Technology Risk and Controls [Multiple Positions Available]
JPMorgan Chase
- Location
- Jersey City, NJ, United States
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 1,524 approvals (FY2023)
- Posted
- Aug 18, 2026
Skills
About this role
Duties
Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks. Drive strategic projects and initiatives to enhance the firm's technology risk management capabilities, in line with industry best practices, and the firm's standards and regulatory requirements. Establish and maintain strong relationships with internal and external stakeholders, including key cross- functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards for public cloud environment by delivering timely responses and complying with stipulated deadlines. Conduct root cause analysis to identify the underlying causes and themes of issues and incidents, developing actionable insights and recommendations to address these root causes and prevent recurrence. Manage reporting and governance of overall controls, policies, issue management, and measurements, providing insight to senior leaders into the effectiveness of controls and inform governance work. Oversee a cross-functional team to identify and escalate emerging and upstream technology risks through execution of the firm's management framework tools, including risk event management, reporting, and action plan tracking, and provide expert counsel to stakeholders and constituents regarding their security obligations, facilitating acceptable outcomes.
QUALIFICATIONS
Minimum education and experience required: Master's degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, or related field of study plus 3 years of experience in the job offered or as Technology Risk and Controls or related occupation. The employer will alternatively accept a Bachelor's degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, or related field of study plus 5 years of experience in the job offered or as Technology Risk and Controls or related occupation.
Skills
Required: This position requires three (3) years of experience with the following: Collaborating with teams on cross- functional projects involving strategic planning and multistakeholder alignment in risk assessment and reporting; Providing oversight, control evaluation, design, and governance across product lines, implementing effective risk mitigation strategies within the cloud and cybersecurity domain in multi- year projects; Leveraging cybersecurity standards and frameworks including STRIDE, MITRE, and FAIR in cloud security concepts including technology risk management and information security, with risk identification, assessment, and mitigation; Applying risk frameworks and tooling aligned to common cybersecurity standards including NIST CSF, NIST SP 800-53, ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, SOC2, CIS Controls, PCI DSS, PDPA, PCPD, and financial industry regulatory requirements; Performing risk assessments, control evaluations, or security analysis with public cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud Platform; Advising, providing responses, and reporting to financial regulators on matters related to adopting cloud technology in the financial services environment within the banking and securities sectors for APAC, NA, and EMEA locations including adhering to the cloud standards of each country's financial regulatory authority including MAS, OJK, HKMA, FCC, PRA, FFIEC, OCC, FRB, and RBI. Job Location: 575 Washington Blvd, Jersey City, NJ 07310. We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, discretionary incentive compensation which may be awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a