Mid-Level
Join a team that helps protect the systems and data that power a global financial institution. You will work hands-on with modern detection and response capabilities, partnering with technologists across the firm to reduce risk and improve resilience. This role offers meaningful exposure to evolving threat activity, investigative work, and continuous improvement of operational security practices.
As a Security Operations Associate at JPMorganChase within the Detection and Response Operations team, you contribute to safeguarding digital assets by proactively detecting, assessing, and responding to threats, vulnerabilities, and security incidents. You use sound judgment to investigate and resolve cybersecurity issues while improving existing processes and response playbooks. You collaborate across teams to drive coordinated security practices and help raise security awareness through clear guidance and documentation.
Job responsibilities
Conduct security investigations, including log review, triage, and root-cause analysis of suspicious activity
Perform threat hunting to identify adversary behaviors across endpoints, networks, and cloud environments
Assess vulnerability impact by validating exposure, mapping to affected assets, and recommending mitigation actions
Use Security Information and Event Management (SIEM) and detection tooling to improve alert fidelity and response time
Analyze malware and suspicious files, emails, and artifacts to determine intent, scope, and containment actions
Partner with cross-functional teams to implement coordinated security processes, standards, and operating procedures
Contribute to incident response activities, including containment, eradication, recovery support, and post-incident review
Propose and implement improvements to detection content, runbooks, and response playbooks to strengthen security posture
Required qualifications, capabilities and skills
Formal training or certification on security operations concepts and 2+ years applied experience
Demonstrated ability to analyze security events using logs from endpoints, network devices, and cloud services
Working knowledge of scripting used to automate security tasks (for example, Python, PowerShell, or similar)
Strong understanding of authentication, authorization, identity controls, and cryptographic concepts
Experience using security tools such as SIEM platforms, intrusion detection, endpoint detection, and malware analysis utilities
Familiarity with the MITRE ATT&CK framework and applying it to investigations and threat hunting
Proven investigative mindset, including hypothesis-driven analysis, evidence validation, and attention to detail
Strong written communication skills, including clear documentation of findings, actions taken, and recommendations
Preferred qualifications, capabilities and skills
Experience supporting security operations in a financial services environment
One or more cybersecurity certifications (for example, Security+, GCIH, GCIA, or comparable credentials)
Prior experience in a Security Operations Center or in a dedicated detection and response role
Experience improving detection logic and operational workflows (for example, tuning alerts, creating playbooks, or automation)
#CTC
Sign up to apply and find out right away if you're a fit.
Your agent will tell you — in seconds.
Sign up and I'll tell you right away how well JPMorgan Chase matches you — what you already have, and what's missing. Then I stay on it: I search for you and only write when I find something worth your time.