Lead Security Engineer - Red Team
Job Description
JPMorgan Chase offers a compelling, benefits-forward environment for a Lead Security Engineer - Red Team in Plano, TX, onsite. This role sits within the Cybersecurity & Technology Controls for AI/ML and centers on leading security engineering efforts, AI red teaming, threat modeling, and secure software design across AI/ML systems. The compensation package is structured with a base salary determined by the role, experience, skill set, and location, plus commission-based pay and/or discretionary incentive compensation paid in cash and/or forfeitable equity. You’ll also have access to comprehensive health coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, and financial coaching.
Responsibilities
- Design, develop, and deploy enterprise-scale software applications and services with a secure-by-design mindset and adversarially resilient AI-enabled systems.
- Engage across all SDLC phases—from requirements analysis through release management—ensuring designs align with enterprise architecture standards.
- Translate functional and technical requirements into secure production code for AI and non-AI components, and lead secure AI and software architecture design with rigorous design and code reviews.
- Develop and enhance security strategies and red teaming programs, defining AI red teaming methodologies, playbooks, and success metrics; perform discovery, threat modeling, and adversarial testing on generative AI, RAG pipelines, and ML systems to uncover prompt injection, jailbreaking, data poisoning, and data leakage risks.
- Reduce AI and LLM vulnerabilities by applying industry standards and evolving AI safety practices, establishing testing protocols, controls, and guidance on secure design, logging, monitoring, and compensating controls; write unit and integration tests and strengthen CI/CD quality gates; provide production and non-production support.
- Lead evaluation sessions with external vendors, researchers, standards bodies, and internal security teams to challenge designs and bring emerging AI threat practices into the organization.
- Collaborate with product, data science, cyber, legal, and risk stakeholders to analyze requirements, propose changes during heightened vulnerability or regulatory shifts, manage backlog and release management across environments, and support a diverse, inclusive team culture.
- Leverage enterprise-approved AI capabilities to accelerate threat modeling, vulnerability analysis, and security documentation, ensuring sensitive data handling and output validation.
- Incorporate reuse-first, AI-assisted practices within SDLC toolchains to strengthen security testing and control validation, maintaining traceability and alignment with resiliency and security expectations.
Requirements
- Formal training or certification in Public Cloud concepts with hands-on experience using cloud-native AI services such as Bedrock.
- Experience with threat modeling, discovery, vulnerability assessment, and penetration testing (MITRE ATLAS, OWASP Top 10 for LLMs) and foundational cybersecurity concepts including IAM, Authentication, OIDC, and SAML.
- Hands-on experience with Infrastructure as Code tools such as Terraform and CloudFormation.
- Proficiency in Python scripting.
- Strong understanding of AI/ML concepts and trends, including knowledge of AI red teaming fundamentals to design and run exercises for complex AI architectures.
- Ability to conceptualize, design, validate, and communicate creative technical solutions to enterprise security challenges, including building internal tools, dashboards, and automation for red teaming activities.
Technologies
- Bedrock
- Terraform
- CloudFormation
- Python
- MITRE ATLAS
- OWASP Top 10 for LLMs
- PyRIT
- Garak
- Custom LLM evaluation harnesses
Preferred qualifications, capabilities, and skills
- Expertise in planning, designing, and implementing AI red teaming exercises and enterprise security solutions for generative AI, LLMs, and ML systems.
- Experience with specialized AI security and red teaming tools and frameworks (for example PyRIT, Garak, custom LLM evaluation harnesses) and contributions to AI security or open source security projects.