Tech Risk and Controls Lead

JPMorgan Chase & Co.London, EnglandOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

As a Tech Risk & Controls Lead in the Cyber Security & Tech Controls (CTC) team, aligned to the Corporate Investment Banking division, you will be a key member of the Cyber Risk Management function supporting technology teams that build, operate, and deliver financial markets platforms and applications across the CIB Markets business. You will operate at the intersection of cybersecurity, engineering, and GRC—driving outcomes through hands-on technical analysis, practical control design, and evidence-based risk decisions.

You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm’s standards, with a strong emphasis on practical implementation realities (architecture, infrastructure, SDLC, tooling, and operational resilience). Leveraging a deep technical and/or engineering background and broad risk management experience , you will identify, assess, and monitor risks and the implementation of effective controls across complex systems and environments. You will be expected to review architectures, interrogate technical designs, validate control effectiveness through artifacts/logs/configurations , and translate technical deficiencies into clear risk narratives for senior stakeholders.

Job responsibilities

- Identify risks: Conduct hands-on technical deep dives across a diverse portfolio of applications to identify emerging and upstream technology and cyber risks.
- Assess risk, monitoring & reporting: Assess, monitor, and report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
- Implement controls: Design & Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
- Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm’s risk posture.
- Analyze & mitigate: Analyze complex situations, advise on risk management strategies, and support the implementation of risk mitigation measures.
- Document & communicate: Document and articulate risks appropriately; raise issues and define action plans in partnership with application teams.
- Identify threats: Work closely with application teams to identify attack paths and threat vectors through threat modeling .

Required qualifications, capabilities, and skills

- Software and/or security engineering background, including experience with modern programming languages (e.g., Python ) and cloud ( AWS ).
- Proven technology risk / information security experience, including risk identification, assessments, control testing, mitigation, and applying industry standards and best practices.
- Strong technical domain knowledge across Software Development Life Cycle (SDLC) and CI/CD, application resilience and security, IAM, data protection, and vulnerability management—especially for on‑prem and public-cloud environments in financial services.
- Analytical and execution skills to assess complex issues, synthesize data from disparate sources into a cohesive risk view, and design/implement pragmatic risk mitigation strategies.
- Strong stakeholder management: communicate clearly with senior leaders and build trusted, durable partnerships with LOB technologists to achieve shared outcomes.
- Governance- and control-oriented mindset, with working knowledge of risk frameworks and relevant regulations; motivated by enabling the business through strengthened controls.

Preferred qualifications, capabilities, and skills

- Industry-recognized risk certifications (e.g., CISM, CRISC, CISSP ).
- Process-improvement mindset with a track record of reducing toil and building efficient, scalable processes.
- Experience with booking, pricing, and risk ecosystems (e.g., Athena, SecDb, Quartz, RICE, or equivalent) strongly preferred.
- Familiarity with large-scale Python codebases.
- Exposure to AI-driven risks and emerging threat patterns.