368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$124k – $274k per year (Estimated)
Location
In office (Wilmington)
Overview
Company
Impact
Profile match
JPMorgan Chase & Co. is a leading global financial services firm and the largest banking institution in the United States by assets. Headquartered in New York City, the company offers a comprehensive range of financial solutions, including investment banking, asset management, treasury services, and commercial banking. Through its widely recognized consumer division, Chase, it delivers retail banking, credit card, and mortgage services to tens of millions of households across the globe.

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

As an Assessments & Exercises Vice President in the Cybersecurity and Technology Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Design and deploy risk-driven tests and simulations (or manage a highly skilled team that does) and inform analysis to clearly outline root-causes. In this role, you will evaluate preventative controls, incident response processes, and detection capabilities, and advise cross-functional teams on security strategy and risk management.

JPMC’s Assurance Operations organization is looking to expand its Cybersecurity Red Team with an experienced Business Process Red Team Operator specialized in social engineering and assessments of critical business processes such as payment operations, fraud, and supplier management. The primary focus of this role will be to perform and manage hands-on offensive security activities leveraging social engineering skillsets as part of Red Team engagements against critical JPMC assets. The successful candidate will have a proven track record in cybersecurity assessments, to include social engineering operations like phishing and vishing, and will be able to demonstrate a general knowledge of computer networking fundamentals, modern threats and vulnerabilities, attack methodologies, and penetration testing tools. The Cybersecurity Red Team consists of highly skilled and qualified members who conduct advanced adversary emulation operations to replicate cybersecurity threats targeting the firm. This position is anticipated to require the use of one or more High Risk Role (HRR) systems, which mandates successful completion of enhanced screening, including criminal and credit background checks, before starting employment and annually thereafter.

Job responsibilities

  • Perform and manage hands-on offensive security activities leveraging social engineering skillsets as part of Red Team engagements against critical JPMC assets
  • Conduct business process assessments to include tabletop or workshop sessions, live testing of business process controls by technical and social engineering attacks, and preparation of deliverables for senior stakeholders
  • Design and execute testing and simulations - such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
  • Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics

Required qualifications, capabilities, and skills

  • 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
  • Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
  • Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels
  • Candidate should have the ability to perform targeted, covert security tests with vulnerability identification, exploitation, and post-exploitation activities
  • Strong understanding of the following: Networking fundamentals (all OSI layers, protocols); Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation techniques; commercial or open-source offensive security tools for reconnaissance, scanning, exploitation, and post-exploitation (e.g. Cobalt Strike, Metasploit, Nmap, Nessus, Burp Suite)
  • Familiarity with AI/ML technologies and tools and operationalizing their use in Red Teaming (e.g., developing video and audio deepfakes, etc.), as well as with system administration skills such as configuration, maintenance, and interpretation of log output from networking devices, operating systems, and infrastructure services and with cloud architecture, operations, and security vulnerabilities
  • Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals
  • Broad experience in multiple businesses or verticals, with organizational and cultural understanding of call centers, payments processes, client service/sales organizations, and operational support staff
  • The ability to articulate and visually present complex technical and fraud subject matter to a wide and senior audience
  • Ability to analyze and produce reports about cybersecurity and fraud vulnerabilities, threats, designs, and procedures

Preferred qualifications, capabilities, and skills

  • Social engineering background (or intelligence, law enforcement, or similar experience)
  • Experience in fraud detection and prevention, with a proven track record in identifying, analyzing, and mitigating fraud risks within financial systems or similar environments.
  • Understanding of relevant regulations and compliance requirements related to fraud prevention, such as AML (Anti-Money Laundering) and KYC (Know Your Customer) standards
  • Relevant certifications such as those offered by Offensive Security (OSCP, OSEP), CREST (Certified Simulated Attack Specialist), SANS (GPEN, GWAPT), fraud-specific certifications such as Certified Fraud Examiner or Certified Anti-Money Laundering Specialist (CAMS)
  • Technical knowledge such as: developing in-house scripting; using interpreted languages (such as Ruby, Python, or Perl) and compiled languages (such as C, C++, C#, or Java); understanding security tools or technology such as firewalls, IDS/IPS, web proxies, and DLP
  • Information Security experience in two or more of the following verticals: fraud operations, threat modeling, network/application security testing, social engineering, Red Team operations, and network exploitation operations
  • Ability to support and grow skillsets for Cybersecurity Red Team operations

#CTC

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Wilmington
up to $37k per year (gross) • In office • Full-Time • 3+ years exp • Novosibirsk
Bash
PowerShell
Python
AI/ML
Red Teaming
DevOps
AWS
IAM
Cybersecurity
Least Privilege
Metasploit
MITRE ATT&CK
Nessus
Nmap
OpenVAS
Snort
Suricata
Wazuh
Management
Slack
Apply
Threat Researcher 1 day ago
$100k – $228k per year (Estimated) • In office • 5+ years exp • Tel Aviv
Python
Java
Java
Spring Boot
AI/ML
Claude
Claude Code
DevOps
AWS
Azure
CI/CD
GCP
Kubernetes
Cybersecurity
Burp Suite
CVE
Metasploit
Nmap
Nuclei
Wiz
Apply
$33k – $86k per year (Estimated) • Remote • Contractor • Bachelor's Degree
DevOps
Kali Linux
Cybersecurity
Burp Suite
Nmap
SQLmap
Apply
In office • 5+ years exp
PowerShell
DevOps
Azure
Azure DevOps
CI/CD
Splunk
Cybersecurity
CWE
Invicti
ISO 27001
Maltego
Metasploit
Nmap
OWASP Top 10
Qualys Cloud Platform
SonarQube
Wazuh
Wireshark
Wiz
Apply
QA Engineer I 1 day ago
$8.5k – $36k per year (Estimated) • In office • Bengaluru
Mobile
Firebase
DevOps
Rest API
Cybersecurity
Burp Suite
Management
Jira
QA
Charles Proxy
Postman
Apply
$127k – $254k per year (Estimated) • In office • 2+ years exp • Wilmington
Java
Python
SQL
Python
pySpark
Databases
Databricks
Snowflake
AI/ML
Spark
DevOps
AWS
CI/CD
Analytics
ETL/ELT
Apply
$193k – $390k per year (Estimated) • In office • 5+ years exp • New York
Marketing
Salesforce
Apply
$140k – $284k per year (Estimated) • In office • 5+ years exp • Seattle
C#
Java
Python
AI/ML
LLM
MLFlow
vLLM
DevOps
CI/CD
Docker
Grafana
Kubernetes
Prometheus
Apply
In office • 7+ years exp • PhD
AI/ML
NLP
NumPy
PyTorch
Recommender Systems
Reinforcement Learning
Scikit-learn
Speech Recognition
TensorFlow
Time Series Forecasting
DevOps
CI/CD
Apply
In office • 3+ years exp
JavaScript
Python
Mobile
JUnit
DevOps
CI/CD
GitLab
GitLab CI
Jenkins
QA
Appium
Rest-Assured
Selenium
TestNG
Apply
$142k – $224k per year • In office • Full-Time • Bachelor's Degree • Wilmington
Apply
Lead AI Engineer 6 hours ago
$186k – $286k per year • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • Wilmington
Java
Python
C#
TypeScript
JavaScript
Java
Spring Boot
C#
.NET
AI/ML
Claude
Copilot
LLM
Anthropic
OpenAI
Frontend
Angular
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitLab CI
Jenkins
Kubernetes
OpenShift
Rest API
GitLab
Apply
$120k – $150k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Wilmington
Management
Confluence
Jira
Trello
Apply
ML Engineer 1 day ago
$180k – $220k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Wilmington
Python
SQL
AI/ML
LightGBM
LLM
PyTorch
Scikit-learn
Spark
TensorFlow
XGBoost
Amazon SageMaker
Feature Store
LLM Guardrails
DevOps
AWS
Analytics
A/B Testing
Apply
$127k – $254k per year (Estimated) • In office • 2+ years exp • Wilmington
Java
Python
SQL
Python
pySpark
Databases
Databricks
Snowflake
AI/ML
Spark
DevOps
AWS
CI/CD
Analytics
ETL/ELT
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.