Cloud Governance Technology Risk & Controls Lead Vp

LONDON, United Kingdom

Applications have closed

Tech Risk & Controls professionals play a critical role in the identification, assessment, oversight, monitoring, and reporting of compliance and operational risk in line with the firm’s standards. They are accountable for supporting and advising technology-aligned process owners in managing operational aspects of governance, risk, and compliance. Tech Risk & Controls is also responsible for the design, implementation, and maintenance of controls and risk management frameworks, and they partner with Product Security to ensure design and implemented controls are operating in alignment with firm, regulatory, legal, and industry standards as required. Tech Risk & Controls also partners with a variety of stakeholders, including Product Managers (both business and technology aligned), Business Control Managers, 2nd Line of Defense (2LOD), Audit, Compliance, and regulators to develop and report a comprehensive view of the technology risk posture and the impact on the business.

Operating within the Cloud Foundational Services product line, a part of Infra Platforms(IP), you will provide a pivotal role in ensuring our public cloud capabilities are operating safely and securely for.  You will manage the overall book of work for ensuring the compliance of our public cloud platform, facing off to regulators, auditors, and our Cybersecurity & Technology Control function.  You will partner closely with both the product management and engineering functions to ensure the work is appropriately prioritized to ensure the technology landscape is operating within the risk appetite, and provide transparent reporting to senior management on the overall risk position of the product line.

 

Responsibilities:

We are seeking a Governance Lead for the TRC function in Cloud Foundational Services. Their role will offer guidance, best practices, and support across businesses, creating reporting, improving governance and processes, leading risk reviews and vulnerability assessments, identifying threats, and communicating with senior leaders and other stakeholders.

  • Foundational knowledge of cybersecurity organization practices, risk management processes and principles
  • Manage remediation activities ensuring appropriate, timely and complete resolution
  • Communicate technology findings with leadership and Line of Business key stakeholders and provide accurate remediation metrics and management reports on a timely basis
  • Strong report creation and presentation skills capable of speaking to all levels of the organization
  • Demonstrate ability to conduct cross functional meetings with various Line of Business stakeholders
  • Strong deductive reasoning, critical thinking, problem solving, and prioritization skills
  • Relevant certifications include: CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), CRISC (Certified in Risk Management) and CISA (Certified Information Systems Auditor).
  • Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals
  • Assist with training and spreading technology risk and control awareness within the organization, while building strong relationships and becoming a trusted risk and controls partner within the firm

 

Preferred Experience:

  • Background in  Technology with strong experience in Operational Risk including Tech/Cyber Risk
  • Strong experience in various Technology and Cyber domains, for e.g., Architecture, Vulnerability Management, Cloud, etc.
  • Risk management expertise in AWS services is a big plus
  • Relevant industry certifications are preferable
  • Ability to work with data from disparate sources to build a cohesive view on risk 
  • Experience working in regulated industries, in particular leveraging technology standards, frameworks, compliance, and industry recognized best practice/standards (e.g., ITIL, NIST, ISO, PCI, SOC)
  • Collaboration with internal and external technology audits (3rd Line of Defense), CCOR Operational Risk Management deep dives and testing (2nd Line of Defense), and the ability to advocate on behalf of subject matter experts
  • Advanced level in Office 365 with proficiency combining data sources in Excel
  • Strong written and verbal communication skills with ability to effectively communicate and present security risk concepts with business and technology partners.
  • Preferable experience working in regulated industries, in particular leveraging technology standards, frameworks, compliance, and industry recognized best practice / standards (e.g. NIST, ISO, PCI, SOC)
About Us

JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. In accordance with applicable law, we make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as any mental health or physical disability needs.

 

The health and safety of our colleagues, candidates, clients and communities has been a top priority in light of the COVID-19 pandemic. JPMorgan Chase was awarded the “WELL Health-Safety Rating” for all of our 6,200 locations globally based on our operational policies, maintenance protocols, stakeholder engagement and emergency plans to address a post-COVID-19 environment.

As a part of our commitment to health and safety, we have implemented various COVID-related health and safety requirements for our workforce. Employees are expected to follow the Firm’s current COVID-19 or other infectious disease health and safety requirements, including local requirements.  Requirements include sharing information including your vaccine card in the firm’s vaccine record tool, and may include mask wearing. Requirements may change in the future with the evolving public health landscape. JPMorgan Chase will consider accommodation requests as required by applicable law.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, discretionary incentive compensation which may be awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

Equal Opportunity Employer/Disability/Veterans

 

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
   We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Audits AWS Banking CISA CISM CISSP Cloud Compliance CRISC Governance ITIL Monitoring NIST Product security Risk management SOC Vulnerability management

Perks/benefits: Career development Competitive pay Health care Wellness

Region: Europe
Country: United Kingdom

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.