Job Description
Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.
As a Tech Risk & Controls Director in Cyber Security and Technology Controls you will play a pivotal role in shaping and implementing the firm's technology risk management strategy. Leveraging your advanced knowledge and expertise in technology-risk disciplines, you will identify, oversee, and mitigate compliance and operational risks in line with the firm's standards. You will collaborate with various stakeholders, including Product Owners, Business Control Managers, and regulators, to develop and maintain a comprehensive view of the technology risk posture and its impact on the business. Your ability to make calculated decisions, manage large teams, and drive strategic projects will be crucial in ensuring the firm's adherence to regulatory obligations and industry best practices. Your work will contribute to the long-term success and resilience of the organization in an ever-evolving technology landscape. Your advanced knowledge of risk management principles, practices, and theories will enable you to drive innovative solutions and effectively manage a diverse team in a dynamic and evolving risk landscape.
Job responsibilities
- Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks, and drive strategic projects and initiatives to enhance the firm's technology risk management capabilities, in line with industry best practices and the firm's standards and regulatory requirements
- Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards.
- Manage reporting and governance of overall controls, policies, issue management, and measurements, etc., providing insight to senior leaders into effectiveness of controls and inform governance work.
- Create a proactive risk and control culture. Offer guidance, best practices, and support across businesses to drive awareness and understanding of the business risk and controls framework and challenges to compliance.
- Work closely with various partners across the firm, including but not limited to colleagues in Enterprise Technology, Global Technology, Controls Managers, Business Information Security Officers and Technologists in our Businesses and Corporate Functions, Operational Risk Management & Compliance, Audit, as well as regional partners across the globe.
- Manage end-to-end execution of the Compliance and Operational Risk Evaluation (CORE) frameworks , including control deficiencies and resolutions, to reduce financial loss, regulatory exposure, and reputational risk.
- Act as the SME on operational risk management.
- Engage with Technology leaders to understand the business structure, assess business strategies and processes, guide risk management, and understand opportunities to make process improvements.
- Lead the identification, escalation, monitoring and measuring of operational risk in accordance with firm-wide operational risk programs.
- Lead and provide independent risk and control advisory support and risk challenge, inclusive of targeted reviews, root cause analysis, and developing sustainable and strategic risk mitigation solutions.
- Manage control governance and reporting to identify meaningful metrics to inform on the health of operational risk and control environment; escalate control gaps and weaknesses based on key reporting indicators; and manage control committees and forum inputs from CORE.
Required qualifications, capabilities, and skills
- Formal training or equivalent advanced expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation
- Advanced experience in either; controls, audit, quality assurance, risk management, or compliance with the ability to design, create and evaluate the operational risk and control environment in conjunction with business partners
- Experience working on topics related to operational risk management and reporting
- Strong people management and ability to establish a team with a good and effective culture.
- Flexible, adaptable to shifting priorities; manages competing priorities to achieve the most effective result and able to work in a fast-paced, results focused environment
- Expert level project time management skills to meet strict deadlines
- Ability to understand a process and associated risk to inform control design
- Solid critical thinking, attention to detail and analytical skills; able to synthesize large amounts of data and formulate appropriate conclusions including: understanding root cause / identifying control deficiencies, developing timely and sustainable solutions and analyzing metrics for emerging risk
- Implementation skills including:writing action plans and procedures, change management and the ability to make subjective and informed decisions based upon output, influence stakeholders and justify decision making
- Ability to assess risk from multiple perspectives (Legal/Regulatory/Operational/Client & Reputational) and then have meaningful business conversations, grounded in materiality and practical application.
- Excellent change management, decision making, problem solving, continuous improvement, executive communication, and teamwork skills
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred
About Us
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the Team
The Cybersecurity & Technology Controls group at JPMorganChase aligns the firm's cybersecurity, access management, controls and resiliency teams. The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls. The group's number one priority is to enable the business by keeping the firm safe, stable and resilient.
High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters. Users in these roles are subject to enhanced pre-hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.