Expoint - all jobs in one place

מציאת משרת הייטק בחברות הטובות ביותר מעולם לא הייתה קלה יותר

Limitless High-tech career opportunities - Expoint

JPMorgan Tech Risk Controls Lead 
United States, Virginia 
566733505

15.04.2025

As a Tech Risk & Controls Leadyou will be responsible for identifying, and mitigating compliance and operational risks in line with the firm's standards. As part of the Supplier and Third-Party Risk Governance team, you will be instrumental in advancing our risk governance framework. This role provides a unique opportunity to drive the development and execution of a comprehensive supplier and third-party risk management strategy for technology. You will utilize your expertise to conduct thorough technical and risk analyses, ensuring our technology controls are effectively designed and adhere to regulatory, legal, and industry standards.


Job responsibilities

  • Lead the creation of a robust supplier and third-party risk governance framework for technology by compiling current and relevant data. Establish a scope of third-party governance controls to ensure comprehensive risk management.
  • Model a risk-based approach to third-party governance, ensuring that all procedures are thoroughly documented and stored for reporting purposes.
  • Identify methods to map disaggregated data or systems, creating an end-to-end analysis of supplier governance within the firm.
  • Expand reporting capabilities based on findings, automating data collection processes to enhance efficiency and accuracy.
  • Extend critical metrics to encompass all of Global Technology, ensuring a comprehensive view of supplier and third-party risk across the organization.
  • Act as a strategic thinker, engaging with cross-functional stakeholders to expand and strengthen relationships. Collaborate with Corporate Third-Party Oversight and other related stakeholder teams to enhance the management of supplier assessment findings.
  • Communicate observations and insights to governance partners and senior executives to inform strategic decision-making.

Required Qualifications, Capabilities, and Skills

  • Formal training or certification on security concepts and 5+ years of applied experience.
  • Good experience in GRC, supplier risk management, or third-party technology governance.
  • Proficient in information security domains, including policies and standards, risk and control assessments, and regulatory compliance.
  • Good hands on experience in data security, control evaluation, and governance design, with a proven record of implementing effective risk mitigation strategies.
  • Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives.
  • Excellent analytical skills with the ability to perform governance risk analysis, a proven track record of delivering strategic outcomes, and analytical skills to map and analyze complex data systems.

Preferred qualifications, capabilities, and skills

  • CISA, CRISC, or similar industry-recognized risk and risk certifications are preferred