Plano, TX, USA
3 days ago
Risk Assurance Lead Investigator

As a Technology Risk Assurance Lead at JPMorgan Chase within the Cybersecurity & Technology Controls Organization, you'll be combining signals analysis and security expertise to discover and remediate hidden risk. The role operates and identifies risk trends across all lines of business, working with the entire breadth of technology and resources.

A successful candidate will have a proven track record in effectively analyzing information security data from multiple sources and creating actionable intelligence. They seek to understand beyond the surface of an issue, driving root cause analysis and issue remediation. They have strong empathy and question with focus and true curiosity.

A strong candidate demonstrates the ability to lead hard conversations with care and compassion. Previous experience in roles such as security architecture, security assurance, security operations, vulnerability management, threat modeling, assessments and penetration testing, or risk management will be helpful.
 

This position is anticipated to require the use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment. 

Job responsibilities:

Lead comprehensive risk investigations to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies  Advise stakeholders on risk management, controls development and adherence to mitigate risks  Proactively monitor key risk indicators, analyze control metrics, and offer insights on risk management effectiveness to senior management, driving continuous improvement initiatives  Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and internal policies 

Required qualifications, capabilities and skills:

Formal training or certification in Information Security, and/or 5+ years of project management experience with demonstrated experience working on information security projects.  Experience performing structured investigations into security related incidents.   Demonstrable knowledge across 3 or more of the following domains:   Network security architecture   Application Security / Threat Modeling  Development, Security, and Operations (DevSecOps) / Coding Security Practices  Governance, Risk and Compliance ( NIST, GDPR, etc)  Penetration Testing / Red Teaming   Security Operations / Security Monitoring   Cloud Security Architecture  Data Privacy  Business Continuity   Technology Education   Demonstrable ability to craft technical risk reports, adjusted for audience.   Ability to collaborate and communicate with a diverse range of stakeholders, of varying seniority, to effectively articulate risk and drive change.   Experience in Agile project management and with Agile tools/technology (i.e., Atlassian Jira, Atlassian Confluence).   Understanding of offensive and defensive security tools/technologies, such as penetration testing and red team testing platforms, firewalls, IDS/IPS, Web Proxies, and DLP.  

Preferred qualifications:

CISSP, CISM, CISA, Offensive Security (OSCP, OSEP, OSDA), SANS (GIAC, GPEN, GXPN, GWAPT), CRISC
Confirm your E-mail: Send Email