Tech Risk and Controls Senior Associate

JP Morgan

Location: Dorset

Job Type: Full time


Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.

As a Tech Risk & Controls Senior Associate in Cybersecurity & Tech Controls, you will contribute to the successful management of technology-aligned aspects of Governance, Risk, and Compliance in line with the firm's standards. Leverage your broad knowledge in risk management principles and practices to assess and monitor risks and implement effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm’s risk posture. Through collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards.

Job responsibilities

  • Assess and monitor technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices
  • Support implementation of effective controls in collaboration with cross-functional teams and stakeholders
  • Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm's risk posture
  • Analyze complex situations, provide advice on risk management strategies, and support the implementation of risk mitigation measures

Required qualifications, capabilities, and skills

  • Experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessment, and mitigation
  • Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards
  • Demonstrated ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders
  • Proficient knowledge of risk management frameworks, regulations, and industry best practices
  • Knowledge of multiple IT control and project management practices and experience working across large environments
  • Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals
  • Experience with ITIL production support processes is beneficial, particularly Issue Management, Technology Operations or Continuity management.
  • Expertise in application and infrastructure high-availability and resiliency architectures with demonstrated experience in business application
  • Proficiency in information security domains, including policies and standards, risk and control assessments, access controls, regulatory compliance, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, and data protection
  • Experience in cloud platform security and or Site Reliability Engineering (SRE) practices is desirable
  • Strong leadership skills with exceptional communication and presence

Preferred qualifications, capabilities, and skills

  • CISM, CRISC, CISSP, or other industry-recognized risk and risk certifications preferred