Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.
As a Tech Risk & Controls Director in Cybersecurity and Technology Controls, you will play a pivotal role in shaping and implementing the firm's technology risk management strategy. Leveraging your advanced knowledge and expertise in technology-risk disciplines, you will identify, oversee, and mitigate compliance and operational risks in line with the firm's standards. You will collaborate with various stakeholders, including Product Owners, Business Control Managers, and regulators, to develop and maintain a comprehensive view of the technology risk posture and its impact on the business. Your ability to make calculated decisions, manage large teams, and drive strategic projects will be crucial in ensuring the firm's adherence to regulatory obligations and industry best practices. Your work will contribute to the long-term success and resilience of the organization in an ever-evolving technology landscape.
Want more jobs like this?
Get jobs delivered to your inbox every week.
The Tech Risk and Controls Director will be a part of the Control and Operational Risk Evaluation (CORE) team within GRC. The Director will be able to leverage their experience to advance the firm's processes for managing technology risks and controls, which aligns technology policy with cybersecurity & technology control solutions and (based on metrics and quantitative assessment) appropriately informs the firm's Operational Risk Management reporting. Note that although the framework is established and operational, the space is dynamic, rapidly evolving, and is subject to continuous reassessment and changing priorities.
The position will work closely with various partners across the firm, including but not limited to colleagues in CTC, Enterprise Technology product & engineering, Information Risk Managers and Technologists in our Businesses and Corporate Functions, Operational Risk Management & Compliance, Audit, as well as regional partners across the globe. The ability to work effectively with a diverse set of stakeholders is essential. The role requires creativity, critical thinking, strong communication and influencing skills, and the ability to work across a large and complex organization that features prominently in both U.S. critical infrastructure and the global financial ecosystem.
Job responsibilities
- Working within the CORE team, in partnership with stakeholders from across Global Technology, you will lead the ongoing program to accurately represent and maintain the firm's complex technology operations within the Corporate Operational Risk Environment (CORE) system. This includes:
- Consulting with technology owners in Product, Engineering and Operations to appropriately model their processes, sub-processes, risks and controls for assessment.
- Ensuring technology risk and controls reference data (e.g., risk scenarios, policies, standards, procedures, etc.) is available and aligned for use in CORE, such that assessments are consistent and can be justifiably informed by the performance data gathered from the technology estate (i.e., metrics & measures).
- Consulting with business-aligned information risk managers to ensure technology assessments are aligned and inform business operational risk assessments in a meaningful, actionable manner.
- Collaborating closely with Operational Risk Management and Business Controls Management to ensure that technology risk and control taxonomies are optimised, with supporting systems able to interoperate.
- As the CORE system is used to manage and report the firm's Operational Risk (including information, technology & cybersecurity risk), it is referenced by a majority of the independent assessments, audits and regulatory exams that the firm's technology is continuously subject to. As a result, there are a significant number of partners from across Global Technology and beyond interested in the content of CORE. Effective communications, influencing and stakeholder management are key aspects of this role, including with senior and executive management.
- Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks, and drive strategic projects and initiatives to enhance the firm's technology risk management capabilities, in line with industry best practices and the firm's standards and regulatory requirements
- Identify and escalate emerging and upstream technology risk through execution of the Firm's management framework tools, including risk event management, reporting, and action plan tracking, and provide expert counsel to stakeholders and constituents regarding their security obligations, facilitating acceptable outcomes
- Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards
- Manage reporting and governance of overall controls, policies, issue management, and measurements, etc., providing insight to senior leaders into effectiveness of controls and inform governance work
Required qualifications, capabilities, and skills
- 7+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation
- Demonstrated expertise in risk management frameworks, industry standards, and regulatory requirements relevant to the financial industry (e.g., GDPR, PCI-DSS, SOX, NIST, ISO, ISACA, etc.)
- Proven experience leading/managing in the technology risk & controls and information risk management fields.
- Mastery of multiple business disciplines and functions, including policies and standards, risk and control assessments, access controls, control remediation, regulatory compliance, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, and data protection
- Expertise in understanding the technology development lifecycle and the integration of Governance, Risk, and Compliance (GRC) considerations from inception.
- Good working knowledge of technology-relevant financial services regulation (e.g., FFIEC handbooks, etc.)
- Adept at developing relationships with senior business executives; reputation for partnering across organization lines to mitigate risks
- Strong organizational, project management, and multi-tasking skills with demonstrated ability to manage expectations and deliver results. Ability to leverage methodologies and tools such as Agile, Scrum, Jira, etc.
- Experience in identifying and using data from large data sets to support enterprise scale initiatives via analytics leveraging tools such as SQL, Python, R, Tableau, etc.
- Ability to collaborate with high-performing teams and diverse stakeholders to accomplish common goals, including experience working with geographically distributed and culturally diverse colleagues
Required qualifications, capabilities, and skills
- Experience with AI and machine learning techniques for data analysis.
- Hold active and relevant technical qualifications such as MIRM, CRISC, CISM, CISA, CISSP, AWS Certified Security etc.
ABOUT US
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, we offer discretionary incentive compensation which may be awarded in recognition of firm performance and individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
ABOUT THE TEAM
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.