JPMorganChase Logo

JPMorganChase

Tech Risk and Controls Lead

Posted 2 Hours Ago
Be an Early Applicant
Hybrid
London, Greater London, England, GBR
Entry level
Hybrid
London, Greater London, England, GBR
Entry level
Leads technology and cyber risk management for financial markets platforms. Responsibilities include conducting technical risk deep dives, assessing and monitoring risks, designing and testing controls, reviewing architectures, validating evidence from logs and configurations, identifying attack paths through threat modeling, documenting deficiencies, and advising stakeholders on mitigation strategies and regulatory compliance.
The summary above was generated by AI

As a Tech Risk & Controls Lead in the Cyber Security & Tech Controls (CTC) team, aligned to the Corporate Investment Banking division, you will be a key member of the Cyber Risk Management function supporting technology teams that build, operate, and deliver financial markets platforms and applications across the CIB Markets business. You will operate at the intersection of cybersecurity, engineering, and GRC—driving outcomes through hands-on technical analysis, practical control design, and evidence-based risk decisions.


You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firm’s standards, with a strong emphasis on practical implementation realities (architecture, infrastructure, SDLC, tooling, and operational resilience). Leveraging a deep technical and/or engineering background and broad risk management experience, you will identify, assess, and monitor risks and the implementation of effective controls across complex systems and environments. You will be expected to review architectures, interrogate technical designs, validate control effectiveness through artifacts/logs/configurations, and translate technical deficiencies into clear risk narratives for senior stakeholders.

 

Job responsibilities

  • Identify risks: Conduct hands-on technical deep dives across a diverse portfolio of applications to identify emerging and upstream technology and cyber risks.
  • Assess risk, monitoring & reporting: Assess, monitor, and report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
  • Implement controls: Design & Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
  • Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm’s risk posture.
  • Analyze & mitigate: Analyze complex situations, advise on risk management strategies, and support the implementation of risk mitigation measures.
  • Document & communicate: Document and articulate risks appropriately; raise issues and define action plans in partnership with application teams.
  • Identify threats: Work closely with application teams to identify attack paths and threat vectors through threat modeling.

 

Required qualifications, capabilities, and skills

  • Software and/or security engineering background, including experience with modern programming languages (e.g., Python) and cloud (AWS).
  • Proven technology risk / information security experience, including risk identification, assessments, control testing, mitigation, and applying industry standards and best practices.
  • Strong technical domain knowledge across Software Development Life Cycle (SDLC) and CI/CD, application resilience and security, IAM, data protection, and vulnerability management—especially for on‑prem and public-cloud environments in financial services.
  • Analytical and execution skills to assess complex issues, synthesize data from disparate sources into a cohesive risk view, and design/implement pragmatic risk mitigation strategies.
  • Strong stakeholder management: communicate clearly with senior leaders and build trusted, durable partnerships with LOB technologists to achieve shared outcomes.
  • Governance- and control-oriented mindset, with working knowledge of risk frameworks and relevant regulations; motivated by enabling the business through strengthened controls.

 

Preferred qualifications, capabilities, and skills

  • Industry-recognized risk certifications (e.g., CISM, CRISC, CISSP).
  • Process-improvement mindset with a track record of reducing toil and building efficient, scalable processes.
  • Experience with booking, pricing, and risk ecosystems (e.g., Athena, SecDb, Quartz, RICE, or equivalent) strongly preferred.
  • Familiarity with large-scale Python codebases.
  • Exposure to AI-driven risks and emerging threat patterns.

 

 





About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

JPMorganChase London, England Office

25 Bank Street, Canary Wharf, London, United Kingdom, E14 5JP

Similar Jobs

Junior
Financial Services
Execute and manage compliance and operational risk testing: assess control design and effectiveness, identify gaps, drive remediation, propose testing improvements, and collaborate with cross-functional teams to communicate results and strengthen risk controls.
Mid level
Fintech • Information Technology • Financial Services
Supports financial and regulatory reporting for private credit funds, including coordinating annual audits across approximately 100 financial statements. Partners with fund accounting, finance, legal, compliance, tax, operations, fund administrators, custodians, and other service providers. Maintains reporting processes and controls, identifies automation and process improvement opportunities, and assists with strategic projects and business initiatives.
Top Skills: Excel
An Hour Ago
Remote or Hybrid
United Kingdom
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Manage end-to-end multi-country EMEA payroll processing, including gross-to-net calculations, reconciliations, statutory compliance, year-end activities, vendor coordination, HRIS integrations, employee queries, payroll accounting, payments, audits, and process improvement. The role partners with ADP and in-country providers, supports payroll projects and integrations, and maintains controls, documentation, and reporting accuracy across multiple jurisdictions.
Top Skills: Adp CelergoAdp StreamlineAdp VantageFreshserviceExcelOracle HcmServicenowWorkday

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account