Aumni - Application Security Engineer

Salt Lake City, UT, United States

JPMorgan Chase & Co.

View company page

As a Security Engineer III at JPMorgan Chase within the Aumni Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm’s business objectives.

The Aumni Information Technology & Security department is responsible for maintaining the IT operations and security of Aumni’s product, systems, and data. We collaborate with all other departments in various capacities with an emphasis on reducing friction where possible while maintaining security. 

Our team’s mission statement is:

To deliver stronger, smarter security solutions, provide peace of mind for the venture capital ecosystem, and enable the success of our customers, employees, and investors.

If you don’t have experience in each area listed below, don’t let that discourage you from applying. We are looking for an individual with a strong foundation, an aptitude to learn, and ability to ask good questions.

Job responsibilities

 

  • Educate our software engineers on secure coding practices and even build out a robust security champions program
  • Vulnerability remediation support
  • Implement & manage various SAST, SCA, DAST, and OSS scanning tools. 
  • Maintain automations that enforce Secure SDLC
  • Secure design reviews

 

Required qualifications, capabilities, and skills

 

  • Formal training or certification on Application Security concepts and proficient advanced experience
  • Must be a team player who is eager to share domain knowledge with the team and eager to learn from others as well
  • Experience of the Secure Software Development Lifecycle Framework.
  • Understanding of security best practices for authentication, authorization, and permissions.
  • Ability to teach developers how to follow security best practices
  • Hands on experience investigating & prioritizing vulnerabilities discovered by third party security tools. (Identifying false positives, out of scope items, adjusting CVSS severity of vulnerability to business context, etc.)
  • Hands on experience with DAST tools
  • Knowledgeable of CI/CD tools and how to integrate security into the pipeline
  • Experience with scripting languages (Bash, Python, etc.)
  • Experience with cloud platforms and securing them
  • Secure Design Reviews
Preferred qualifications, capabilities, and skills  
  • Experience configuring and monitoring secret scanning tools
  • Experience performing high risk code review/testing
  • Knowledge of well-known Security Frameworks (ASVS, NIST CSF)

JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, we offer discretionary incentive compensation which may be awarded in recognition of firm performance and individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Application security Banking Bash CI/CD Cloud CVSS DAST Monitoring NIST Python SAST Scripting SDLC Vulnerabilities

Perks/benefits: Competitive pay Health care Wellness

Region: North America
Country: United States
Job stats:  5  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.