As a Tech Risk Assurance Lead within the Cryptography Services and Data Loss Prevention - Cyber Risk Pillar team, you will provide expert technical risk assurance and control oversight to ensure the firm's products and lines of business achieve their objectives while effectively managing risk. Utilizing your background in cryptography, data protection, DLP and technology controls and risk management, you will work with cross-functional teams to identify, assess, and mitigate emerging risks and vulnerabilities. Your tactical and strategic decision-making will significantly impact the firm's operations, financial management, and public image. You will play a crucial role in fostering a robust risk culture and catalyzing continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.
Want more jobs like this?
Get jobs delivered to your inbox every week.
Job responsibilities
- Progress the Product Operating Model by partnering with stakeholders across the organization to develop Control Procedures for their respective cryptographic implementations
- Partner with stakeholders across the firm to develop dynamic and continuous automated measurements of controls across in-scope infrastructure and application assets
- Contribute to the firm wide Cryptography Standards, Control Objectives, and Control Procedures (e.g., encryption at rest / in transit, cryptographic key lifecycle management)
- Oversee the Cryptography Services Executive and Functional Operational Metrics, which enable JPMC to proactively measure, assess, inform, and improve cybersecurity and technology risk firm wide.
- Lead comprehensive risk assessments to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
- Advise stakeholders on risk management, controls development and adherence to mitigate risks
- Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and alignment to standards (e.g., PCI Data Security Standards)
Required qualifications, capabilities, and skills
- 5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation
- Strong proficiency in Cryptography / Data Protection (including encryption and key management), risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
- Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
- Understanding of the external threat landscape, threat actors, adversary tactics & techniques, and industry trends
- Strong written and verbal communication skills with ability to effectively communicate and present cybersecurity risk concepts with business and technology partners
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred
- Cloud knowledge across multiple providers (e.g. AWS, GCP, Oracle) and services (SaaS, PaaS, IaaS)
ABOUT US
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
ABOUT THE TEAM
Our Corporate Technology team relies on smart, driven people like you to develop applications and provide tech support for all our corporate functions across our network. Your efforts will touch lives all over the financial spectrum and across all our divisions: Global Finance, Corporate Treasury, Risk Management, Human Resources, Compliance, Legal, and within the Corporate Administrative Office. You'll be part of a team specifically built to meet and exceed our evolving technology needs, as well as our technology controls agenda.