Tech Risk Assurance Lead - Infrastructure controls

JPMorgan Chase & Co.Jersey City, New JerseyOn-siteFull-timeSenior, 5–8 yearsListed 23 hours ago

Apply now

About this role

Are you ready to make a meaningful impact on the firm's technology risk posture while working alongside some of the brightest minds in financial services? At JPMorganChase, we invest in our people, our technology, and our communities — and this role puts you at the center of it all.

As a Tech Risk Assurance Lead within the Corporate Technology Standard and Control Design team at JPMorganChase, you will support compliance and promote best practices across Global Technology within the Technology Operations and Incident & Event Management domains. You will leverage your technology risk and controls expertise to identify and assess technology risks, design or enhance mitigating controls, and partner with cross-functional teams to implement improvements that strengthen the firm's risk posture. This is an opportunity to shape how risk and control frameworks evolve across one of the world's most complex technology environments.

Job responsibilities

- Define and maintain technology control requirements in partnership with stakeholders, ensuring clear outcomes, measurable expectations, and well-defined scope

- Apply technology risk and control expertise across one or more domains including Change Management, Incident Management, and Event Management

- Build and sustain trusted partnerships with key stakeholders such as line of business security officers, assessment teams, and product leads to drive cross-functional collaboration and progress toward shared goals

- Prepare detailed reports and documentation of risk assessments, findings, and recommendations, ensuring accuracy and accessibility while supporting findings formalization and tracking to closure

- Govern, monitor, and evaluate control effectiveness on an ongoing basis, identifying gaps and recommending enhancements to strengthen risk posture and regulatory compliance

- Develop and advance analytics-driven assurance approaches for risk identification, prioritization, mitigation planning, and control assessments

- Leverage enterprise-authorized AI capabilities to accelerate synthesis of risk and control evidence and draft executive-ready reporting, validating outputs and handling data in alignment with security and sensitivity requirements

Required qualifications, capabilities, and skills

- Formal training or certification on tech risk assurance concepts and 5+ years applied experience

- 5+ years of experience with technology systems and cyber or technology risk management activities, including control effectiveness assessments, reporting, and mitigation tracking, with the ability to translate technical findings into clear business impacts

- Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices such as NIST, ISO, FFIEC, and GDPR

- Technical proficiency in AI risk governance and data security, including securing platforms, applications, and business processes with an understanding of AI threats, mitigations, and defense mechanisms

- Demonstrated experience using enterprise-authorized AI capabilities to support technology risk and controls workflows — validating AI-assisted summaries and recommendations before use, escalating when uncertain, and ensuring alignment to security, auditability, data sensitivity, and regulatory expectations

- Experience applying data analytics and data-driven approaches to risk identification, control testing, and assurance

- Demonstrated ability to influence executive-level strategic decision-making and translate technology insights into business strategy for senior stakeholders

Preferred qualifications, capabilities, and skills

- CRISC certification or equivalent risk and control certification

- Experience with AI both from a risk governance perspective and as a practitioner using AI tools such as large language models and code generation platforms

- Familiarity with incident and event management frameworks and their intersection with technology risk and compliance programs

#CTC