About this role
Join a team where your investigative instincts and attention to detail directly protect millions of clients and one of the world's most recognized financial brands. At JPMorganChase, the Brand Protection team sits at the intersection of cybersecurity, fraud, and intelligence — and your work here will have real, measurable impact from day one.
As a Cyber Intelligence Associate at JPMorganChase within the Brand Protection team, you will support the day-to-day monitoring and investigative response to online misuse of JPMorganChase brands. You will triage alerts, validate findings using approved tools and datasets, document evidence clearly, and coordinate remediation actions with internal partners and approved external providers. Your contributions will help reduce risk to clients and the firm by enabling faster detection, higher-quality assessments, and efficient remediation of brand abuse across phishing, impersonation, fraudulent domains, fake applications, and deceptive content.
This role is designed for an early-career analyst who is detail-oriented, eager to grow, and comfortable operating in a high-tempo, service-level-driven environment where accuracy and speed both matter.
Job responsibilities
- Triage and investigate incoming alerts for potential brand misuse involving JPMorganChase brands, including phishing, impersonation, fraudulent domains, fake applications, deceptive advertisements, and content infringement
- Conduct open-source intelligence-driven validation using approved internal datasets and external research sources, collecting and documenting evidence clearly and consistently
- Apply established playbooks to assess severity, likely intent, and potential business impact, escalating cases to appropriate stakeholders — including cybersecurity, risk, legal, and communications — based on defined criteria
- Initiate and track remediation actions such as takedowns, blocks, and removals via established workflows, maintaining accurate case status through to closure
- Produce clear, concise reporting including incident summaries, case notes, and stakeholder updates that translate technical findings into business risk language
- Contribute to operational improvements by updating documentation, supporting quality checks, and tracking key metrics such as time-to-triage, time-to-remediation, and repeat offender patterns
- Stay current on evolving phishing and impersonation techniques and proactively share learnings with the broader team
Required qualifications, capabilities, and skills
- Formal training or certification on cyber intelligence concepts and 2+ years applied experience
- Bachelor's degree or 1+ year of equivalent practical experience — including internships or co-ops — in cybersecurity, investigations, fraud, trust and safety, risk, or a related operational field
- Strong analytical judgment and attention to detail, with the ability to separate signal from noise and follow evidence-based workflows
- Strong written communication and documentation habits, including clear articulation of evidence, rationale, and actions taken
- Demonstrated ability to collaborate across multiple teams and work effectively within defined service-level agreements and structured processes
- Exposure to domain and DNS intelligence, phishing infrastructure analysis, social media platform reporting, and takedown workflows
Preferred qualifications, capabilities, and skills
- Familiarity with the intelligence cycle, including collection, processing, analysis, dissemination, and feedback
- Experience with case management or ticketing systems in an operational environment
- Introductory experience with query or search tools such as SQL, Splunk, or similar platforms
- Basic scripting experience, such as Python, to support investigative or operational workflows
#CTC