Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

JPMorgan Risk Assurance Investigator - Integrations 
United States, Texas, Plano 
441889504

07.09.2024

As a Risk Assurance Investigator - Integrations within the Cybersecurity & Technology Controls Organization, you'll combine signals analysis and security expertise to discover and remediate hidden risk. The role operates and identifies risk trends across all lines of business, working with the entire breadth of technology and resources. You will be required the use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment with a proven track record in effectively analyzing information security data from multiple sources and creating actionable intelligence.

Job responsibilities:

  • Lead comprehensive risk investigations to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
  • Advise stakeholders on risk management, controls development and adherence to mitigate risks
  • Proactively monitor key risk indicators, analyze control metrics, and offer insights on risk management effectiveness to senior management, driving continuous improvement initiatives
  • Provide guidance to development and data science teams building next generation risk tooling
  • Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and internal policies

Required qualifications, capabilities, and skills:

  • Obtain formal training or certification in Information Security, and/or 5+ years of Information Security experience, and/or 5+ years of demonstrated experience working on security investigations.
  • Developed experience in roles such as security engineering, security architecture, security assurance, security operations, vulnerability management, threat modeling, assessments and penetration testing, or risk management will be helpful.
  • Experience with integrations and automations tooling (Python, Jupyter, etc)
  • Experience connecting systems and data sets to provide signal intelligence.
  • Experience performing structured investigations into security related incidents.
  • Demonstrable ability to craft technical risk reports, adjusted for audience.
  • Formal knowledge in Application/Security, Threat Modeling, Penetration Testing / Red Teaming
  • Familiar knowledge in development, security, and operations (DevSecOps) / Coding Security Practices.
  • Working knowledge in Governance, Risk, and Compliance (NIST, GDPR), Data Privacy, Business Continuity, Cloud Architecture.
  • Ability to collaborate and communicate with a diverse range of stakeholders, of varying seniority, to effectively articulate risk and drive change.
  • Understanding of offensive and defensive security tools/technologies, such as penetration testing and red team testing platforms, firewalls, IDS/IPS, Web Proxies, and DLP.

Preferred qualifications, capabilities, and skills

  • CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are useful
  • Offensive Security (OSCP, OSEP, OSDA)