As a Tech Risk & Controls Lead in the Cyber Security & Tech Controls (CTC) team, aligned to the Corporate Investment Banking division, you will be a key member of the Cyber Risk Management function supporting technology teams that build, operate, and deliver financial markets platforms and applications across the CIB Markets business. You will operate at the intersection of cybersecurity, engineering, and GRC—driving outcomes through hands-on technical analysis, practical control design, and evidence-based risk decisions.
You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm’s standards, with a strong emphasis on practical implementation realities (architecture, infrastructure, SDLC, tooling, and operational resilience). Leveraging a deep technical and/or engineering background and broad risk management experience, you will identify, assess, and monitor risks and the implementation of effective controls across complex systems and environments. You will be expected to review architectures, interrogate technical designs, validate control effectiveness through artifacts/logs/configurations, and translate technical deficiencies into clear risk narratives for senior stakeholders.
Job responsibilities
- Identify risks: Conduct hands-on technical deep dives across a diverse portfolio of applications to identify emerging and upstream technology and cyber risks.
- Assess risk, monitoring & reporting: Assess, monitor, and report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
- Implement controls: Design & Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
- Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm’s risk posture.
- Analyze & mitigate: Analyze complex situations, advise on risk management strategies, and support the implementation of risk mitigation measures.
- Document & communicate: Document and articulate risks appropriately; raise issues and define action plans in partnership with application teams.
- Identify threats: Work closely with application teams to identify attack paths and threat vectors through threat modeling.
Required qualifications, capabilities, and skills
- Software and/or security engineering background, including experience with modern programming languages (e.g., Python) and cloud (AWS).
- Proven technology risk / information security experience, including risk identification, assessments, control testing, mitigation, and applying industry standards and best practices.
- Strong technical domain knowledge across Software Development Life Cycle (SDLC) and CI/CD, application resilience and security, IAM, data protection, and vulnerability management—especially for on‑prem and public-cloud environments in financial services.
- Analytical and execution skills to assess complex issues, synthesize data from disparate sources into a cohesive risk view, and design/implement pragmatic risk mitigation strategies.
- Strong stakeholder management: communicate clearly with senior leaders and build trusted, durable partnerships with LOB technologists to achieve shared outcomes.
- Governance- and control-oriented mindset, with working knowledge of risk frameworks and relevant regulations; motivated by enabling the business through strengthened controls.
Preferred qualifications, capabilities, and skills
- Industry-recognized risk certifications (e.g., CISM, CRISC, CISSP).
- Process-improvement mindset with a track record of reducing toil and building efficient, scalable processes.
- Experience with booking, pricing, and risk ecosystems (e.g., Athena, SecDb, Quartz, RICE, or equivalent) strongly preferred.
- Familiarity with large-scale Python codebases.
- Exposure to AI-driven risks and emerging threat patterns.
About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
Skills Required
- Software and/or security engineering background
- Experience with modern programming languages, including Python
- Experience with cloud environments, including AWS
- Proven technology risk or information security experience
- Experience with risk identification, assessments, control testing, and mitigation
- Knowledge of SDLC and CI/CD
- Knowledge of application resilience and security, IAM, data protection, and vulnerability management
- Experience with on-premises and public-cloud environments in financial services
- Analytical and execution skills for complex risk assessment and mitigation
- Strong stakeholder management and communication skills
- Knowledge of risk frameworks, regulations, and industry standards
- CISM, CRISC, or CISSP certification
- Process-improvement experience reducing toil and building scalable processes
- Experience with booking, pricing, and risk ecosystems such as Athena, SecDb, Quartz, or RICE
- Familiarity with large-scale Python codebases
- Exposure to AI-driven risks and emerging threat patterns
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery






