We are seeking a Regulatory Assessment Lead with a deep background in audit, regulatory, and industry assessments to join our growing Technology Risk and Controls organization.
As a Regulatory Assessment Lead in Cybersecurity and Technology Controls, you will evaluate the firm's technology control environment against applicable regulatory requirements and industry standards. You will translate complex regulatory obligations and provide subject matter expertise and technical guidance to technology-aligned process owners, ensuring that implemented controls comply with regulatory requirements and industry standards.
This role serves as the primary assessment lead, interfacing with internal auditors, compliance and risk teams, technology stakeholders and business product teams to drive complex assessments. The role ensures the firm's continuous compliance with key regulatory and industry standards, including CRI Profile, Swift CSP, CHAPS CRM, HKMA CRAF, and Japan CSSA.
The successful candidate will provide strategic direction and expert leadership in audit readiness and assessment practices, while driving continuous improvement in the firm's control posture. Strong knowledge of risk management principles and practices will enable you to deliver innovative solutions and lead a diverse team in a complex and evolving regulatory environment.
Job responsibilities
-
Lead end-to-end delivery and drive efficient and effective execution of assessments, ensuring the firm's technology control environment meets applicable regulatory obligations and industry standards.
-
Communicate issues and observations identified from our assessments to relevant stakeholders, including root cause analysis and resolution recommendations.
-
Provide subject matter expertise in regulatory assessments, ensuring that the organization adheres to applicable regulations and industry standards such as CRI Profile, Swift CSP, CHAPS CRM, HKMA CRAF and Japan CSSA.
-
Partner with LOBs, global risk and control functions, cybersecurity and technology teams to conduct control assessments, ensuring compliance with regulatory requirements and alignment with the Firm’s policies, standards and procedures.
-
Build and sustain trusted relationships with Location CISO, Regulatory Engagement Management team, LOB technologists, CCOR (Compliance Conduct and Operational Risk), and Internal Audit to facilitate cross-functional collaboration and drive progress toward shared goals.
-
Collaborate with global teams to ensure consistency of assessment methodologies, tooling, and reporting standards across regions.
- Manage and mentor junior team members, fostering a culture of excellence, continuous learning, and regulatory awareness within the APAC assessments practice.
Required qualifications, capabilities, and skills
-
Bachelor’s Degree in Management Information Systems, Cybersecurity or related disciplines.
-
5+ years of experience or equivalent expertise in technology risk management, information security, technology audit or related field with a focus on assessments in the financial services industry.
-
Demonstrated experience leading regulatory assessments, control evaluations, or technology audits in a large organization.
-
Strong understanding of industry risk frameworks (CRI Profile, ISO 27001, etc.) and practical experience with regulatory and industry requirements, including Swift CSP, CHAPS CRM, HKMA CRAF and Japan CSSA.
-
Proficient knowledge of control evaluation of technology risk domains including cybersecurity, data governance, IT resilience, third-party risk management and change management.
-
Experience with payments environment and familiarity with payments-specific regulatory standards and cybersecurity control requirements.
- Strong analytical, problem-solving, and critical thinking skills, with the ability to manage multiple priorities and deliver high-quality outputs under tight deadlines.
Preferred qualifications, capabilities, and skills
CISA, CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred.
About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.Skills Required
- Bachelor's degree in Management Information Systems, Cybersecurity, or a related discipline
- 5+ years of experience or equivalent expertise in technology risk management, information security, technology audit, or a related field, with focus on financial services assessments
- Experience leading regulatory assessments, control evaluations, or technology audits in a large organization
- Strong understanding of industry risk frameworks, including CRI Profile and ISO 27001
- Practical experience with Swift CSP, CHAPS CRM, HKMA CRAF, and Japan CSSA requirements
- Knowledge of technology risk domains including cybersecurity, data governance, IT resilience, third-party risk management, and change management
- Experience with payments environments and payments-specific regulatory and cybersecurity control requirements
- Strong analytical, problem-solving, and critical-thinking skills, with ability to manage multiple priorities and deadlines
- CISA, CISM, CRISC, CISSP, or similar industry-recognized risk certification
JPMorganChase Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.
-
Healthcare Strength — Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
-
Parental & Family Support — Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
-
Retirement Support — Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.
JPMorganChase Insights
What We Do
JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.
Why Work With Us
Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.
Gallery
.png)








