JPMorgan Chase & Co.
Tech Risk and Controls Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
TECH RISK & CONTROLS LEAD (VP) — CYBERSECURITY & TECHNOLOGY CONTROLS
Join our team to strengthen the firm’s technology control environment, reduce technology risk, and maintain strong regulatory and operational outcomes.
As a Tech Risk & Controls Lead (VP) in Cybersecurity & Technology Controls (or [Insert LOB/Sub-LOB]), you will be accountable for the day-to-day execution of the tech risk and controls agenda. You will translate regulatory obligations and firm standards into clear control expectations for technology and process owners. You will monitor control health, lead targeted assessments where required, drive issues to durable remediation, and produce concise, executive-ready reporting on control effectiveness and risk posture.
KEY RESPONSIBILITIES
- Own technology risk management for your scope, including identifying material risks, assessing impact, and communicating clear, actionable outcomes.
- Set and enforce control expectations by translating regulatory obligations, industry standards, and firm requirements into practical guidance for technology-aligned process owners.
- Monitor and challenge control effectiveness across key technology risk domains (e.g., cybersecurity, data security/governance, resilience, third-party, change management); identify gaps and recommend enhancements.
- Lead control assessments when required, including regulatory and industry-driven assessments, and ensure strong evidence quality and audit readiness.
- Drive issue and action-plan management end to end: root cause analysis, remediation plans, prioritization, escalation, closure validation, and sustained control improvement.
- Run controls governance and reporting for senior stakeholders, including control performance, issue themes, and key measurements; translate technical findings into business impact and decisions.
- Partner across stakeholders including LOB technologists, Product Owners, Business Control Managers, Location CISO, Regulatory Engagement Management, CCOR, Internal Audit, and compliance/risk teams.
- Use enterprise-authorized AI capabilities to accelerate evidence synthesis and draft executive-ready reporting, with strong validation habits, auditability, and disciplined handling of sensitive data.
- Coach and develop junior team members as applicable, setting a high bar for quality, timeliness, and regulatory awareness.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
REQUIRED QUALIFICATIONS, CAPABILITIES, AND SKILLS
- Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related discipline (or equivalent experience).
- 5+ years of relevant experience (technology risk management, cybersecurity, technology audit, controls, or assessments), ideally in financial services.
- Strong knowledge of risk and control frameworks and regulatory expectations; practical familiarity with relevant standards (e.g., ISO 27001, CRI Profile) and, where in scope, requirements such as Swift CSP, CHAPS CRM, HKMA CRAF, Japan CSSA.
- Demonstrated ability to evaluate control design and operating effectiveness, identify gaps, and drive remediation to completion.
- Strong judgment and stakeholder management skills, including the ability to influence senior technology and business leaders.
- Demonstrated experience using enterprise-authorized AI tools in risk/controls workflows, including validating AI-assisted outputs and escalating when uncertain.
PREFERRED QUALIFICATIONS


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Certifications such as CISM, CRISC, CISSP (or similar).
- Experience in payments environments and familiarity with payments-related regulatory standards and cybersecurity control requirements.
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs [https://careers.jpmorgan.com/us/en/how-we-hire/faqs] for more information about requesting an accommodation.
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London