Join a role that’s central to our technological resilience and regulatory compliance, offering a unique opportunity to shape the firm’s tech risk strategy and enhance industry compliance.
As a Tech Risk & Controls Director in our Cybersecurity and Technology Controls (CTC) team, you will play a pivotal role in shaping and implementing the firm’s technology risk management strategy. Leveraging your advanced knowledge and expertise in technology-risk disciplines, you will identify, oversee, and mitigate compliance and operational risks in line with the firm’s standards and regulatory requirements. You will collaborate with various stakeholders, including Product Owners, Control Managers, and regulators, to develop and maintain a comprehensive view of the technology risk posture and its impact on the legal entity. Your ability to make calculated decisions, manage teams, and support strategic projects will be crucial in ensuring the firm’s adherence to regulatory obligations and industry best practices. Your work will contribute to the long-term success and resilience of the organisation in an ever-evolving technology landscape.
Job responsibilities
- Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks, and support strategic projects and initiatives to enhance the firm’s technology risk management capabilities, in line with industry best practices and the firm’s standards and regulatory requirements.
- Identify and escalate emerging and upstream technology risk through execution of the firm’s management framework tools, including risk event management, reporting, and action plan tracking, and provide expert counsel to stakeholders and constituents regarding their security obligations, facilitating acceptable outcomes.
- Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, 2nd Line of Defense, and auditors, to ensure compliance with legal, regulatory, and industry standards.
- Manage reporting and governance of overall controls, policies, issue management, and measurements, etc., providing insight to senior leaders into effectiveness of controls and inform governance work.
- Promote a culture of high performance, operational excellence, and innovation within the team, driving continuous improvement in risk management practices.
Required qualifications, capabilities, and skills
- 10+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation.
- Proficient verbal and written communication skills in both German and English, essential due to the dialogue required with the regulators.
- Demonstrated extensive experience in the financial sector, particularly in engaging with regulatory bodies, ensuring compliance, and navigating complex regulatory frameworks such as DORA.
- Proven experience in creating, monitoring, and presenting technology and security Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to executive and management board levels, ensuring alignment with organisational objectives and regulatory requirements.
- Demonstrated expertise in risk management frameworks, industry standards, and regulatory requirements (in particular in the EU and Germany) relevant to the financial industry.
- Proven ability to lead teams, manage cross-functional projects, influence executive-level strategic decision-making, and effectively translate technology insights to business strategy in communications with senior executives.
- Advanced knowledge and experience leading information security, risk assessment & reporting, and control evaluation, design, and governance, with a track record of implementing effective risk mitigation strategies.
- Experience in using common technology controls industry best practice frameworks (e.g., from NIST, ISO, ISACA, etc.), with the ability to apply critical thinking and structured problem-solving techniques to address issues and drive continuous improvement in risk management practices.
-
Able to operate on multiple tasks whilst still achieving high delivery standards with an attention to detail.
Preferred Qualifications, capabilities, and skills
- CISSP certifications are strongly preferred
Skills Required
- 10+ years experience in technology risk management, information security, or related field
- Proficient verbal and written communication skills in German and English
- Extensive experience in the financial sector engaging with regulatory bodies and navigating frameworks such as DORA
- Proven experience creating, monitoring, and presenting technology and security KPIs and KRIs to executive and management board levels
- Expertise in risk management frameworks, industry standards, and regulatory requirements relevant to the EU and Germany
- Proven ability to lead teams, manage cross-functional projects, and influence executive-level strategic decision-making
- Advanced knowledge and experience in information security, risk assessment & reporting, control evaluation, design, and governance
- Experience using technology controls frameworks and industry best practices (e.g., NIST, ISO, ISACA) and applying structured problem-solving
- Ability to manage multiple tasks with high delivery standards and attention to detail
- CISSP certification
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental health coverage are comprehensive, with on-site clinics, preventive care, and specialized supports such as maternity nurse guidance and fertility treatments. Wellness activities can help offset copays and out-of-pocket costs, reinforcing the perceived strength of health benefits.
-
Retirement Support — A 401(k) with dollar-for-dollar matching and additional automatic pay credits reflect strong employer-backed retirement savings. An employee stock purchase plan and related financial programs further bolster long-term financial support.
-
Leave & Time Off Breadth — Paid time off, sick time, holidays, and generous parental leave are provided alongside family medical leave and adoption/fertility assistance. Additional programs like caregiver support and volunteer time off expand the breadth of time-away options.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery






