JPMorgan Chase & Co logo
JPMorgan Chase & CoPosted 3 weeks ago

Technology Support Lead

On-siteJersey City, New Jersey, United States

Full TimeSenior LevelEnterpriseFinancial Services

Job Summary

Provide Level 2 and Level 3 support for remote-access VPN services, including SSL/IPsec, AnyConnect, site-to-site VPN, and perimeter firewall services. Diagnose and resolve incidents across Cisco ASA, Firepower Threat Defense, and Identity Services Engine within agreed service levels. Lead major incident bridges, drive root-cause analysis, and deliver post-incident reviews with concrete preventative actions. Plan, peer review, and implement standard and complex changes through Cisco Security Manager, Defense Orchestrator, and related platforms. Manage ISE policy sets, authentication rules, and integrations with Active Directory and MFA. Maintain Firepower software lifecycle, including FXOS upgrades and high-availability pairs. Operate ThousandEyes coverage to monitor remote-access user experience and correlate findings with firewall telemetry. Reduce operational toil through scripting and API-driven automation using Python, Ansible, and Infrastructure-as-Code practices. Participate in a 24x7 on-call rotation for P1/P2 incidents affecting remote connectivity or perimeter security. Work on-site five days per week.

Required Qualifications

  • 5+ years of experience or equivalent expertise troubleshooting, resolving, and maintaining information technology services
  • Experience operating Cisco network security platforms in a large enterprise or service-provider environment
  • Strong hands-on expertise with Cisco ASA, including multi-context, failover, clustering, NAT, ACL, AnyConnect/SSL VPN, IPsec, DAP, and split tunneling
  • Production experience with Cisco Firepower / FTD managed through FMC and/or Cisco Defense Orchestrator, including access control policy, SSL policy, IPS/Snort 3, file/malware, and identity policy
  • Working knowledge of Firepower Chassis Manager / FXOS, including logical device provisioning, interface mapping, and software upgrades on 41xx/93xx-class hardware
  • Operational experience with Cisco ISE, including RADIUS/TACACS+, 802.1X, MAB, posture, profiling, guest access, certificate-based authentication, and AD/Entra ID integration
  • Experience using Cisco Security Manager and Cisco Defense Orchestrator for multi-device policy management, migration, and change orchestration
  • Hands-on experience with ThousandEyes, including agent deployment, test design for HTTP, page-load, network, BGP, and end-user tests, alerting, and root-cause analysis
  • Solid networking fundamentals, including routing with BGP and OSPF, switching, NAT, QoS, PKI, DNS, and TCP/IP troubleshooting using packet capture and Wireshark
  • Strong incident management discipline and clear written and verbal communication with technical and non-technical stakeholders
  • Ability to work on-site five days per week and participate in an on-call rotation

Desired Qualifications

  • CCNP Security, CCIE Security, ThousandEyes certifications, Cisco Certified Specialist – Secure Firewall, or Cisco Certified Specialist – ISE
  • Experience migrating ASA to FTD at scale, or FMC to cloud-delivered FMC through CDO-managed environments
  • Scripting experience in Python and familiarity with Ansible, Git, and CI/CD pipelines for network change
  • Experience integrating telemetry into Splunk, ELK, Grafana, and SOAR platforms

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce