JPMorganChase Logo

JPMorganChase

Tech Risk and Controls Lead

Posted An Hour Ago
Be an Early Applicant
Hybrid
London, Greater London, England
Entry level
Hybrid
London, Greater London, England
Entry level
Oversee concurrent PCI DSS assessments, validate scope and documentation, coordinate with QSAs and control owners, identify compliance gaps, guide remediation, and report risk findings. The role requires strong technology risk and controls expertise, project management, stakeholder communication, and knowledge of PCI, IT risk frameworks, regulatory requirements, and technology infrastructure. It also involves applying AI and automation to improve assessment efficiency and risk identification.
The summary above was generated by AI

As part of the Cybersecurity Technology Controls Global Regulatory Assessments team, the PCI Specialist is responsible for overseeing the end-to-end processes of a PCI Assessment driven by contractual and/or determined by business need in support of the JPMC Multi-Level PCI Compliance Validation efforts. The PCI Assessor/Advisor acts as the PCI Subject Matter Expert partnering with external Assessor partners and internal control and application owners to ensure compliance with PCI DSS SSC Frameworks.  This role requires expert project management capabilities, technical proficiency, and the ability to effectively facilitate assessments across diverse stakeholder groups including external assessors, technical teams, and non-technical business partners to deliver quality outcomes within established timeframes.


Job responsibilities

  • Oversee and manage multiple concurrent PCI assessments within firm Standards & Procedures according to established methodology and frameworks, adhering to time-sensitive deadlines through effective project management and stakeholder coordination
  • Capture, review and analysis of PCI required documentation, ensuring quality and suitability that meets PCI SSC requirements while exercising professional judgment on complex technical and compliance matters. 
  • Work with Business Leads & control owners and other members of the PCI team to determine and validate scope (people, processes and technologies etc.)
  • Partner strategically with external QSAs to facilitate assessment processes while ensuring alignment with business objectives and regulatory requirements
  • Proactively monitor Key Risk Parameters to identify non-compliance and assist in remediation including potential compensating controls to address security, risk and control gaps where appropriate.
  • Provide guidance on remediation activities as it pertains to the business area, ensuring appropriate resolution of issues, action plans, breaks and remedies and support the closure verification process
  • Develop and maintain strong business and technology relationships, becoming a trusted partner.
  • Communicate risk and other control findings with key stakeholders, develop recommendations and provide accurate metrics and management reports on a timely basis.
  •  Leverage emerging technologies, including AI and automation tools, to enhance assessment efficiency, documentation quality, and risk identification processes

 Required qualifications, capabilities, and skills

  • Candidates must possess demonstrable experience in technology risk and controls, risk-based consulting, risk assessments, audit and regulatory activities, with specific emphasis on PCI Data Security Standards
    Bachelor’s degree in computer science, Management Information Systems, Accounting Information Systems, or a related field.  Experience within financial services areas is preferred.  
  • Comprehensive knowledge and practical experience across all domains of Technology Infrastructure and PCI DSS requirements. Experience with implementation and oversight of technology risk and controls, coordination of activities for audits and assessing in an assigned environment.
  • Detail-oriented professional with strong conceptual, analytical, decision-making, planning, time management, and prioritization capabilities.
  • Exceptional oral and written communication skills with ability to articulate complex technical concepts to diverse audiences at all organizational levels and influence without direct authority.
  • Proven experience in planning, coordination, and implementation with ability to work across teams and functions to execute and deliver quality outcomes.
  • Demonstrated aptitude to upskill and learn new technologies based on business requirements. 

 

Preferred qualifications, capabilities, and skills

  • Proficiency in reviewing, understanding, and evaluating technical and software documentation and applying knowledge to assess control suitability.
  • Experience operating in environments that are heavily governed under compliance, regulatory, or risk reduction controls.
  • Advanced understanding of industry best practices, regulatory requirements, and company policies.
  • Knowledge of process-focused methodologies for IT related activities (Change Management, Incident Management, and SDLC).
  • Working knowledge of IT Risk & Process frameworks: COSO, COBIT, NIST CF, ITIL
  • Demonstrated interest and practical application of AI, automation, and emerging technologies to enhance compliance and assessment processes
  • Ability to exercise sound judgment in ambiguous situations, balancing regulatory requirements with business realities to develop pragmatic solutions

About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Similar Jobs

4 Days Ago
Hybrid
Senior level
Senior level
Financial Services
Owns technology risk and controls management across cybersecurity, data security, resilience, third-party risk, and change management. Translates regulations and standards into control expectations, assesses control effectiveness, leads remediation and audit readiness, and provides executive reporting on risk posture. Partners with technology, business, compliance, audit, and regulatory stakeholders while coaching junior staff and responsibly using authorized AI tools.
Top Skills: Chaps CrmCri ProfileEnterprise-Authorized Ai ToolsHkma CrafIso 27001Japan CssaSwift Csp
Senior level
Financial Services
Leads technology risk intelligence by analyzing cybersecurity and control data, identifying emerging firmwide risks, evaluating control effectiveness, and recommending remediation. Partners with technology, risk, control, and business stakeholders to produce executive reporting, support governance, and strengthen regulatory compliance. Uses authorized AI capabilities to synthesize evidence and streamline control testing while validating outputs for accuracy, security, auditability, and regulatory alignment.
Top Skills: Artificial IntelligenceCybersecurity
5 Days Ago
Hybrid
Senior level
Senior level
Financial Services
Leads technology risk and controls management by identifying, quantifying, and mitigating compliance and operational risks. Oversees control effectiveness, issue management, governance, reporting, and regulatory alignment. Partners with technology stakeholders, control teams, data officers, and regulators to improve risk posture and support executive decision-making. Uses enterprise-authorized AI to synthesize evidence and streamline control testing while validating outputs for security, auditability, and regulatory compliance.
Top Skills: Artificial IntelligenceCybersecurityData SecurityRisk Management Frameworks

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account