The Tech Risk and Controls Lead will assess technology risks, implement controls, evaluate their effectiveness, and communicate with stakeholders in a cyber risk management function.
Job Description
Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.
As a Tech Risk & Controls Lead in the Cyber Security Tech Controls (CTC) team, aligned with the Corporate Investment Banking division, you will be an integral part of a cyber risk management function. You will cover technology teams and applications that support various business units within the firm, including sales, trading, operations, risk and research.
You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm's standards. Leveraging your broad knowledge in risk management principles and technical experience, you will identify, assess, and monitor risks and the implementation of effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm's risk posture. Through a deep technical aptitude, collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards.
Job responsibilities
Required qualifications, capabilities, and skills
Preferred qualifications, capabilities, and skills
About Us
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.
As a Tech Risk & Controls Lead in the Cyber Security Tech Controls (CTC) team, aligned with the Corporate Investment Banking division, you will be an integral part of a cyber risk management function. You will cover technology teams and applications that support various business units within the firm, including sales, trading, operations, risk and research.
You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm's standards. Leveraging your broad knowledge in risk management principles and technical experience, you will identify, assess, and monitor risks and the implementation of effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm's risk posture. Through a deep technical aptitude, collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards.
Job responsibilities
- Assess risk, Monitoring & Reporting: Assess, monitor & report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
- Implement controls: Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
- Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm's risk posture.
- Analyze/Mitigate: Analyze complex situations, provide advice on risk management strategies, and support the implementation of risk mitigation measures.
- Document and Communicate: Document and articulate risks appropriately; raise issues and action plans as appropriate in partnership with application teams.
- Identify threats: Work closely with application teams to identify attack and threat vectors through threat modelling.
Required qualifications, capabilities, and skills
- Formal experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessments, controls testing, and mitigation.
- Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards.
- Demonstrated ability to analyse complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders.
- Proficient knowledge of risk management frameworks, regulations, and industry best practices.
- Good understanding of Software Development Life Cycle (SDLC) pipelines, CI/CD, application resiliency and security, IAM, Data Protection and vulnerability management.
- Technical ability to gather and combine data from disparate sources to build a cohesive view on risk.
- Ability to develop and maintain robust relationships becoming a trusted partner with LOB technologists to progress toward shared goals.
- Awareness of key risks in the financial services sector, particularly pertaining to on premise and/or public cloud hosted infrastructure & applications.
- Enthusiasm for enabling the business to create new governance and controls.
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or other industry-recognized risk certifications.
- Software / Security engineering background in any modern programming languages and Cloud experience (ideally Amazon Web Services).
- Ability to think outside the box and proven experience in eliminating toil and crafting efficient processes.
About Us
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
Top Skills
Amazon Web Services
Ci/Cd
Data Protection
Iam
Information Security
Risk Management Frameworks
Similar Jobs at JPMorganChase
Financial Services
The Tech Risk and Controls Lead is responsible for managing tech risks in cloud environments, ensuring compliance, and providing guidance to stakeholders.
Top Skills:
AWSAzureCloudData SecurityGdprGoogle Cloud PlatformIso 27001Soc 2
18 Days Ago
Financial Services
Lead efforts in mitigating tech risks and ensuring compliance within the organization; manage assessments and maintain strong stakeholder relationships.
Top Skills:
ChapsSwift
Financial Services
Lead technology risk and control initiatives, analyze cybersecurity metrics, report on compliance, and develop stakeholder relationships within a diverse and technical environment.
Top Skills:
AWSCloud ComputingCybersecurity FrameworksEnterprise Risk ManagementFinancial Services Regulations
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.