Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.
As a Technology Risk and Controls Director within our Cloud Foundational Services Function, you will be passionate about operational risk management and control solutions for computing environments. You will partner with one or more disciplines, lines of business, regions and locations to respond to evolving business requirements and emerging threats. You will leverage your expert knowledge of today's ever-changing technology risk landscape and controls environment to advise and support IT operations across the firm. You will partner with process owners to respond to internal and external audit and regulatory requests for information, while ensuring senior stakeholders are kept updated on the risk posture for the organization. you will report directly to the Technology, Risk & Controls Portfolio Lead and will be responsible for a small team.
Lead the strategic development and implementation of technology risk management in a dynamic, evolving tech landscape. Cloud Technology Risk & Controls Lead (Executive Director) who helps teams run cloud services safely and reliably. You’ll work with partners across the firm to spot new risks, strengthen day‑to‑day controls, and keep leaders informed on overall risk health. You’ll also coordinate responses to audits and regulatory requests, and guide IT teams on security, resiliency, and high‑availability design. The role covers key areas like access management, incident response, vulnerability management, and data protection, with a strong understanding of public cloud environments..
Job responsibilities
- Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks, and drive strategic projects and initiatives to enhance the firm's technology risk management capabilities, in line with industry best practices and the firm's standards and regulatory requirements
- Sets reuse-first expectations for enterprise-authorized AI adoption within the work environment across technology risk and controls operations to accelerate evidence synthesis, issue analysis, and executive reporting, with human-in-the-loop validation and appropriate handling of sensitive data.
- Identify and escalate emerging and upstream technology risk through execution of the Firm’s management framework tools, including risk event management, reporting, and action plan tracking, and provide expert counsel to stakeholders and constituents regarding their security obligations, facilitating acceptable outcomes
- Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards
- Manage reporting and governance of overall controls, policies, issue management, and measurements, etc., providing insight to senior leaders into effectiveness of controls and inform governance work
- Establishes governance standards for AI-assisted workflows used in risk reporting and issue/action-plan management, ensuring traceability/auditability and alignment to security, resiliency, and regulatory expectations. Operational risk management subject matter expert.
- Direct oversight and management of Audits for Cloud Foundational Services.
- Supports and advises process owners in managing operational risk and provides transparency to stakeholders.
- Ensures alignment with regulatory and firmwide control obligations and industry standards. Audit engagement and response management.
Required qualifications, capabilities, and skills
- Significant experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation
- Demonstrated experience leading safe adoption of enterprise-authorized AI capabilities within the work environment within technology risk and controls workflows, including validation practices and awareness of data sensitivity.
- Ability to define review/approval and escalation expectations for AI-assisted recommendations while maintaining security, auditability, and regulatory compliance outcomes.
- Demonstrated expertise in risk management frameworks, industry standards, and regulatory requirements relevant to the financial industry
- Proven ability to lead large teams, manage cross-functional projects, influence executive-level strategic decision-making, and effectively translate technology insights to business strategy in communications with senior executives
- Advanced knowledge and experience leading data security, risk assessment & reporting, and control evaluation, design, and governance, with a track record of implementing effective risk mitigation strategies.
- Bachelor’s degree or equivalent experience.
- Strong leadership skills with exceptional communication and presence.
- Advanced knowledge of multiple IT control and project management practices and experience working across large environments.
- Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals.
- Expertise in application and infrastructure high-availability and resiliency architectures with demonstrated experience in business.
- Proficiency in information security domains, including policies and standards, risk and control assessments, access controls, regulatory compliance, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, and data protection.
- Understanding of Public Cloud environments.
Skills Required
- Significant experience in technology risk management, information security, or related field
- Experience leading safe adoption of enterprise-authorized AI capabilities within technology risk and controls workflows
- Ability to define review/approval and escalation expectations for AI-assisted recommendations maintaining security and auditability
- Demonstrated expertise in risk management frameworks, industry standards, and financial regulatory requirements
- Proven ability to lead large teams, manage cross-functional projects, and influence executive-level decision-making
- Advanced knowledge and experience leading data security, risk assessment & reporting, and control evaluation, design, and governance
- Bachelor's degree or equivalent experience
- Strong leadership skills with exceptional communication and presence
- Advanced knowledge of IT control and project management practices across large environments
- Expertise in application and infrastructure high-availability and resiliency architectures
- Proficiency across information security domains: policies and standards, access controls, regulatory compliance, resiliency, governance, incident management, secure SDLC, vulnerability management, and data protection
- Understanding of public cloud environments
- Direct oversight and management of audits for Cloud Foundational Services
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental health coverage are comprehensive, with on-site clinics, preventive care, and specialized supports such as maternity nurse guidance and fertility treatments. Wellness activities can help offset copays and out-of-pocket costs, reinforcing the perceived strength of health benefits.
-
Retirement Support — A 401(k) with dollar-for-dollar matching and additional automatic pay credits reflect strong employer-backed retirement savings. An employee stock purchase plan and related financial programs further bolster long-term financial support.
-
Leave & Time Off Breadth — Paid time off, sick time, holidays, and generous parental leave are provided alongside family medical leave and adoption/fertility assistance. Additional programs like caregiver support and volunteer time off expand the breadth of time-away options.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery







