-conformance testing, cross-platform interoperability testing, and negative/adversarial test cases.
  • Hands-on experience designing and maintaining CI/CD pipelines (e.g., Jenkins, GitHub Actions, or equivalent), including multi-language build matrices, automated security scanning (SAST, dependency vulnerability checks), and artifact publication.
  • Strong diagnostic skills for network-level issues — comfortable using tools like Wireshark, OpenSSL CLI (s_client, s_server), keytool, and language-specific debuggers to trace TLS handshake failures and certificate issues.
  • Solid understanding of agile development methodologies, including iterative delivery, code review discipline, and application resiliency principles.

Preferred Qualifications, Capabilities, and Skills

  • Experience with cryptographic library internals such as OpenSSL, Bouncy Castle, or LibreSSL.
  • Familiarity with FIPS 140-2/140-3 compliance requirements and their impact on TLS configuration and cryptographic provider selection.
  • Experience with mutual TLS (mTLS) at scale, including certificate lifecycle management and automated rotation.
  • Knowledge of PKI systems, HSMs, or key management infrastructure.
  • Experience with container-based build and test environments (Docker, Kubernetes) and cloud platforms (AWS).
  • Familiarity with performance profiling of TLS handshakes and bulk-encryption throughput across runtimes.
  • Experience using AI-assisted development tools (e.g., GitHub Copilot, Claude Code) to accelerate library development and test generation.
  • Relevant certifications such as CISSP, CCSP, or vendor-specific security credentials are a plus but not required.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer Cryptographic Libraries & TLS in Palo Alto, CA vacancy
  •  ...applying advanced cryptographic techniques within...  ...Emerging Technologies Security group within the...  ...security engineers to solve complex security...  ...Research & Development: Lead the analysis and...  ...cryptographic libraries  Evaluate existing...  ...protocols (e.g., TLS, IPsec etc.)  Industry... 
    Suggested

    JPMorgan Chase & Co.

    Palo Alto, CA
    1 day ago
  • $15.36k - $23.04k

     ...Lead Security Engineer (AI) – Product Security USA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our... 
    Suggested
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Nubank

    Palo Alto, CA
    4 days ago
  • $250k - $350k

     ...insatiable drive to push the boundaries of what's scientifically possible. About the Role You will lead, design, build, and operate security engineering at Periodic Labs. You will secure the systems that power our research and operations, including cloud environments... 
    Suggested
    Remote work
    Visa sponsorship

    Periodic Labs

    Menlo Park, CA
    3 days ago
  •  ...Nectar in Palo Alto is seeking a Security Engineer to manage security across our enterprise SaaS platform. The role involves overseeing the security of deployed applications and leading compliance initiatives while ensuring enterprise-grade security for our customers.... 
    Suggested

    Nectar Inc

    Palo Alto, CA
    1 day ago
  • $172k - $312k

     ...cars. We are looking for a highly motivated engineer who truly believes in security as a first principle. Companies have talked...  ...cryptography and common attacks against modern cryptographic algorithms (encryption at rest, TLS, hashing, etc.) Compensation and... 
    Suggested
    Hourly pay
    Full time
    Temporary work
    Remote work
    Flexible hours

    Tesla

    Palo Alto, CA
    3 days ago
  • $220.5k - $300k

     ...Latent AI is seeking a Principal Security Software Engineer to enhance security measures using AI within their Starshield program. This role involves designing and implementing security solutions and automating security processes. Candidates should have a strong background... 

    Latent AI

    Palo Alto, CA
    1 day ago
  •  ...Citizens only due to national security regulations. Manager Updates...  ..., involving validation of cryptographic modules, working with labs etc...  ...'s Degree in Electrical Engineering, Computer/Information Science...  ...their design (i.e., SSH, IPsec, TLS, etc.) Be highly proficient... 
    Remote work

    The Fountain Group

    Mountain View, CA
    9 days ago
  • $205.5k - $310.2k

     ...Senior Principal Security Software Engineer – C and Cryptographic Systems Join us to do the best work of your career and make a profound social impact as a...  ...Policy 15 Understanding of Transport Layer Security (TLS) and Key Management/Data At Rest Encryption (DARE) Excellent... 
    Relocation

    Dell Technologies

    Santa Clara, CA
    1 day ago
  • $185k - $205k

     ...Lead, Cloud & Security Operations Engineer Palo Alto, CA The world is moving towards instant digital payments and TabaPay is leading the way. We help thousands of Fintechs in the US and Canada instantly move money in and out of accounts and we are actively expanding... 
    Work at office
    Remote work
    Flexible hours

    Taba Pay Inc

    Palo Alto, CA
    6 days ago
  • $150k - $250k

    A cybersecurity firm in Sunnyvale, California, is seeking a technical leader to build a core endpoint security agent. This role involves architecting a resilient system while tackling complex challenges in OS integrations, including Windows internals. The ideal candidate... 

    Cylake, Inc

    Sunnyvale, CA
    5 days ago
  • $150k - $250k

    A cybersecurity firm in Sunnyvale is seeking a technical leader to build their core endpoint security agent. The ideal candidate will have over 5 years of experience in systems-level programming and strong Rust skills. The role involves tackling complex security challenges... 

    Cylake

    Sunnyvale, CA
    5 days ago
  • $165k - $242k

     ...Senior Security Engineer, PKI & Secrets Livingston, NJ / New York, NY...  ...with confidence. Trusted by leading AI labs, startups, and global...  ...PKI & Secrets team owns the cryptographic infrastructure underpinning...  ...supporting workload identity, mutual TLS, and hardware attestation.... 
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    4 days ago
  •  ...platform. About the Role As our Lead Firmware Engineer, you will own the "brain" of our...  ...experience implementing hardware‑based security features (e.g., Secure Boot, TrustZone, Cryptographic Co‑processors ) and secure communication protocols (TLS/DTLS over BLE). Compliance... 

    Femtech Insider Ltd.

    Mountain View, CA
    1 day ago
  • $262k - $365k

    Google Inc. in Sunnyvale, CA, is looking for a Software Engineering Manager to lead embedded security projects and manage a team. The ideal candidate has a strong background in embedded software development, technical leadership, and people management. This role involves... 

    Google Inc.

    Sunnyvale, CA
    5 days ago
  • $147k - $237.5k

     ...Palo Alto Networks, Inc. is seeking a Principal Software Engineer in Santa Clara, California, to drive the technical leadership and delivery of high-scale cloud security solutions. In this high-impact role, you will tackle complex network security challenges, manage the... 

    Palo Alto Networks

    Santa Clara, CA
    1 day ago
  • $176k - $253k

     ...the opportunity to help set the direction of the anti-abuse roadmap and Product Security while working closely with other teams at Snowflake. As an Senior Anti-Abuse Security Engineer , you will design, build, and operate systems that protect our platform,... 
    Flexible hours

    Snowflake Computing

    Menlo Park, CA
    2 days ago
  • $187k - $220k

     ...so are the rewards. The Product and Application Security team builds and operates systems that help engineers identify and resolve security risks earlier in the...  ...team creates practical safeguards, including shared libraries, frameworks, and automated checks that make... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    I did my part and supported the Regular Toilet

    Menlo Park, CA
    1 day ago
  •  ...for all business systems. By combining ServiceNow's leading workflow automation with Moveworks' Reasoning Engine and natural language capabilities, we deliver the...  ...world work better for everyone. The Moveworks Security team at ServiceNow is not looking for a traditional... 
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Mountain View, CA
    3 days ago
  • $113.4k - $252k

     ...The Senior Product Security Engineer will be responsible for securing Navan products, by identifying...  ...You'll Do: Act as the tech lead for high-priority product security...  ...application & network protocols, cryptographic primitives, authentication & authorization... 
    Shift work

    Navan

    Palo Alto, CA
    3 days ago
  • $162k - $260k

     ...LinkedIn. Aurora's Product Security team's mission is to...  ...contributing and documenting security engineering processes and the resulting...  ..., offensive security or cryptographic protocols and concepts ~ Experience...  ...empathy and our ability to lead effectively. As a result, we... 
    Work experience placement
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    Mountain View, CA
    4 days ago
  • Senior Security Engineer, Security Operations - Responsible for automating the entire security operations lifecycle with AI and advanced detection techniques. Working within ServiceNow’s global platform, this role builds autonomous workflows that replace manual SOC practices... 
    Full time
    Remote work
    Flexible hours

    ServiceNow

    Mountain View, CA
    5 days ago
  • $174k - $252k

    Senior Security Engineer, Google Photos AI Security corporate_fare Google place Mountain View, CA, USA Qualifications Bachelor's degree or...  ...one or more general purpose languages. 1 year of experience leading teams in a technical capacity or leading technical risk analysis... 
    Full time
    Work at office

    Google Inc.

    Mountain View, CA
    5 days ago
  • $140.6k - $175.8k

     ...diverse, but our team shares a love of the outdoors and a desire to protect it for future generations. Role Summary As a Security Engineer at Rivian, you will spearhead the adversarial evaluation of our AI-enabled features and internal platforms. This role will operate... 
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Shift work

    Rivian

    Palo Alto, CA
    4 days ago
  •  ...Lead Software Engineer Be an integral part of an agile team that's constantly pushing the envelope...  ...Design and develop scalable, secure services using Java Spring Boot, TypeScript...  ..., Canton) Understanding of cryptographic protocols, smart contracts and key management... 

    Chase

    Palo Alto, CA
    4 days ago
  • $168k - $230k

     ...A leading aerospace company in Palo Alto is seeking a Sr. Security Software Engineer for their Starshield program. The role involves designing and implementing security...  ...like Python or C++, and an understanding of cryptographic principles. Competitive annual salary ranges... 

    SPACE EXPLORATION TECHNOLOGIES CORP

    Palo Alto, CA
    2 days ago
  • $130k - $150k

     ...with the ultimate goal of enabling human life on Mars. SECURITY SOFTWARE ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink...  ...of the security design of today’s Internet, including the cryptographic primitives involved. You see the big picture, prioritize... 
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Palo Alto, CA
    3 days ago
  •  ...Rivian VW Group is seeking a Product Security Engineer based in Palo Alto, California. In this role, you'll create and validate security requirements for our vehicles, leading efforts in security testing and documentation. We're looking for someone with a B.S. in a relevant... 

    Rivian VW Group

    Palo Alto, CA
    1 day ago
  • $15.36k - $23.04k

     ...Lead Systems Engineer - Traffic Management USA, Durham; USA, Miami; USA, Palo...  ...services reachable and secure. It is the layer that routes...  ...balancers, reverse proxies, TLS/mTLS and routing, and using...  ...platform capabilities or shared libraries for other engineers — abstractions... 
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Nubank

    Palo Alto, CA
    4 days ago
  • $140k - $240k

     ...approach allows Cerebras to deliver industry-leading training and inference speeds and...  ...Role In this role, you will be the security czar for the Cerebras's AI cluster product...  ...principles, best practices, security-first based engineering. Cerebras cluster involves complex HW... 

    CEREBRAS SYSTEMS INC.

    Sunnyvale, CA
    3 days ago
  •  ...No 3rd Party Candidates or 3rd Parties must be a W2 consultant, in addition this is a hybrid 2 days onsite. Hands-On Security Engineering Experience Mid-level engineer with 4–6 years of practical experience Someone technical and execution-focused rather than... 
    Flexible hours

    ECLARO

    Los Altos, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer Cryptographic Libraries & TLS. Be the first to apply!