JOB DESCRIPTION
As a world leading bank, our culture is all about thinking outside the box, challenging the status quo and striving to be best-in-class.
As a Technology and Cyber Risk Management Lead within our Technology & Cyber CCOR team, you will play a pivotal role in developing and executing the Technology Compliance programme, leveraging your deep expertise in technology and cyber risk management to ensure regulatory compliance and operational resilience. You will work closely with the wider Technology & Cybersecurity CCOR team who is responsible for the design, implementation and oversight of the 2nd Line of Defence independent risk management program for technology and cybersecurity risks. As part of the team, you will also be able to broaden this platform to work on legal entity, regional and global initiatives, in addition to being part of local and firmwide community, and Diversity, Opportunity and Inclusion initiatives.
Job responsibilities
Regulatory Advisory & Compliance
-
Advise Technology and business stakeholders on regulatory requirements (e.g., DORA, EU AI Act, NIS2, Cyber Resilience Act) relating to IT Governance, resiliency, outsourcing, data loss prevention, privacy, AI, and cloud technology.
-
Review initiatives to translate regulatory changes into actionable policies and procedures, ensuring alignment across legal entities and regions.
Stakeholder Engagement & Strategic Initiatives
-
Build trusted relationships with CIB Technology, other key lines of business and JPMC stakeholders by applying your knowledge of banking processes such as trading activities, payment flows or custody and supporting technology infrastructure.
- Participate in Technology change programs, new product approvals, and external risk event analysis.
-
Engage with regional and line of business conduct, compliance, and operational risk leads to drive firmwide initiatives.
Risk Assessment & Incident Review
-
Oversee the execution of impact and gap assessments of new and emerging regulations, collaborating with divisional partners to develop and enhance compliance frameworks.
-
Perform reviews of significant technology and security events, including root cause analysis, back-testing against risk management frameworks, and escalation/reporting.
Technology Adoption & Data Analytics
-
Provide guidance on the adoption and integration of innovative technologies (e.g., Cloud, AI/ML, Quantum), ensuring compliance and risk mitigation.
-
Employ advanced data analytics to identify and address risks in critical systems of record, leveraging AI tools and modern analytic techniques.
Required qualifications, capabilities, and skills
Expertise in architecture, design, and operation of complex systems supporting global financial markets, with an understanding of process and supporting IT infrastructure supporting critical business processes such as trading, clearing and settlement, payments, and/or custody
Strong analytical skills and a growth mindset keeping abreast of innovative use of technology and emerging technologies including agentic systems and Quantum
Professional experience in risk management, compliance, or technology-related fields
Knowledge of technology and cyber regulatory expectations in high-risk jurisdictions.
Strong technical experience in technology, cybersecurity, governance, operational risk or technology compliance within the financial services industry or experience in an equivalent role in the technology industry
-
Knowledge and experience with Information Security and Risk Management standards and frameworks such as NIST, ISO 27001/27002 and modern development practices and supporting toolsets (e.g. Agile, DevOps, AI assisted coding)
-
Understanding of technology risk management and control principles with a proven ability to anticipate and identify risks and effective mitigating actions
-
Strong organizational, project management, data analysis and modern data analytic techniques, multi-tasking and stakeholder management skills with demonstrated ability to manage expectations and deliver results with a high level of professionalism, self-motivation, and integrity
-
Experienced in using AI tools to support data analytics and preparation of deliverables
Preferred qualifications, capabilities, and skills
-
Professional IT and Information Security certifications such as CISSP, CISA, CISM, CRISC, CGEIT as well as Cloud related certifications (e.g. CCSP, AWS Certified Practitioner) are beneficial
-
EMEA technology regulatory knowledge is preferred and an understanding of EU regulation (i.e. DORA, EU AI Act, Cyber Resilience Act, NIS2 etc.)
-
Knowledge of innovative and automation technologies and supporting toolsets such Alteryx, UiPath, Qlik sense, Tableau etc
-
Proficiency in effective prompting to responsibly leverage AI solutions
ABOUT US
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
ABOUT THE TEAM
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.