Tech Risk and Controls Lead
Full-time
London, UK
Tech Risk & Controls Lead (VP) — Cybersecurity & Technology Controls
Join our team to strengthen the firm’s technology control environment, reduce technology risk, and maintain strong regulatory and operational outcomes.
As a Tech Risk & Controls Lead (VP) in Cybersecurity & Technology Controls (or [Insert LOB/Sub-LOB]), you will be accountable for the day-to-day execution of the tech risk and controls agenda. You will translate regulatory obligations and firm standards into clear control expectations for technology and process owners. You will monitor control health, lead targeted assessments where required, drive issues to durable remediation, and produce concise, executive-ready reporting on control effectiveness and risk posture.
Key responsibilities
- Own technology risk management for your scope, including identifying material risks, assessing impact, and communicating clear, actionable outcomes.
- Set and enforce control expectations by translating regulatory obligations, industry standards, and firm requirements into practical guidance for technology-aligned process owners.
- Monitor and challenge control effectiveness across key technology risk domains (e.g., cybersecurity, data security/governance, resilience, third-party, change management); identify gaps and recommend enhancements.
- Lead control assessments when required, including regulatory and industry-driven assessments, and ensure strong evidence quality and audit readiness.
- Drive issue and action-plan management end to end: root cause analysis, remediation plans, prioritization, escalation, closure validation, and sustained control improvement.
- Run controls governance and reporting for senior stakeholders, including control performance, issue themes, and key measurements; translate technical findings into business impact and decisions.
- Partner across stakeholders including LOB technologists, Product Owners, Business Control Managers, Location CISO, Regulatory Engagement Management, CCOR, Internal Audit, and compliance/risk teams.
- Use enterprise-authorized AI capabilities to accelerate evidence synthesis and draft executive-ready reporting, with strong validation habits, auditability, and disciplined handling of sensitive data.
- Coach and develop junior team members as applicable, setting a high bar for quality, timeliness, and regulatory awareness.
Required qualifications, capabilities, and skills
- Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related discipline (or equivalent experience).
- 5+ years of relevant experience (technology risk management, cybersecurity, technology audit, controls, or assessments), ideally in financial services.
- Strong knowledge of risk and control frameworks and regulatory expectations; practical familiarity with relevant standards (e.g., ISO 27001, CRI Profile) and, where in scope, requirements such as Swift CSP, CHAPS CRM, HKMA CRAF, Japan CSSA.
- Demonstrated ability to evaluate control design and operating effectiveness, identify gaps, and drive remediation to completion.
- Strong judgment and stakeholder management skills, including the ability to influence senior technology and business leaders.
- Demonstrated experience using enterprise-authorized AI tools in risk/controls workflows, including validating AI-assisted outputs and escalating when uncertain.
Preferred qualifications
- Certifications such as CISM, CRISC, CISSP (or similar).
- Experience in payments environments and familiarity with payments-related regulatory standards and cybersecurity control requirements.
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
Lead in managing tech risks and controls, ensuring compliance and operational integrity in a dynamic risk landscape.


