Technology Operational Risk - Vice President

JPMorgan Chase JPMorgan Chase · Banking · United Kingdom · Corporate Sector

The role involves providing independent oversight of technology and cybersecurity operational risk management practices, with a focus on cloud technology and technical risk assessments. Responsibilities include reviewing governance, processes, and controls, engaging with technology teams to understand the environment, participating in technical risk assessments and threat modeling, evaluating risk management frameworks, and advising on policy and framework enhancements. The role also requires providing subject matter expertise in technology governance forums and reviewing significant technology-related events. Experience with cloud platforms (GCP, AWS) and AI as a subject matter area is mentioned.

What you'd actually do

  1. Perform oversight of operational risks through targeted assessments of technology / cyber security aligned processes for Chase International.
  2. Engage with technology teams to gain full understanding of the technology and control environment that supporting the business, including hands-on engagement with cloud infrastructure, security controls, and threat modelling practices.
  3. Oversee and participate in technical risk assessments, including the development and evaluation of threat models for critical systems and cloud-based solutions, assuring comprehensive identification and mitigation of potential vulnerabilities.
  4. Participate in the assessment of emerging risk based on regulatory and market developments, New Business Initiatives, or external operational risk events.
  5. Stay abreast of technology trends, threats, and emerging technologies including advancements in cloud services and controls. Integrating your insights into risk considerations for continuous oversight of the business.

Skills

Required

  • cybersecurity or engineering roles in Retail Banking
  • deep and broad understanding of cybersecurity and technology associated risks
  • deep knowledge of cloud computing, including hands-on experience with Google Cloud Platform and Amazon Web Services specifically
  • Subject matter expert in areas such as networking, identity management, access management, artificial intelligence, software development and cybersecurity
  • Excellent communication skills, experience preparing formal written documentation. Attention to detail, clear and concise writing, can translate complex technical information into understandable language for regulators.

Nice to have

  • BS/BA degree in computer science, Cyber Security or equivalent experience
  • Professional cloud certifications such as AWS Certified Security Specialty and Google Professional Cloud Security Engineer. (e.g. AWS, GCP)
  • Knowledge of cloud infrastructure and hybrid implementations, experience with cloud security posture management and data security posture management tools.
  • Ability to assess controls, identify vulnerabilities and potential mitigations.
  • Software development experience and understanding of risks associated with the software supply chain.
  • Professional Certifications in Cyber and Information Security Risk (eg. ISACA, ISC2, SANs, OffSec, CEH)

What the JD emphasized

  • regulatory obligations
  • regulatory requirements