JOB DESCRIPTIONAssume a vital position as a key member of a high-performing team that delivers infrastructure and performance excellence. Your role will be instrumental in shaping the future at one of the world's largest and most influential companies.
As a Lead Infrastructure Engineer - Tier 4/Palo Alto/Fortinet at JPMorgan Chase within the Infrastructure Platform (IP) Compute Platform Network Services (CPNS), you apply deep knowledge of software, applications, and technical processes within the infrastructure engineering discipline. Continue to evolve your technical and cross-functional knowledge outside of your aligned domain of expertise.
The Firewall Engineer will be responsible for designing, implementing, and governing enterprise firewall and network segmentation architectures that protect critical assets across on-premises, cloud, and hybrid environments. This role leads standards development, solution selection, deployment patterns, and automation practices to ensure scalable, resilient, and compliant security controls aligned to Zero Trust principles and business objectives.
Job Responsibilities
- Define enterprise firewall reference architectures, segmentation models, and policy frameworks across data centers, branches, and cloud, aligned to Zero Trust and leastâprivilege principles.
- Design highly available, scalable NGFW deployments including clustering, load balancing, dynamic routing, NAT, TLS/SSL decryption, and applicationâlayer controls for northâsouth and eastâwest traffic.
- Develop hybrid and multiâcloud patterns (AWS, Azure, GCP) using cloudânative controls (e.g., Security Groups/NACLs, AWS Network Firewall, Azure Firewall, GCP VPC rules) and virtual NGFWs; integrate with SDâWAN where applicable.
- Establish policy standards, naming conventions, and rule lifecycle processes (request, review, approval, attestation/recertification, decommission) mapped to NIST CSF, ISO 27001, PCI DSS, and regional requirements.
- Create and maintain architecture blueprints, patterns, runbooks, and decision records; lead design reviews and change advisory for firewall changes.
- Lead deployments, upgrades, and migrations across Palo Alto and Fortinet platforms; drive consolidation and rationalization programs.
- Build InfrastructureâasâCode and automation (Terraform, Ansible, Python) for provisioning, policy updates, preâchange validation, drift detection, and compliance checks; integrate with CI/CD pipelines.
- Define logging, telemetry, and alerting standards; integrate firewall events with SIEM and SOAR for detection and response.
- Partner with Network and SOC teams to optimize performance, reduce ruleâset complexity, and remediate misconfigurations; maintain health dashboards and SLOs for clusters, sessions, throughput, and latency; Conduct periodic rule reviews, risk assessments, and attestations; enforce leastâprivilege access and manage exceptions with traceability.
- Support audits and regulatory examinations with control narratives and evidence; provide continuous compliance reporting and drive findings to closure within SLAs; Provide Tier 3/architectural escalation during incidents; lead rootâcause analysis; design and test failover, backup/restore, and disaster recovery strategies for firewall configuration and state.
- Translate business and application requirements into secure connectivity solutions and standardized segmentation patterns; Evaluate vendor capabilities, influence product roadmaps, and manage lifecycle and cost/risk tradeâoffs.
Required qualifications, capabilities, and skills
- Formal training or certification on software engineering concepts and 5+ years applied experience
- Proven experience with nextâgeneration firewalls, IDS/IPS, and segmentation; deep handsâon with Palo Alto and/or Fortinet; exposure to Check Point/Cisco.
- Strong networking expertise: TCP/IP, BGP/OSPF, VLANs, NAT, IPSec/SSL VPN, SDâWAN; practical TLS/SSL decryption strategies and operations.
- Experience with at least one public cloud (AWS, Azure, or GCP) and cloudânative network security controls.
- Proficiency with IaC and automation (Terraform, Ansible, Python) and configuration management workflows; guardrail and validation integration into CI/CD.
- Familiarity with SIEM/SOAR integrations, logging taxonomy, and event correlation for firewall telemetry.
- Working knowledge of security frameworks and standards (NIST CSF, ISO 27001, PCI DSS; industryâspecific as applicable).
- Excellent communication and documentation skills; ability to lead crossâfunctional reviews.
Preferred qualifications, capabilities, and skills
- Experience implementing Zero Trust architectures, microsegmentation (hostâbased or SDN), and SASE/ZTNA solutions.
- Background with cloudânative controls and virtual NGFWs across AWS, Azure, and GCP.
- Exposure to SDN (e.g., NSXâT) and network policy orchestration.
- Performance tuning and capacity planning for highâthroughput, lowâlatency environments.
- Leadership of largeâscale firewall migrations or platform consolidation programs.
ABOUT USJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the worldâs most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicantsâ and employeesâ religious practices and beliefs, as well as mental health or physical disability needs. Visit our
FAQs
for more information about requesting an accommodation.
ABOUT THE TEAMOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that weâre setting our businesses, clients, customers and employees up for success.
hackajob is partnering with JPMorganChase to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.