Your expertise in cybersecurity compliance can make a real impact — not just for a team, but for one of the world's most complex and consequential financial institutions. At JPMorganChase, we invest in our people, our technology, and our controls to stay ahead of an ever-evolving threat landscape. This is your opportunity to grow your career at the intersection of regulatory compliance, emerging technology, and enterprise-scale risk management.
As an Assessments & Exercises Senior Associate at JPMorganChase within the Cybersecurity Technology Controls Global Regulatory Assessments team, you will play a hands-on role in supporting end-to-end Payment Card Industry (PCI) compliance assessments that directly support the firm's multi-level PCI compliance validation efforts. You will collaborate with external assessor partners and internal control and application owners to ensure adherence to PCI Data Security Standard (PCI DSS) frameworks, while developing your technical depth and professional judgment in a high-impact, fast-paced environment. This role offers meaningful exposure to senior assessors, cross-functional stakeholders, and emerging automation tools — positioning you for continued growth within the firm's cybersecurity organization.
Job responsibilities
- Support and collaborate on multiple concurrent PCI assessments, adhering to established methodology, firm standards, and time-sensitive milestones through effective project management and stakeholder coordination
- Capture, review, and analyze PCI-required documentation, ensuring quality and suitability that meets PCI Security Standards Council (SSC) requirements while exercising professional judgment on complex technical and compliance matters
- Prepare for assessment walkthroughs, organize evidence, document discussions, and track follow-up actions in support of Vice Presidents and senior assessors throughout the assessment lifecycle; monitor key risk parameters to proactively identify non-compliance and assist in remediation efforts, including the evaluation of potential compensating controls to address security, risk, and control gaps
- Provide guidance on remediation activities for assigned business areas, supporting appropriate resolution of issues, action plans, and closure verification processes
- Research PCI requirements, emerging guidance, and industry developments; synthesize findings and share informed perspectives with the broader assessment team
- Maintain remediation tracking by managing action items, following up with stakeholders, validating submitted documentation, and escalating delays or concerns to the assessment lead; participate in team quality reviews, incorporate feedback, and progressively take ownership of defined assessment activities as knowledge and experience develop
- Leverage approved automation and large language model (LLM) tools to assist with evidence organization, requirement mapping, workpaper drafting, quality checks, and reporting — while validating outputs and safeguarding sensitive information
- Support the testing of controlled agentic workflows for repetitive administrative and assessment-support tasks, contributing feedback on accuracy, usability, risks, and improvement opportunities
Required qualifications, capabilities, and skills
- Formal training or certification on assessments & exercises concepts and 3+ years applied experience
- 3+ years of professional experience in technology risk and controls, cybersecurity consulting, audit, or compliance assessments, with hands-on exposure to PCI DSS
- Bachelor's degree in Computer Science, Management Information Systems, Accounting Information Systems, or a related field
- Comprehensive knowledge and practical experience across technology infrastructure domains and PCI DSS requirements
- Strong analytical, decision-making, time management, and prioritization capabilities with a detail-oriented approach to complex compliance matters
- Effective oral and written communication skills, with the ability to articulate complex technical concepts to diverse audiences including non-technical business partners
- Demonstrated ability to plan, coordinate, and execute across teams and functions to deliver quality outcomes within established timeframes
- Proven aptitude for upskilling and adopting new technologies in response to evolving business and regulatory requirements
Preferred qualifications, capabilities, and skills
- Experience working with a Qualified Security Assessor (QSA) firm or cybersecurity consulting organization
- Proficiency in reviewing and evaluating technical and software documentation to assess control suitability and compliance alignment
- Experience operating in heavily governed environments subject to compliance, regulatory, or risk-reduction controls, preferably within financial services
- Working knowledge of IT risk and process frameworks such as COSO, COBIT, NIST Cybersecurity Framework, or ITIL
- Familiarity with process-focused methodologies for IT activities including Change Management, Incident Management, and the Software Development Lifecycle (SDLC)
- Demonstrated interest and practical application of artificial intelligence, automation, or emerging technologies to enhance compliance and assessment processes
#CTC
About UsWe offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Skills Required
- Formal training or certification in assessments and exercises concepts
- At least 3 years of applied experience in assessments and exercises
- At least 3 years of professional experience in technology risk and controls, cybersecurity consulting, audit, or compliance assessments
- Hands-on exposure to PCI DSS
- Bachelor's degree in Computer Science, Management Information Systems, Accounting Information Systems, or a related field
- Comprehensive knowledge and practical experience across technology infrastructure domains and PCI DSS requirements
- Strong analytical, decision-making, time management, prioritization, and attention-to-detail skills
- Effective oral and written communication skills, including explaining technical concepts to nontechnical audiences
- Ability to plan, coordinate, and execute work across teams within established timeframes
- Aptitude for upskilling and adopting new technologies
- Experience working with a Qualified Security Assessor firm or cybersecurity consulting organization
- Experience reviewing and evaluating technical and software documentation for control suitability and compliance alignment
- Experience in heavily governed compliance, regulatory, or risk-reduction environments, preferably financial services
- Working knowledge of COSO, COBIT, NIST Cybersecurity Framework, or ITIL
- Familiarity with Change Management, Incident Management, and SDLC methodologies
- Interest and practical experience applying artificial intelligence, automation, or emerging technologies to compliance and assessment processes
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery






