As a Technology Risk Assurance Lead at JPMorgan Chase within the Cybersecurity & Technology Controls Organization, you'll be combining signals analysis and security expertise to discover and remediate hidden risk. The role operates and identifies risk trends across all lines of business, working with the entire breadth of technology and resources.
A successful candidate will have a proven track record in effectively analyzing information security data from multiple sources and creating actionable intelligence. They seek to understand beyond the surface of an issue, driving root cause analysis and issue remediation. They have strong empathy and question with focus and true curiosity. A strong candidate demonstrates the ability to lead hard conversations with care and compassion.
Previous experience in roles such as security architecture, security assurance, security operations, vulnerability management, threat modeling, assessments and penetration testing, or risk management will be helpful.
This position is anticipated to require the use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
- Lead comprehensive risk investigations to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
- Advise stakeholders on risk management, controls development and adherence to mitigate risks
- Proactively monitor key risk indicators, analyze control metrics, and offer insights on risk management effectiveness to senior management, driving continuous improvement initiatives
- Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and internal policies
Required qualifications and/or skills:
- Formal training or certification in Information Security, and/or 5+ years of project management experience with demonstrated experience working on information security projects.
- Experience performing structured investigations into security related incidents.
- Demonstrable knowledge across 3 or more of the following domains:
- Network security architecture
- Application Security / Threat Modeling
- Development, Security, and Operations (DevSecOps) / Coding Security Practices
- Governance, Risk and Compliance ( NIST, GDPR, etc)
- Penetration Testing / Red Teaming
- Security Operations / Security Monitoring
- Cloud Security Architecture
- Data Privacy
- Business Continuity
- Technology Education
- Demonstrable ability to craft technical risk reports, adjusted for audience.
- Ability to collaborate and communicate with a diverse range of stakeholders, of varying seniority, to effectively articulate risk and drive change.
- Experience in Agile project management and with Agile tools/technology (i.e., Atlassian Jira, Atlassian Confluence).
- Understanding of offensive and defensive security tools/technologies, such as penetration testing and red team testing platforms, firewalls, IDS/IPS, Web Proxies, and DLP.
Preferred qualifications:
- CISSP, CISM, CISA, Offensive Security (OSCP, OSEP, OSDA), SANS (GIAC, GPEN, GXPN, GWAPT), CRISC