LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Tech Risk and Controls Lead

ExperiencedNo visa sponsorship
J.P. Morgan logo

at J.P. Morgan

Bulge Bracket Investment Banks

Posted 6 days ago

No clicks

**Tech Risk and Controls Lead: Cybersecurity & Tech Controls (CTC) Team, Corporate Investment Banking** Lead our Tech Risk team, driving cybersecurity and GRC within the CIB Markets business. You'll operate at the intersection of cybersecurity, engineering, and governance, leveraging your deep technical background to identify, assess, and mitigate risks across diverse applications and environments. **Key Responsibilities:** - Hands-on risk identification through technical deep dives - Risk assessment, monitoring, and reporting compliance - Control design, implementation, and evaluation - Threat modeling and risk mitigation strategies -Clear communication of risks to senior stakeholders **Required Skills & Experience:** - Software/safety engineering background and modern programming languages (Python) - Proven technology risk/information security experience - Strong technical domain knowledge (SDLC, CI/CD, IAM, application resilience) - Analytical skills and Governance mindset - Stakeholder management with senior leaders and technologists

Compensation
Not specified

Currency: Not specified

City
London
Country
United Kingdom

Full Job Description

Location: LONDON, United Kingdom

As a Tech Risk & Controls Lead in the Cyber Security & Tech Controls (CTC) team, aligned to the Corporate Investment Banking division, you will be a key member of the Cyber Risk Management function supporting technology teams that build, operate, and deliver financial markets platforms and applications across the CIB Markets business. You will operate at the intersection of cybersecurity, engineering, and GRCdriving outcomes through hands-on technical analysis, practical control design, and evidence-based risk decisions.

 

You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firms standards, with a strong emphasis on practical implementation realities (architecture, infrastructure, SDLC, tooling, and operational resilience). Leveraging a deep technical and/or engineering background and broad risk management experience, you will identify, assess, and monitor risks and the implementation of effective controls across complex systems and environments. You will be expected to review architectures, interrogate technical designs, validate control effectiveness through artifacts/logs/configurations, and translate technical deficiencies into clear risk narratives for senior stakeholders.

 

Job responsibilities

  • Identify risks: Conduct hands-on technical deep dives across a diverse portfolio of applications to identify emerging and upstream technology and cyber risks.
  • Assess risk, monitoring & reporting: Assess, monitor, and report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
  • Implement controls: Design & Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
  • Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firms risk posture.
  • Analyze & mitigate: Analyze complex situations, advise on risk management strategies, and support the implementation of risk mitigation measures.
  • Document & communicate: Document and articulate risks appropriately; raise issues and define action plans in partnership with application teams.
  • Identify threats: Work closely with application teams to identify attack paths and threat vectors through threat modeling.

 

Required qualifications, capabilities, and skills

  • Software and/or security engineering background, including experience with modern programming languages (e.g., Python) and cloud (AWS).
  • Proven technology risk / information security experience, including risk identification, assessments, control testing, mitigation, and applying industry standards and best practices.
  • Strong technical domain knowledge across Software Development Life Cycle (SDLC) and CI/CD, application resilience and security, IAM, data protection, and vulnerability managementespecially for onprem and public-cloud environments in financial services.
  • Analytical and execution skills to assess complex issues, synthesize data from disparate sources into a cohesive risk view, and design/implement pragmatic risk mitigation strategies.
  • Strong stakeholder management: communicate clearly with senior leaders and build trusted, durable partnerships with LOB technologists to achieve shared outcomes.
  • Governance- and control-oriented mindset, with working knowledge of risk frameworks and relevant regulations; motivated by enabling the business through strengthened controls.

 

Preferred qualifications, capabilities, and skills

  • Industry-recognized risk certifications (e.g., CISM, CRISC, CISSP).
  • Process-improvement mindset with a track record of reducing toil and building efficient, scalable processes.
  • Experience with booking, pricing, and risk ecosystems (e.g., Athena, SecDb, Quartz, RICE, or equivalent) strongly preferred.
  • Familiarity with large-scale Python codebases.
  • Exposure to AI-driven risks and emerging threat patterns.

 

 

 

 

 

 

Join our dynamic team to navigate complex cyber and technology risk landscapes and fortify technology governancemaking a pivotal impact on our firms robust risk strategy. This role requires hands-on technical depth and the ability to engage credibly with engineers, architects, and platform owners across modern enterprise financial platforms & applications.

Tech Risk and Controls Lead

Compensation

Not specified

City: London

Country: United Kingdom

J.P. Morgan logo
Bulge Bracket Investment Banks

6 days ago

No clicks

at J.P. Morgan

ExperiencedNo visa sponsorship

**Tech Risk and Controls Lead: Cybersecurity & Tech Controls (CTC) Team, Corporate Investment Banking** Lead our Tech Risk team, driving cybersecurity and GRC within the CIB Markets business. You'll operate at the intersection of cybersecurity, engineering, and governance, leveraging your deep technical background to identify, assess, and mitigate risks across diverse applications and environments. **Key Responsibilities:** - Hands-on risk identification through technical deep dives - Risk assessment, monitoring, and reporting compliance - Control design, implementation, and evaluation - Threat modeling and risk mitigation strategies -Clear communication of risks to senior stakeholders **Required Skills & Experience:** - Software/safety engineering background and modern programming languages (Python) - Proven technology risk/information security experience - Strong technical domain knowledge (SDLC, CI/CD, IAM, application resilience) - Analytical skills and Governance mindset - Stakeholder management with senior leaders and technologists

Full Job Description

Location: LONDON, United Kingdom

As a Tech Risk & Controls Lead in the Cyber Security & Tech Controls (CTC) team, aligned to the Corporate Investment Banking division, you will be a key member of the Cyber Risk Management function supporting technology teams that build, operate, and deliver financial markets platforms and applications across the CIB Markets business. You will operate at the intersection of cybersecurity, engineering, and GRCdriving outcomes through hands-on technical analysis, practical control design, and evidence-based risk decisions.

 

You will contribute to the successful identification and management of technology-aligned aspects of Governance, Risk, and Compliance (GRC) in line with the firms standards, with a strong emphasis on practical implementation realities (architecture, infrastructure, SDLC, tooling, and operational resilience). Leveraging a deep technical and/or engineering background and broad risk management experience, you will identify, assess, and monitor risks and the implementation of effective controls across complex systems and environments. You will be expected to review architectures, interrogate technical designs, validate control effectiveness through artifacts/logs/configurations, and translate technical deficiencies into clear risk narratives for senior stakeholders.

 

Job responsibilities

  • Identify risks: Conduct hands-on technical deep dives across a diverse portfolio of applications to identify emerging and upstream technology and cyber risks.
  • Assess risk, monitoring & reporting: Assess, monitor, and report technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices.
  • Implement controls: Design & Support the implementation of effective controls in collaboration with cross-functional teams and stakeholders.
  • Evaluate controls: Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firms risk posture.
  • Analyze & mitigate: Analyze complex situations, advise on risk management strategies, and support the implementation of risk mitigation measures.
  • Document & communicate: Document and articulate risks appropriately; raise issues and define action plans in partnership with application teams.
  • Identify threats: Work closely with application teams to identify attack paths and threat vectors through threat modeling.

 

Required qualifications, capabilities, and skills

  • Software and/or security engineering background, including experience with modern programming languages (e.g., Python) and cloud (AWS).
  • Proven technology risk / information security experience, including risk identification, assessments, control testing, mitigation, and applying industry standards and best practices.
  • Strong technical domain knowledge across Software Development Life Cycle (SDLC) and CI/CD, application resilience and security, IAM, data protection, and vulnerability managementespecially for onprem and public-cloud environments in financial services.
  • Analytical and execution skills to assess complex issues, synthesize data from disparate sources into a cohesive risk view, and design/implement pragmatic risk mitigation strategies.
  • Strong stakeholder management: communicate clearly with senior leaders and build trusted, durable partnerships with LOB technologists to achieve shared outcomes.
  • Governance- and control-oriented mindset, with working knowledge of risk frameworks and relevant regulations; motivated by enabling the business through strengthened controls.

 

Preferred qualifications, capabilities, and skills

  • Industry-recognized risk certifications (e.g., CISM, CRISC, CISSP).
  • Process-improvement mindset with a track record of reducing toil and building efficient, scalable processes.
  • Experience with booking, pricing, and risk ecosystems (e.g., Athena, SecDb, Quartz, RICE, or equivalent) strongly preferred.
  • Familiarity with large-scale Python codebases.
  • Exposure to AI-driven risks and emerging threat patterns.

 

 

 

 

 

 

Join our dynamic team to navigate complex cyber and technology risk landscapes and fortify technology governancemaking a pivotal impact on our firms robust risk strategy. This role requires hands-on technical depth and the ability to engage credibly with engineers, architects, and platform owners across modern enterprise financial platforms & applications.