Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.
As a Tech Risk & Controls Lead in the Cyber Security Tech Controls (CTC) team, aligned with the Corporate Investment Banking division, you will be an integral part of a cyber risk management function. You will cover technology teams and applications that support various business units within the firm, including sales, trading, operations, risk and research.
You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm's standards. Leveraging your broad knowledge in risk management principles and technical experience, you will identify, assess, and monitor risks and the implementation of effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm’s risk posture. Through a deep technical aptitude, collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards.
Job responsibilities
- Assess risk, Monitoring & Reporting: Assess, monitor & report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
- Implement controls: Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
- Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm's risk posture.
- Analyze/Mitigate: Analyze complex situations, provide advice on risk management strategies, and support the implementation of risk mitigation measures.
- Document and Communicate: Document and articulate risks appropriately; raise issues and action plans as appropriate in partnership with application teams.
- Identify threats: Work closely with application teams to identify attack and threat vectors through threat modelling.
Required qualifications, capabilities, and skills
- Formal experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessments, controls testing, and mitigation.
- Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards.
- Demonstrated ability to analyse complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders.
- Proficient knowledge of risk management frameworks, regulations, and industry best practices.
- Good understanding of Software Development Life Cycle (SDLC) pipelines, CI/CD, application resiliency and security, IAM, Data Protection and vulnerability management.
- Technical ability to gather and combine data from disparate sources to build a cohesive view on risk.
- Ability to develop and maintain robust relationships becoming a trusted partner with LOB technologists to progress toward shared goals.
- Awareness of key risks in the financial services sector, particularly pertaining to on premise and/or public cloud hosted infrastructure & applications.
- Enthusiasm for enabling the business to create new governance and controls.
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or other industry-recognized risk certifications.
- Software / Security engineering background in any modern programming languages and Cloud experience (ideally Amazon Web Services).
- Ability to think outside the box and proven experience in eliminating toil and crafting efficient processes.
Skills Required
- Formal experience or equivalent expertise in technology risk management, information security, or a related field, focused on risk identification, assessments, controls testing, and mitigation.
- Experience identifying and assessing risks and evaluating controls, with strong knowledge of industry standards.
- Ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders.
- Proficient knowledge of risk management frameworks, regulations, and industry best practices.
- Understanding of SDLC pipelines, CI/CD, application resiliency and security, IAM, data protection, and vulnerability management.
- Technical ability to gather and combine data from disparate sources to create a cohesive view of risk.
- Ability to develop and maintain strong relationships with line-of-business technologists and serve as a trusted partner.
- Awareness of key technology risks in financial services, including on-premise and public-cloud infrastructure and applications.
- Enthusiasm for enabling business teams to create new governance processes and controls.
- CISM, CRISC, CISSP, or another industry-recognized risk certification.
- Software or security engineering background using modern programming languages.
- Cloud experience, ideally with Amazon Web Services.
- Experience eliminating toil and creating efficient processes.
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery







