Senior Security Architect – SecOps and Vulnerability Management

Company: JP Morgan Chase
Apply for the Senior Security Architect – SecOps and Vulnerability Management
Location: London
Job Description:

Overview

In this role you partner with technology and business teams to identify and address security issues, embedding a security-first culture and leading threat modeling and architecture reviews. You will influence product strategy, manage emerging risks, and serve as the subject matter expert for SecOps and Vulnerability Management, including detection and response capabilities on modern stacks. You collaborate globally on audit, regulatory, and risk initiatives with a focus on cloud and emerging technologies, shaping secure-by-design products and resilient architectures.

Responsibilities

  • Design, scale, and manage enterprise SIEM architecture for centralized visibility and threat detection across corporate and cloud infra
  • Develop advanced SIEM correlation rules, parsers, and detection logic to reduce alert fatigue for SOC
  • Architect SBOM lifecycle to track and mitigate open-source and third-party supply chain risks
  • Design risk-based vulnerability management platform prioritizing flaws using real-world exploit intelligence and asset criticality
  • Build SOAR playbooks to automate incident response, threat containment, and vulnerability ticketing
  • Provide senior escalation support during security incidents and lead post-incident root-cause analysis
  • Foster security-first culture with developer-friendly tooling and reusable secure patterns to speed delivery
  • Manage emerging security issues, monitor risk indicators, and escalate where needed
  • Partner with engineering leads, product owners, and vendors to translate regulatory requirements into actionable controls
  • Support audits and regulatory activities with evidence of control effectiveness and automated processes
  • Leverage enterprise AI capabilities to accelerate risk analysis and control validation with proper data handling
  • Promote reuse of AI-assisted security validation within SDLC/toolchain for better testing, remediation, and traceability

Key requirements

  • Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps)
  • Proficiency in advanced detection logic (KQL, SPL, or YARA)
  • Experience with SBOMs (CycloneDX or SPDX) and tools like Dependency-Track or Snyk
  • Advanced threat modeling (e.g., STRIDE-LM) for SIEM data flows and vulnerability management
  • Experience architecting vulnerability programs with Tenable, Qualys, or Wiz; utilizing EPSS and CVSS for patch prioritization
  • Ability to design and influence automated SOAR playbooks
  • Experience creating reference architectures and scalable guardrails
  • Strong communication and stakeholder influence
  • Experience using AI capabilities in security workflows with validation and data sensitivity awareness
  • Ability to evaluate AI-assisted security recommendations and ensure alignment with security and auditability expectations
  • Strong written and verbal communication
  • Influencing peers and stakeholders
  • Developer-friendly mindset and collaboration across teams
  • Microsoft Sentinel
  • Splunk
  • Chronicle/SecOps

…

Posted: October 1st, 2026