Expoint - all jobs in one place

המקום בו המומחים והחברות הטובות ביותר נפגשים

Limitless High-tech career opportunities - Expoint

JPMorgan Tech Risk Assurance Lead - Cyber Pillar 
United States, New Jersey, Jersey City 
462944487

Yesterday

As a Tech Risk Assurance Lead within the Cryptography Services and Data Loss Prevention - Cyber Risk Pillar team, you will provide expert technical risk assurance and control oversight to ensure the firm's products and lines of business achieve their objectives while effectively managing risk. Utilizing your background in cryptography, data protection, DLP and technology controls and risk management, you will work with cross-functional teams to identify, assess, and mitigate emerging risks and vulnerabilities. Your tactical and strategic decision-making will significantly impact the firm's operations, financial management, and public image. You will play a crucial role in fostering a robust risk culture and catalyzing continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.

Job responsibilities

  • Progress the Product Operating Model by partnering with stakeholders across the organization to develop Control Procedures for their respective cryptographic implementations
  • Partner with stakeholders across the firm to develop dynamic and continuous automated measurements of controls across in-scope infrastructure and application assets
  • Contribute to the firm wide Cryptography Standards, Control Objectives, and Control Procedures (e.g., encryption at rest / in transit, cryptographic key lifecycle management)
  • Oversee the Cryptography Services Executive and Functional Operational Metrics, which enable JPMC to proactively measure, assess, inform, and improve cybersecurity and technology risk firm wide.
  • Lead comprehensive risk assessments to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
  • Advise stakeholders on risk management, controls development and adherence to mitigate risks
  • Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and alignment to standards (e.g., PCI Data Security Standards)

Required qualifications, capabilities, and skills

  • 5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation
  • Strong proficiency in Cryptography / Data Protection (including encryption and key management), risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
  • Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
  • Understanding of the external threat landscape, threat actors, adversary tactics & techniques, and industry trends
  • Strong written and verbal communication skills with ability to effectively communicate and present cybersecurity risk concepts with business and technology partners

Preferred qualifications, capabilities, and skills

  • CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred
  • Cloud knowledge across multiple providers (e.g. AWS, GCP, Oracle) and services (SaaS, PaaS, IaaS)