Tech Risk and Controls Lead

JPMorgan Chase

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
OH
Posted
78 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $190k
$141k most similar roles pay here $234k

This listing doesn't post a salary. Most similar roles pay $156,806–$223,700.

Based on 239 similar postings.

Employer

About JPMorgan Chase

JPMorgan Chase & Co. is a global financial services firm and one of the largest banks in the world, offering investment banking, commercial banking, asset management, and consumer financial services.

JPMorgan Chase currently has 1117 open roles on FindRole.

Listed pay typically runs $186,160–$215,000 across 7 roles with salary data.

Most-posted roles

View all roles at JPMorgan Chase

At a glance

TL;DR · Tech Risk and Controls Lead

The Tech Risk and Controls Lead joins the Cybersecurity Technology and Controls team to shape the firm's technology controls strategy in alignment with various standards and regulatory requirements. This role focuses on the Security Configuration Management domain, where you will manage control design, governance, standardization, and measurement across platform, network, endpoint, and application security configurations. You will develop technical control objectives, define performance metrics, and integrate telemetry into governance dashboards while managing hybrid ecosystems including cloud-native and on-premises environments. Key responsibilities include utilizing enterprise-authorized AI capabilities to accelerate risk analysis and reporting while ensuring auditability. Required skills include experience with GRC tools like Archer, infrastructure as code, and configuration drift monitoring tools such as Evolven, Puppet, Chef, and Wiz. Candidates should possess certifications like CISSP or AWS Security Specialist.

What you'll do

  • Lead the development of technical control objectives and standards for Security Configuration Management and other Cyber domains.
  • Define measurable performance metrics and integrate telemetry into governance dashboards for all control categories.
  • Utilize enterprise-authorized AI tools to accelerate cybersecurity architecture analysis, risk identification, and executive reporting.
  • Govern control implementation across hybrid cloud, data center, and endpoint environments to ensure a consistent security posture.
  • Integrate configuration drift monitoring tools with the GRC ecosystem to align with standardized objectives.
  • Partner with engineering teams to evaluate control sufficiency against threat models and regulatory requirements.
  • Drive AI-assisted security validation within SDLC routines to improve testing quality and auditability.
  • Provide strategic insights to leadership to drive continuous improvement in control effectiveness and efficiency.

What we're looking for

  • Formal training or certification with 5+ years of experience in cybersecurity controls architecture, security engineering, or operations leadership.
  • Professional certifications such as CISSP, CISM, GIAC, or cloud-specific certifications like AWS Solutions Architect or AWS Security Specialist.
  • Proficiency in designing or governing technical control frameworks across hybrid environments including AWS, Azure, and on-premises systems.
  • Experience designing metrics and governance frameworks for Security Configuration Management, SOC, network security, or endpoint control domains.
  • Working knowledge of GRC tools such as Archer, infrastructure as code, and control enforcement in dynamic environments.
  • Demonstrated experience using enterprise-authorized AI capabilities to support technology risk and controls workflows with proper data sensitivity handling.
  • Ability to review and validate AI-assisted risk summaries and recommendations to ensure alignment with security, auditability, and regulatory expectations.

More like this

Similar roles

Tech Risk and Controls Lead

JPMorgan Chase

Jersey City, NJ 5 days ago
AI Large Language Models Microsoft Copilot GitHub Copilot VS Code Cybersecurity SRE Disaster Recovery Risk Management Data Analytics Automation Control Governance Compliance root-cause analysis Observability Fault Tolerance
5+ yrs exp

Tech Risk and Controls

JPMorgan Chase

Plano, TX 23 days ago
AI/ML AWS Azure NIST CSF NIST SP 800-53 ISO/IEC 27001 PCI DSS SOX SOC1 GDPR Risk Management Data Security Root Cause Analysis Governance
6+ yrs exp

Vice President, Technology Risk & Controls

Blackrock

Wilmington, DE 58 days ago $117,500$173,500
NIST COBIT ITIL ISO 27001 CSA CCM Cybersecurity Risk Management Control Frameworks Program Management Asset Lifecycle Management Continuous Monitoring Key Risk Indicators Key Performance Indicators
Hybrid