Tech Risk Assurance Lead - Cyber Risk Pillar - Cryptographic Services & Data Loss Prevention

Jersey City, NJ, United States

Apply now Apply later

As a Tech Risk Assurance Lead in the Cryptography Services and Data Loss Prevention team within the Cyber Risk Pillar, you will provide expert technical risk assurance and control oversight to ensure the firm's products and lines of business achieve their objectives while effectively managing risk. Utilizing your background in cryptography, data protection, DLP and technology controls and risk management, you will work with cross-functional teams to identify, assess, and mitigate emerging risks and vulnerabilities. Your tactical and strategic decision-making will significantly impact the firm's operations, financial management, and public image. You will play a crucial role in fostering a robust risk culture and catalyzing continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.

Job responsibilities

  • Progress the Product Operating Model by partnering with stakeholders across the organization to develop Control Procedures for their respective cryptographic implementations
  • Partner with stakeholders across the firm to develop dynamic and continuous automated measurements of controls across in-scope infrastructure and application assets 
  • Contribute to the firmwide Cryptography Standards, Control Objectives, and Control Procedures (e.g., encryption at rest / in transit, cryptographic key lifecycle management)
  • Oversee the Cryptography Services Executive and Functional Operational Metrics, which enable JPMC to proactively measure, assess, inform, and improve cybersecurity and technology risk firmwide.
  • Lead comprehensive risk assessments to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies
  • Advise stakeholders on risk management, controls development and adherence to mitigate risks
  • Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and alignment to standards (e.g., PCI Data Security Standards) 

Required qualifications, capabilities, and skills

  • 5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation
  • Strong proficiency in Cryptography / Data Protection (including encryption and key management), risk management & controls, security governance, and analytical thinking, with a track record of implementing effective risk mitigation strategies
  • Demonstrated expertise in regulatory compliance, risk management frameworks, and industry best practices (e.g., NIST, ISO, FFIEC, GDPR)
  • Understanding of the external threat landscape, threat actors, adversary tactics & techniques, and industry trends
  • Strong written and verbal communication skills with ability to effectively communicate and present cybersecurity risk concepts with business and technology partners 

Preferred qualifications, capabilities, and skills

  • CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred
  • Cloud knowledge across multiple providers (e.g. AWS, GCP, Oracle) and services (SaaS, PaaS, IaaS)

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, we offer discretionary incentive compensation which may be awarded in recognition of firm performance and individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: AWS Banking CISM CISSP Cloud Compliance CRISC Cryptography Encryption FFIEC GCP GDPR Governance IaaS NIST Oracle PaaS Risk assessment Risk management SaaS Vulnerabilities

Perks/benefits: Competitive pay Health care Wellness

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.