JPMorgan Chase
Global financial services and investment banking leader
Industry
Banking
Region
Americas
Use case
Security Automation
Tech stack
"For the first time, with Kestra, our analysts weren’t waiting for engineering to catch up. They could define the workflows themselves. That changed everything."
For JPMorgan Chase, protecting customers against fraud and malicious activity is not simply an IT challenge; it is the backbone of trust. As one of the world’s largest and most influential banks, the stakes could not be higher. Every day, billions of transactions pass through its systems, and behind each one is the constant threat of cyberattacks, fraud, and data breaches.
Within JPMorgan Chase, the cybersecurity and technology division was given the responsibility to rethink how threat intelligence and fraud detection data were collected, enriched, analyzed, and disseminated across the enterprise. The mission was ambitious: create a secure and scalable data orchestration environment capable of supporting hundreds of users, dozens of external data sources, and multiple business-critical products, all under strict compliance rules and aggressive deadlines.
“We needed more than a workflow engine. We needed a backbone, something to move data seamlessly so our teams could focus on fighting fraud, not writing scripts.”, Cybersecurity Product Owner
The division counted more than 100 active users, split between product owners, analysts, and engineers. Many were highly technical, but not all were comfortable writing Python or maintaining custom code bases. JPMorgan Chase had made the directive clear: the orchestration layer should not depend on Python.
The teams wanted a middle ground between no-code drag-and-drop interfaces and heavy code-first frameworks. They needed something expressive enough for engineers, yet accessible to cybersecurity specialists who worked closer to the data.
The challenge became clearer:
Their stack was already sophisticated:
What was missing was the glue. JPMorgan Chase needed something to orchestrate the ingestion of APIs, the transformation of data, and the dissemination of intelligence. And it had to be secure, resilient, and fast enough to handle thousands of workflows a week.
The cybersecurity and fraud detection workflows followed a clear sequence:
Each stage required different technologies. The orchestration had to tie them together without slowing anyone down.
The scale was daunting:
And because this is JPMorgan Chase, security was paramount:
They also mandated a multi-cloud strategy. AWS was the first step, but the system needed to be ready for JPMorgan Chase’s private cloud and even future deployments on GCP or Azure. Disaster recovery requirements were uncompromising: at least one hot environment running continuously, with multiple warm environments ready for failover.
“If one pipeline breaks, the risk is measured in millions. Reliability wasn’t optional , it was the entire point.” , Engineering Lead
The teams had tried open-source orchestrators before. Some were too code-heavy, forcing every workflow into Python. Others were too rigid, limited to specific automation tasks. JPMorgan Chase needed something in between: a declarative, YAML-first approach that remained extensible.
That’s when Kestra entered the picture.
For product owners and analysts, Kestra became the “wizard behind the curtain” , a system that handled ingestion, enrichment, analysis, and dissemination invisibly, without requiring Python. For engineers, it offered the flexibility to integrate with Trino, dbt, and internal APIs.
The first alpha mapped directly to JPMorgan Chase’s milestones:
The orchestration wasn’t just about technology , it was about people.
Despite the complexity, the results were delivered in under three months. Kestra unified every stage of the cybersecurity data lifecycle while meeting compliance and resilience demands.
The impact was measurable:
The cultural shift was just as significant as the technical one.
“For the first time, our analysts weren’t waiting for engineering to catch up. They could define the workflows themselves. That changed everything.” Product Owner
Product owners no longer had to rely on engineers to code ingestion jobs. Analysts could enrich and test data directly. Engineers could dedicate their time to extending the system, confident that the orchestration layer would keep running.
The vision is to scale this orchestration backbone across more divisions, more feeds, and more use cases.
The team summarized it best:
“Pretty much all of our cyber automations and analytics jobs should eventually run through this platform. It’s not just a tool , it’s becoming part of how we work.”
For JPMorgan Chase, Kestra is the backbone of cybersecurity data. Fraud and threat detection decisions now run on reliable, compliant workflows that deliver intelligence at scale and on time.
What would change if your cybersecurity workflows orchestrated billions of rows automatically—protecting your organization at financial-industry scale?