Location
London
Hours
Full Time
Salary
Competitive, commensurate with experience
About the Role
Join JPMorganChase to directly influence the future of technology as a Senior DevSecOps Architect. Collaborate with top cybersecurity and engineering talent to solve complex challenges and enable safe, secure innovation. In this role within the Cybersecurity & Technology Controls team for International Consumer, you will proactively partner with technology and business colleagues to identify and address security issues, embed a security-first culture, lead threat modeling, and drive architecture reviews to ensure products are secure by design. You will manage emerging risks, influence product strategy, and serve as the subject matter expert for DevSecOps strategy, embedding automated security controls into CI/CD pipelines. This role involves global collaboration supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies.
Job Responsibilities
- Design, implement, and continuously improve security architecture for CI/CD pipelines and DevOps toolchains, embedding automated security checks at every stage from code commit to production deployment.
- Champion Infrastructure as Code (IaC) and Security-as-Code practices, including policy enforcement, security linting, and automated compliance validation across cloud environments.
- Lead advanced threat modeling (e.g., STRIDE-LM) for pipelines, microservices, and cloud-native applications, and conduct architecture reviews to promote secure design patterns.
- Design and deploy automated preventive and detective guardrails to proactively reduce risk across CI/CD pipelines, cloud, and SaaS environments.
- Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns that accelerate delivery.
- Manage emerging security issues with urgency, monitor risk indicators, and recommend resolutions; serve as escalation point for IT Risk and Cyber domains related to DevSecOps and Change Management.
- Partner with engineering leads, product owners, and vendors to ensure effective technology risk management, translating regulatory and policy requirements into actionable, engineer-friendly controls.
- Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes.
- Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in DevSecOps maturity.
- Utilize enterprise-authorized AI capabilities to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements.
- Drive reuse-first adoption of AI-assisted security validation within SDLC/toolchain routines, improving control testing, remediation quality, and traceability/auditability in line with resiliency expectations.
Experience
- Advanced threat modeling experience (e.g., STRIDE-LM) for DevOps/CI/CD pipelines and toolchains.
- Expert ability to advise and influence secure pipeline architecture using Policy-as-Code and automated gates.
- Hands-on security expertise in AWS and GCP.
- Practical experience creating reference architectures and patterns for engineering teams.
- Proven ability to design and deploy automated preventive and detective guardrails at scale.
- Expertise in leveraging IaC scanning to detect misconfigurations and compliance violations across Terraform and Kubernetes manifests.
- Hands-on experience integrating a comprehensive DevSecOps tooling stack including SAST, SCA, RASP, IAST, container and image scanning, secrets detection, and AI-powered DAST solutions.
- Experience implementing and managing SBOMs to track internal, third-party risk and supply chain security.
- Ability to solve design and functionality problems independently.
- Strong written and verbal communication skills.
- Demonstrated success influencing peers and stakeholders.
- Ability to evaluate and recommend emerging technologies for future state architecture.
- Experience using enterprise-authorized AI capabilities to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
- Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring alignment with security, resiliency, and auditability expectations.
About You
- Passionate about security and innovation with a drive to make a real impact.
- Collaborative and able to work effectively with global teams.
- Proactive in managing risks and driving continuous improvement.
- Strong mentoring skills and willingness to foster a security-first culture.
- Willingness to challenge existing processes respectfully and learn modern technologies.
Qualifications
- Relevant certifications such as AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, CISSP, CKS, OSCP are preferred.
- Proven track record in Shift-Left/Start-Left evangelism and mentoring developers.
- Experience operating in regulated organizations with a 3LoD model.
- Experience translating policy and regulatory requirements into control design for engineers and architects.
- Experience in financial services consumer businesses or Fintech organizations is advantageous.
JPMorganChase










