IT & Software

Senior DevSecOps Architect

JP Morgan Chase

London · Greater London · United Kingdom

Overview

In this Senior DevSecOps Architect role, you partner with technology and business teams to strengthen security across products and pipelines. You lead threat modeling, secure-by-design reviews, and embed automated security controls into CI/CD. You will influence product strategy, manage emerging risks, and serve as the DevSecOps SME across cloud and emerging tech. You work globally to support audit, regulatory, and risk programs while fostering a security-first culture.

Responsibilities
  • Design, implement, and improve security architecture for CI/CD pipelines and DevOps toolchains with automated security checks at every stage
  • Champion Infrastructure as Code (IaC) and Security-as-Code practices, including policy enforcement and automated compliance validation
  • Lead advanced threat modeling (STRIDE-LM) for pipelines, microservices, and cloud-native apps; conduct architecture reviews for secure patterns
  • Design and deploy automated guardrails to reduce risk across CICD pipelines, cloud, and SaaS environments
  • Foster security culture with developer-friendly tooling, training, and reusable secure patterns to accelerate delivery
  • Manage emerging security issues with urgency, monitor risk indicators, and serve as escalation point for IT Risk and Cyber domains
  • Partner with engineering leads, product owners, and vendors to translate regulatory requirements into actionable controls
  • Support audit, regulatory, and risk activities by providing evidence of control effectiveness and automating repeatable processes
  • Identify opportunities to improve DevSecOps maturity across the organization
Key requirements
  • Advanced threat modeling experience (STRIDE-LM) for DevOps/CICD pipelines and toolchains
  • Expert ability to advise secure pipeline architecture using Policy-as-Code and automated gates
  • Hands-on security expertise in AWS and GCP
  • Experience creating reference architectures and patterns for engineering teams
  • Proven ability to design and deploy automated preventive and detective guardrails at scale
  • Experience with IaC scanning to detect misconfigurations and compliance violations across Terraform and Kubernetes manifests
  • Hands-on experience integrating a comprehensive DevSecOps tooling stack (SAST, SCA, RASP, IAST, container and image scanning, secrets detection, AI-powered DAST)
  • Experience implementing and managing SBOMs to track internal and third-party risk
  • Ability to solve design problems independently
  • Strong written and verbal communication; proven influencing ability
  • Ability to evaluate and recommend emerging technologies for future state architecture
  • strong communication
  • influencing peers and stakeholders
  • team collaboration
  • STRIDE-LM threat modeling
  • Policy-as-Code
  • IaC scanning (Terraform, Kubernetes)

Reference: WJ-747_30139317

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.