JP Morgan Chase

JP Morgan Chase

London

Senior DevSecOps Architect

Full-Time£62,000 - 102,000 per yearevvelsi günUnited Kingdom
IT

Job Description

Salary: £62,000 - 102,000 per year

Requirements:
  • Advanced threat modeling experience for DevOps and CI/CD pipelines and toolchains, including STRIDE-LM or similar methods.
  • Expert ability to advise on secure pipeline architecture using Policy-as-Code and automated gates.
  • Hands-on security expertise in AWS and GCP.
  • Practical experience creating reference architectures and patterns for engineering teams.
  • Proven ability to design and deploy automated preventive and detective guardrails at scale.
  • Expertise in IaC scanning to detect misconfigurations and compliance violations across Terraform and Kubernetes manifests.
  • Hands-on experience integrating a comprehensive DevSecOps tooling stack, including SAST, SCA, RASP, IAST, container and image scanning, secrets detection, and AI-powered DAST solutions.
  • Experience implementing and managing SBOMs to track internal and third-party risk and supply chain security.
  • Ability to solve design and functionality problems independently.
  • Strong written and verbal communication skills.
  • Demonstrated success in influencing peers and stakeholders.
  • Ability to evaluate and recommend emerging technologies for future-state architecture.
  • Demonstrated experience using enterprise-authorized AI capabilities to support cybersecurity architecture workflows with strong validation habits and awareness of data sensitivity.
  • Ability to assess and validate AI-assisted security recommendations before adoption, escalating uncertainty and ensuring outcomes align with security, resiliency, and auditability expectations.
  • Preferred: shift-left/start-left evangelism and a track record of mentoring developers.
  • Preferred certifications such as AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, CISSP, CKS, or OSCP.
  • Preferred experience operating in regulated organizations with a 3LoD model.
  • Preferred experience translating policy and regulatory requirements into control design for engineers and architects.
  • Preferred experience in financial services consumer businesses or fintech organizations.
Responsibilities:
  • Design, implement, and continuously improve security architecture for CI/CD pipelines and DevOps toolchains.
  • Ensure automated security checks are embedded at every stage from code commit to production deployment.
  • Champion Infrastructure as Code and Security as Code practices, including policy enforcement, security linting, and automated compliance validation across cloud environments.
  • Lead advanced threat modeling for pipelines, microservices, and cloud-native applications.
  • Conduct architecture reviews to drive adoption of secure design patterns.
  • Design and deploy automated preventive and detective guardrails to reduce risk across CI/CD pipelines, cloud, and SaaS environments.
  • Cultivate a security-first culture across product, technology, and business teams by providing developer-friendly tooling, training, and reusable secure patterns.
  • Act with urgency to manage emerging security issues, monitor risk indicators, and recommend resolutions.
  • Serve as the escalation point for IT Risk and Cyber domains related to DevSecOps and Change Management.
  • Partner with engineering leads, product owners, and vendors to ensure effective technology risk management.
  • Translate regulatory and policy requirements into actionable, engineer-friendly controls.
  • Support audit, regulatory, and risk activities by providing evidence of control effectiveness and translating compliance requirements into automated, repeatable processes.
  • Identify and address unfamiliar technology components, share best practices, and influence peers to drive continuous improvement in DevSecOps maturity.
  • Use enterprise-authorized AI capabilities to accelerate cybersecurity risk analysis and control assessment, validating outputs and handling data according to sensitivity and security requirements.
  • Drive reuse-first adoption of AI-assisted security validation within SDLC and toolchain routines to improve control testing, remediation quality, and traceability/auditability.
Technologies:
  • AI
  • AWS
  • CI/CD
  • Cloud
  • DevSecOps
  • DevOps
  • Embedded
  • GCP
  • Support
  • Kubernetes
  • Marketing
  • Security
  • Terraform
  • microservices
  • Architect

More:

We are JPMorganChase, a global leader in financial services. In our Cybersecurity & Technology Controls team for International Consumer, we work with top cybersecurity and engineering talent to solve complex challenges and enable safe, secure innovation. We offer a dynamic environment designed for achievers, where security is built in from the start and your impact can directly influence the future of technology. We are committed to diversity, inclusion, and equal opportunity, and our corporate functions span finance, risk, human resources, marketing, and more to support our businesses, clients, customers, and employees worldwide.

last updated 36 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About JP Morgan Chase

JP Morgan Chase

JP Morgan Chase

London

IT

Skills & Technologies

ScalaRailsAWSGCPKubernetesTerraformCI/CDAIDevOpsUI

Inferred from job description

Salary Insight

£82,000

This role

£75,000

UK median

This salary is 9% above the UK median for Senior roles75,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom