Technology Risk and Controls Lead - Portfolio of Applications

JPMorgan Chase JPMorgan Chase · Banking · Jersey City, NJ +1 · Corporate Sector

This role serves as a Technology Risk and Controls Lead for a portfolio of applications, providing expertise in risk identification, remediation guidance, and reporting. It requires experience in assessing technology risks for AI/ML solutions and managing risk frameworks within a corporate environment.

What you'd actually do

  1. Serve as the primary risk advisor for a portfolio of applications supporting Corporate functions.
  2. Provide subject matter expertise and technical guidance to key stakeholders, including Application Owners, CTOs, Chief Data Officers, and Business Control Managers.
  3. Lead the risk lifecycle: including the identification, assessment, reporting and registration of technology risks, ensuring comprehensive risk coverage across the portfolio.
  4. Develop and deliver remediation guidance to address identified risks and support risk mitigation strategies.
  5. Prepare and present monthly risk posture report to stakeholders, offering a clear and comprehensive view of the technology risk posture and its impact on the business.

Skills

Required

  • Formal training or certification with 5–7 years of experience or equivalent expertise in technology, risk management, information security, or a related field, with a focus on technology risk identification, assessment, and control evaluation.
  • Strong understanding of technology risk management frameworks and industry standards.
  • Expertise and in depth knowledge in data, access and vulnerability management.
  • Experience in performing technology risk and control assessment for AI/ML solutions.
  • Proven ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders.
  • Proven ability to develop and maintain strong client and stakeholder relationships.
  • Excellent organizational and project management skills, with the ability to manage multiple competing priorities and deliver under tight deadlines.
  • High degree of initiative and self-direction, with the ability to perform well under pressure; demonstrated intellectual curiosity and capacity to learn quickly.

Nice to have

  • Industry-recognized certifications such as CRISC, CISM, CISSP, or CISA, demonstrating formal expertise in technology risk and information security management.
  • Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle.
  • Familiarity with cloud security risk management (e.g., AWS, Azure, GCP), including shared responsibility models and cloud-native control frameworks.

What the JD emphasized

  • Experience in performing technology risk and control assessment for AI/ML solutions.