Sr Lead Cloud Security Engineer (AWS)
JPMorgan Chase View all jobs
- Dublin
- Permanent
- Full-time
- Contribute to the evolution of a multi-year information risk and control strategy for public cloud.
- Lead risk-based design and assessment of security controls across cloud services and platforms.
- Chair governance forums, make risk acceptance decisions, and drive remediation and benefits realization.
- Partner with senior leaders to embed “security by design” across engineering, product, and risk teams.
- Set the operating model for infrastructure-as-code security, including guardrails and automated controls.
- Establish and maintain documentation, standards, and playbooks for scalable security programs.
- Build, mentor, and lead a high-performing team of security engineers and risk analysts.
- Define and report control effectiveness and residual risk through executive dashboards.
- Drive tooling and automation strategy for cloud security, including vendor management and integration.
- Strengthen cloud incident preparedness and response through threat modeling and post-incident reviews.
- Implement agile delivery mechanisms for security programs at scale.
- Deep expertise securing public cloud environments, including identity management, network segmentation, data protection, and native cloud services across AWS, Azure, or GCP.
- Proven leadership of cross-functional security programs with measurable outcomes.
- Exceptional executive communication and stakeholder management skills.
- Ability to translate policy and risk requirements into practical designs and policy-as-code guardrails.
- Hands-on familiarity with Terraform, infrastructure-as-code security, DevSecOps, and CI/CD concepts.
- Strong program execution under tight timelines; highly self-directed with a bias for action and ownership.
- Advanced cloud and security certifications (e.g., AWS/Azure/GCP Professional or Specialty, CISSP, CCSP, CISM).
- Experience deploying and operating CSPM, CIEM, or CWPP solutions.
- Experience influencing VP+ stakeholders and navigating complex prioritization across platforms.
- Familiarity with enforcement frameworks such as OPA or Sentinel.
- Experience engaging internal audit and external regulators with clear narratives and remediation roadmaps.
- Background in developing and maintaining agile delivery mechanisms for security programs.
- Ability to mentor and develop talent within a matrixed team environment.