As a Technology Risk Assurance Lead at JPMorgan Chase within the Cybersecurity & Technology Controls Organization, you'll be combining signals analysis and security expertise to discover and remediate hidden risk. In this role, you'll identify risk trends across all lines of business, working with a wide range of technology and resources. You'll have the opportunity to analyze information security data from multiple sources and create actionable intelligence. You'll dive deep into issues, promoting root cause analysis and issue remediation. This role will allow you to lead hard conversations with care and compassion, demonstrating your strong empathy and focused curiosity..
This position is anticipated to require the use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
Job responsibilities:
1. Lead comprehensive risk investigations to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
2. Advise stakeholders on risk management, controls development and adherence to mitigate risks
3. Proactively monitor key risk indicators, analyze control metrics, and offer insights on risk management effectiveness to senior management, driving continuous improvement initiatives
4. Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and internal policies
Required qualifications, capabilities and skills:
5. Formal training or certification in Information Security, and/or 5+ years of project management experience with demonstrated experience working on information security projects.
6. Experience performing structured investigations into security related incidents.
7. Demonstrable knowledge across 3 or more of the following domains: Network security architecture Application Security / Threat Modeling Development, Security, and Operations (DevSecOps) / Coding Security Practices Governance, Risk and Compliance ( NIST, GDPR, etc) Penetration Testing / Red Teaming Security Operations / Security Monitoring Cloud Security Architecture Data Privacy Business Continuity Technology Education
8. Demonstrable ability to craft technical risk reports, adjusted for audience.
9. Ability to collaborate and communicate with a diverse range of stakeholders, of varying seniority, to effectively articulate risk and drive change.
10. Experience in Agile project management and with Agile tools/technology (., Atlassian Jira, Atlassian Confluence).
11. Understanding of offensive and defensive security tools/technologies, such as penetration testing and red team testing platforms, firewalls, IDS/IPS, Web Proxies, and DLP.
Preferred qualifications, capabilities and skills:
12. CISSP, CISM, CISA, Offensive Security (OSCP, OSEP, OSDA), SANS (GIAC, GPEN, GXPN, GWAPT), CRISC