Tech Risk and Controls Lead

Company: JP Morgan Chase
Apply for the Tech Risk and Controls Lead
Location: London
Job Description:

Overview

In this role, you lead technology risk management within the Cyber Security Tech Controls team, aligned to Corporate Investment Banking. You identify, assess and monitor tech risks, and support the design and effectiveness of controls to strengthen the firm’s risk posture. You collaborate with cross-functional teams and application owners to ensure governance, regulatory compliance and industry best practices. You will leverage threat modelling to anticipate threats and advise on risk mitigation, contributing to a robust risk program and security posture.

Responsibilities

  • Assess, monitor and report technology risks in line with firm standards and regulatory requirements
  • Support implementation of effective controls with cross-functional teams
  • Evaluate existing controls, identify gaps, and recommend improvements
  • Analyze complex situations and advise on risk mitigation measures
  • Document and articulate risks; raise issues and action plans with application teams
  • Identify attack and threat vectors through threat modelling with application teams

Key requirements

  • Formal experience in technology risk management, information security or related field with focus on risk identification, assessments, controls testing and mitigation
  • Experience in risk identification, assessment and control evaluation with understanding of industry standards
  • Ability to analyze complex issues, develop risk mitigation strategies and communicate with senior stakeholders
  • Proficient knowledge of risk management frameworks, regulations and best practices
  • Good understanding of SDLC, CI/CD, application resiliency and security, IAM, data protection and vulnerability management
  • Technical ability to gather data from disparate sources to build a cohesive risk view
  • Ability to build trusted partnerships with LOB technologists to progress shared goals
  • Awareness of risks in financial services, especially on-prem and cloud hosted infrastructure and applications
  • Enthusiasm for enabling governance and controls
  • Stakeholder management
  • Analytical thinking
  • Collaborative mindset
  • SDLC pipelines
  • CI/CD
  • Application resiliency and security

…

Posted: September 14th, 2026