Description Out of the successful launch of Chase in 2021, we’re a new team, with a new mission. We’re creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We’re people-first. We value collaboration, curiosity and commitment. As a Head of Security at JPMorgan Chase within the International Consumer Bank, you are the heart of this venture, focused on getting smart ideas into the hands of our customers. You have a curious mindset, thrive in collaborative squads, and are passionate about new technology. By your nature, you are also solution-oriented, commercially savvy and have a head for fintech. You thrive in working in tribes and squads that focus on specific products and projects – and depending on your strengths and interests, you'll have the opportunity to move between them. While we’re looking for professional skills, culture is just as important to us. We understand that everyone's unique – and that diversity of thought, experience and background is what makes a good team, great. By bringing people with different points of view together, we can represent everyone and truly reflect the communities we serve. This way, there's scope for you to make a huge difference – on us as a company, and on our clients and business partners around the world. Job responsibilities: Understand complex regulatory and internal security requirements and be able to advise on implementation options Guide & defining the security practices & standards end-to-end, covering external connectivity and internal service communication Interact with 3rd party vendors on security-related aspects during onboarding Interact with senior internal stakeholders - internal auditors, firmwide controls, etc Review & constantly improve existing security practices and standards Provide security architecture review with focus on threat modelling Required qualifications, capabilities and skills: Extensive experience in an engineering role with heavy focus on security (encryption, authorization, authentication, etc) Experience with at least one high-level programming language (Java, Python, etc) Excellent knowledge of security best practices at different stages of the development lifecycle Excellent knowledge of methods for authentication, authorization and encryption (AuthN/Z, JWT, RBAC, TLS, OAuth2) Understanding of applied cryptography - symmetric/asymmetric cryptography Practical experience with TLS certificates setup Understanding of security vulnerabilities and remediation options in codebases (Java/Kotlin/etc) & containers Excellent knowledge of all of the above concepts in the context of at least one (ideally more) public cloud provider (AWS,GCP,Azure) Knowledge of security/identity SaaS vendors (Auth0, Forgerock) Understanding of modern SDLC practices and security aspects & tools of CI/CD pipelines (code scanning, container scanning) ICBcareers ICBEngineering