Technology Risk and Controls Lead - Portfolio of Applications

JPMorgan Chase JPMorgan Chase · Banking · Columbus, OH +1 · Corporate Sector

This role serves as a Technology Risk and Controls Lead for a portfolio of applications within JPMorgan Chase's Cybersecurity and Technology Controls organization. The primary focus is on advising on and managing technology risks throughout their lifecycle, including identification, remediation guidance, registration, and reporting. The role requires expertise in risk management principles, information security, data, access, and vulnerability management, with specific experience in assessing risks for AI/ML solutions. The lead will also be responsible for preparing risk posture reports and driving innovative risk mitigation strategies, requiring strong communication and stakeholder management skills.

What you'd actually do

  1. Serve as the primary risk advisor for a portfolio of applications supporting Corporate functions.
  2. Provide subject matter expertise and technical guidance to key stakeholders, including Application Owners, CTOs, Chief Data Officers, and Business Control Managers.
  3. Lead the risk lifecycle: including the identification, assessment, reporting and registration of technology risks, ensuring comprehensive risk coverage across the portfolio.
  4. Develop and deliver remediation guidance to address identified risks and support risk mitigation strategies.
  5. Prepare and present monthly risk posture report to stakeholders, offering a clear and comprehensive view of the technology risk posture and its impact on the business.

Skills

Required

  • Formal Training or certification with 5–7 years of experience or equivalent expertise in technology, risk management, information security, or a related field
  • Strong understanding of technology risk management frameworks and industry standards
  • Expertise and depth knowledge in data, access and vulnerability management
  • Experience in performing technology risk and control assessment for AI/ML solutions
  • Proven ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders
  • Proven ability to develop and maintain strong client and stakeholder relationships
  • Excellent organizational and project management skills
  • High degree of initiative and self-direction

Nice to have

  • Industry-recognized certifications such as CRISC, CISM, CISSP, or CISA
  • Proficiency in third-party and vendor risk management
  • Familiarity with cloud security risk management (e.g., AWS, Azure, GCP)

What the JD emphasized

  • technology risk identification, assessment, and control evaluation
  • AI/ML solutions