Overview
In this role you will help protect JPMorgan Chase’s digital assets by detecting, analyzing, and responding to threats and incidents. You will work with cross-functional teams to implement coordinated security strategies and educate colleagues on best practices. Your work strengthens the organization’s cybersecurity posture and supports secure operations across critical systems. You will operate in a fast-paced environment, driving incident response and continuous improvement with a focus on risk reduction and data protection.
Responsibilities
- Monitor and analyze security infrastructure to detect and respond to threats, ensuring data and system integrity
- Conduct in-depth security investigations using logs and network traces to determine root causes and plan mitigations
- Triage security alerts and own investigations through to resolution in incident response
- Create and maintain incident response process documentation and threat detection playbooks
- Collaborate with cross-functional teams to implement security policies and educate staff
- Draft and disseminate vulnerability and intelligence reports for acquisitions
- Engage with acquisitions to assess cybersecurity posture and drive uplifts where needed
- Accept and manage weekend shift requirements and act as escalation point for analysts
Key requirements
- Minimum 3 years in cybersecurity operations (threat detection, incident response, or vulnerability management)
- Experience with network trace analysis, log analysis, vulnerability assessment, exploitation techniques, and security investigations
- Proficiency in scripting for automation, controls, and data manipulation
- Strong understanding of security protocols, cryptography, authentication, and security architecture
- Hands-on experience with SIEM, IDS, EDR, malware analysis tools, and email security solutions
- Knowledge of adversary tactics, attack stages, and detection methods
- Familiarity with Windows and Linux OS and signs of compromise
- Excellent communication skills to present risks to technical and non-technical audiences
- communication
- cross-functional collaboration
- prioritization and workload management
- SIEM
- IDS
- EDR
…
