As part of the Cybersecurity Technology Controls Global Regulatory Assessments team, the PCI Specialist is responsible for overseeing the end-to-end processes of a PCI Assessment driven by contractual and/or determined by business need in support of the JPMC Multi-Level PCI Compliance Validation efforts. The PCI Assessor/Advisor acts as the PCI Subject Matter Expert partnering with external Assessor partners and internal control and application owners to ensure compliance with PCI DSS SSC Frameworks. This role requires expert project management capabilities, technical proficiency, and the ability to effectively facilitate assessments across diverse stakeholder groups including external assessors, technical teams, and non-technical business partners to deliver quality outcomes within established timeframes.
Job responsibilities
- Oversee and manage multiple concurrent PCI assessments within firm Standards & Procedures according to established methodology and frameworks, adhering to time-sensitive deadlines through effective project management and stakeholder coordination
- Capture, review and analysis of PCI required documentation, ensuring quality and suitability that meets PCI SSC requirements while exercising professional judgment on complex technical and compliance matters.
- Work with Business Leads & control owners and other members of the PCI team to determine and validate scope (people, processes and technologies etc.)
- Partner strategically with external QSAs to facilitate assessment processes while ensuring alignment with business objectives and regulatory requirements
- Proactively monitor Key Risk Parameters to identify non-compliance and assist in remediation including potential compensating controls to address security, risk and control gaps where appropriate.
- Provide guidance on remediation activities as it pertains to the business area, ensuring appropriate resolution of issues, action plans, breaks and remedies and support the closure verification process
- Develop and maintain strong business and technology relationships, becoming a trusted partner.
- Communicate risk and other control findings with key stakeholders, develop recommendations and provide accurate metrics and management reports on a timely basis.
- Leverage emerging technologies, including AI and automation tools, to enhance assessment efficiency, documentation quality, and risk identification processes
Required qualifications, capabilities, and skills
- Candidates must possess demonstrable experience in technology risk and controls, risk-based consulting, risk assessments, audit and regulatory activities, with specific emphasis on PCI Data Security Standards
Bachelor’s degree in computer science, Management Information Systems, Accounting Information Systems, or a related field. Experience within financial services areas is preferred. - Comprehensive knowledge and practical experience across all domains of Technology Infrastructure and PCI DSS requirements. Experience with implementation and oversight of technology risk and controls, coordination of activities for audits and assessing in an assigned environment.
- Detail-oriented professional with strong conceptual, analytical, decision-making, planning, time management, and prioritization capabilities.
- Exceptional oral and written communication skills with ability to articulate complex technical concepts to diverse audiences at all organizational levels and influence without direct authority.
- Proven experience in planning, coordination, and implementation with ability to work across teams and functions to execute and deliver quality outcomes.
- Demonstrated aptitude to upskill and learn new technologies based on business requirements.
Preferred qualifications, capabilities, and skills
- Proficiency in reviewing, understanding, and evaluating technical and software documentation and applying knowledge to assess control suitability.
- Experience operating in environments that are heavily governed under compliance, regulatory, or risk reduction controls.
- Advanced understanding of industry best practices, regulatory requirements, and company policies.
- Knowledge of process-focused methodologies for IT related activities (Change Management, Incident Management, and SDLC).
- Working knowledge of IT Risk & Process frameworks: COSO, COBIT, NIST CF, ITIL
- Demonstrated interest and practical application of AI, automation, and emerging technologies to enhance compliance and assessment processes
- Ability to exercise sound judgment in ambiguous situations, balancing regulatory requirements with business realities to develop pragmatic solutions
About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
Skills Required
- Demonstrable experience in technology risk and controls, risk-based consulting, risk assessments, audit, and regulatory activities, with emphasis on PCI DSS.
- Bachelor’s degree in computer science, Management Information Systems, Accounting Information Systems, or a related field.
- Comprehensive knowledge and practical experience across technology infrastructure and PCI DSS requirements.
- Experience implementing and overseeing technology risk and controls, coordinating audits, and assessing assigned environments.
- Strong analytical, decision-making, planning, time management, prioritization, oral communication, and written communication skills.
- Experience planning, coordinating, and implementing cross-functional activities to deliver quality outcomes.
- Ability to learn and apply new technologies based on business requirements.
- Experience in financial services environments.
- Ability to review and evaluate technical and software documentation and assess control suitability.
- Experience in compliance-, regulatory-, or risk-controlled environments.
- Advanced understanding of industry best practices, regulatory requirements, and company policies.
- Knowledge of Change Management, Incident Management, and SDLC methodologies.
- Working knowledge of COSO, COBIT, NIST Cybersecurity Framework, and ITIL.
- Practical application of AI, automation, and emerging technologies in compliance or assessment processes.
- Ability to develop pragmatic solutions and exercise sound judgment in ambiguous situations.
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery





