Tech Risk and Controls Lead

🏢 JP Morgan
📍 LONDON, United KingdomFull-timeOn-site
📅 Posted: 2d ago🔄 Updated: 2d ago
CV%
✨ AI Summary
The Tech Risk and Controls Lead will be responsible for navigating complex risk landscapes and fortifying technology governance within the Corporate Investment Banking division. This role involves assessing, monitoring, and reporting technology risks, implementing and evaluating controls, and analyzing/mitigating complex situations. Key responsibilities include documenting risks, communicating issues and action plans, and identifying attack and threat vectors through threat modeling. The ideal candidate will have experience in technology risk management, information security, risk identification, assessment, controls testing, and mitigation, with a strong understanding of industry standards and risk management frameworks. Proficiency in SDLC, CI/CD, application security, IAM, data protection, and vulnerability management is necessary, along with the ability to analyze complex issues and build robust relationships with stakeholders.
Required Skills
Business, Sales & Management
Risk Management
Information Technology
Information SecuritySDLCCI/CDApplication Security TestingIAMVulnerability ManagementThreat Modeling
Engineering, Construction & Trades
Risk Assessment
Other
controls testing
Finance, Legal & Governance
Risk MitigationData Protection & Privacy
Soft Skills & Professional Competencies
ResilienceAnalytical SkillsCommunicationRelationship Building
Nice to have:
Information Technology
AWS
Business, Sales & Management
Process Improvement
Requirements
Requires formal experience or equivalent expertise in technology risk management, information security, or a related field, focusing on risk identification, assessments, controls testing, and mitigation. Must have demonstrated ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders. Proficiency in risk management frameworks, regulations, industry best practices, SDLC pipelines, CI/CD, application resiliency and security, IAM, Data Protection, and vulnerability management is essential. Technical ability to gather and combine data from disparate sources and awareness of key risks in the financial services sector are also required.
Description

Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.

As a Tech Risk & Controls Lead in the Cyber Security Tech Controls (CTC) team, aligned with the Corporate Investment Banking division, you will be an integral part of a cyber risk management function. You will cover technology teams and applications that support various business units within the firm, including sales, trading, operations, risk and research.

You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm's standards. Leveraging your broad knowledge in risk management principles and technical experience, you will identify, assess, and monitor risks and the implementation of effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm’s risk posture. Through a deep technical aptitude, collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards. 

Job responsibilities

  • Assess risk, Monitoring & Reporting: Assess, monitor & report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
  • Implement controls: Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
  • Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm's risk posture.
  • Analyze/Mitigate: Analyze complex situations, provide advice on risk management strategies, and support the implementation of risk mitigation measures.
  • Document and Communicate: Document and articulate risks appropriately; raise issues and action plans as appropriate in partnership with application teams.
  • Identify threats: Work closely with application teams to identify attack and threat vectors through threat modelling.


 Required qualifications, capabilities, and skills

  • Formal experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessments, controls testing, and mitigation.
  • Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards.
  • Demonstrated ability to analyse complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders.
  • Proficient knowledge of risk management frameworks, regulations, and industry best practices.
  • Good understanding of Software Development Life Cycle (SDLC) pipelines, CI/CD, application resiliency and security, IAM, Data Protection and vulnerability management.
  • Technical ability to gather and combine data from disparate sources to build a cohesive view on risk.
  • Ability to develop and maintain robust relationships becoming a trusted partner with LOB technologists to progress toward shared goals.
  • Awareness of key risks in the financial services sector, particularly pertaining to on premise and/or public cloud hosted infrastructure & applications.
  • Enthusiasm for enabling the business to create new governance and controls.


 Preferred qualifications, capabilities, and skills

  • CISM, CRISC, CISSP, or other industry-recognized risk certifications.
  • Software / Security engineering background in any modern programming languages and Cloud experience (ideally Amazon Web Services).
  • Ability to think outside the box and proven experience in eliminating toil and crafting efficient processes.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00