JPMorganChase Logo

JPMorganChase

Tech Risk and Controls Lead

Posted 3 Days Ago
Be an Early Applicant
Hybrid
London, Greater London, England, GBR
Senior level
Hybrid
London, Greater London, England, GBR
Senior level
Owns technology risk and controls management across cybersecurity, data security, resilience, third-party risk, and change management. Translates regulations and standards into control expectations, assesses control effectiveness, leads remediation and audit readiness, and provides executive reporting on risk posture. Partners with technology, business, compliance, audit, and regulatory stakeholders while coaching junior staff and responsibly using authorized AI tools.
The summary above was generated by AI
Tech Risk & Controls Lead (VP) — Cybersecurity & Technology Controls

Join our team to strengthen the firm’s technology control environment, reduce technology risk, and maintain strong regulatory and operational outcomes.

As a Tech Risk & Controls Lead (VP) in Cybersecurity & Technology Controls (or [Insert LOB/Sub-LOB]), you will be accountable for the day-to-day execution of the tech risk and controls agenda. You will translate regulatory obligations and firm standards into clear control expectations for technology and process owners. You will monitor control health, lead targeted assessments where required, drive issues to durable remediation, and produce concise, executive-ready reporting on control effectiveness and risk posture.

Key responsibilities
  • Own technology risk management for your scope, including identifying material risks, assessing impact, and communicating clear, actionable outcomes.
  • Set and enforce control expectations by translating regulatory obligations, industry standards, and firm requirements into practical guidance for technology-aligned process owners.
  • Monitor and challenge control effectiveness across key technology risk domains (e.g., cybersecurity, data security/governance, resilience, third-party, change management); identify gaps and recommend enhancements.
  • Lead control assessments when required, including regulatory and industry-driven assessments, and ensure strong evidence quality and audit readiness.
  • Drive issue and action-plan management end to end: root cause analysis, remediation plans, prioritization, escalation, closure validation, and sustained control improvement.
  • Run controls governance and reporting for senior stakeholders, including control performance, issue themes, and key measurements; translate technical findings into business impact and decisions.
  • Partner across stakeholders including LOB technologists, Product Owners, Business Control Managers, Location CISO, Regulatory Engagement Management, CCOR, Internal Audit, and compliance/risk teams.
  • Use enterprise-authorized AI capabilities to accelerate evidence synthesis and draft executive-ready reporting, with strong validation habits, auditability, and disciplined handling of sensitive data.
  • Coach and develop junior team members as applicable, setting a high bar for quality, timeliness, and regulatory awareness.
Required qualifications, capabilities, and skills
  • Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related discipline (or equivalent experience).
  • 5+ years of relevant experience (technology risk management, cybersecurity, technology audit, controls, or assessments), ideally in financial services.
  • Strong knowledge of risk and control frameworks and regulatory expectations; practical familiarity with relevant standards (e.g., ISO 27001, CRI Profile) and, where in scope, requirements such as Swift CSP, CHAPS CRM, HKMA CRAF, Japan CSSA.
  • Demonstrated ability to evaluate control design and operating effectiveness, identify gaps, and drive remediation to completion.
  • Strong judgment and stakeholder management skills, including the ability to influence senior technology and business leaders.
  • Demonstrated experience using enterprise-authorized AI tools in risk/controls workflows, including validating AI-assisted outputs and escalating when uncertain.
Preferred qualifications
  • Certifications such as CISM, CRISC, CISSP (or similar).
  • Experience in payments environments and familiarity with payments-related regulatory standards and cybersecurity control requirements.
 
About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

JPMorganChase London, England Office

25 Bank Street, Canary Wharf, London, United Kingdom, E14 5JP

Similar Jobs

Senior level
Financial Services
Leads technology risk intelligence by analyzing cybersecurity and control data, identifying emerging firmwide risks, evaluating control effectiveness, and recommending remediation. Partners with technology, risk, control, and business stakeholders to produce executive reporting, support governance, and strengthen regulatory compliance. Uses authorized AI capabilities to synthesize evidence and streamline control testing while validating outputs for accuracy, security, auditability, and regulatory alignment.
Top Skills: Artificial IntelligenceCybersecurity
4 Days Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Financial Services
Leads technology risk and controls management by identifying, quantifying, and mitigating compliance and operational risks. Oversees control effectiveness, issue management, governance, reporting, and regulatory alignment. Partners with technology stakeholders, control teams, data officers, and regulators to improve risk posture and support executive decision-making. Uses enterprise-authorized AI to synthesize evidence and streamline control testing while validating outputs for security, auditability, and regulatory compliance.
Top Skills: Artificial IntelligenceCybersecurityData SecurityRisk Management Frameworks
14 Days Ago
Hybrid
London, Greater London, England, GBR
Entry level
Entry level
Financial Services
Leads technology risk and controls governance for cloud foundational services. Produces executive-ready governance materials, manages meetings and remediation actions, monitors KRIs and KPIs, validates control effectiveness, synthesizes risks into senior-level insights, and improves reporting processes. Partners across functions to strengthen oversight, using authorized AI and automation with appropriate human validation, data sensitivity awareness, and auditability.
Top Skills: Enterprise Ai And AutomationMicrosoft PowerpointPublic Cloud

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account