JPMorganChase Logo

JPMorganChase

Tech Risk and Controls

Posted 2 Days Ago
Be an Early Applicant
Hybrid
Brooklyn, NY
Mid level
Hybrid
Brooklyn, NY
Mid level
Supports end-to-end PCI DSS assessments, reviews evidence and technical documentation, coordinates stakeholders, tracks remediation, evaluates compensating controls, and researches regulatory requirements. The role prepares walkthroughs, maintains assessment workpapers, validates control compliance, and assists senior assessors. It also uses automation and LLM tools for evidence mapping, drafting, quality checks, and reporting while assessing risks and protecting sensitive information.
The summary above was generated by AI

Your expertise in cybersecurity compliance can make a real impact — not just for a team, but for one of the world's most complex and consequential financial institutions. At JPMorganChase, we invest in our people, our technology, and our controls to stay ahead of an ever-evolving threat landscape. This is your opportunity to grow your career at the intersection of regulatory compliance, emerging technology, and enterprise-scale risk management.

As an Assessments & Exercises Senior Associate at JPMorganChase within the Cybersecurity Technology Controls Global Regulatory Assessments team, you will play a hands-on role in supporting end-to-end Payment Card Industry (PCI) compliance assessments that directly support the firm's multi-level PCI compliance validation efforts. You will collaborate with external assessor partners and internal control and application owners to ensure adherence to PCI Data Security Standard (PCI DSS) frameworks, while developing your technical depth and professional judgment in a high-impact, fast-paced environment. This role offers meaningful exposure to senior assessors, cross-functional stakeholders, and emerging automation tools — positioning you for continued growth within the firm's cybersecurity organization.

Job responsibilities

  • Support and collaborate on multiple concurrent PCI assessments, adhering to established methodology, firm standards, and time-sensitive milestones through effective project management and stakeholder coordination
  • Capture, review, and analyze PCI-required documentation, ensuring quality and suitability that meets PCI Security Standards Council (SSC) requirements while exercising professional judgment on complex technical and compliance matters
  • Prepare for assessment walkthroughs, organize evidence, document discussions, and track follow-up actions in support of Vice Presidents and senior assessors throughout the assessment lifecycle; monitor key risk parameters to proactively identify non-compliance and assist in remediation efforts, including the evaluation of potential compensating controls to address security, risk, and control gaps
  • Provide guidance on remediation activities for assigned business areas, supporting appropriate resolution of issues, action plans, and closure verification processes
  • Research PCI requirements, emerging guidance, and industry developments; synthesize findings and share informed perspectives with the broader assessment team
  • Maintain remediation tracking by managing action items, following up with stakeholders, validating submitted documentation, and escalating delays or concerns to the assessment lead; participate in team quality reviews, incorporate feedback, and progressively take ownership of defined assessment activities as knowledge and experience develop
  • Leverage approved automation and large language model (LLM) tools to assist with evidence organization, requirement mapping, workpaper drafting, quality checks, and reporting — while validating outputs and safeguarding sensitive information
  • Support the testing of controlled agentic workflows for repetitive administrative and assessment-support tasks, contributing feedback on accuracy, usability, risks, and improvement opportunities

Required qualifications, capabilities, and skills

  • Formal training or certification on assessments & exercises concepts and 3+ years applied experience
  • 3+ years of professional experience in technology risk and controls, cybersecurity consulting, audit, or compliance assessments, with hands-on exposure to PCI DSS
  • Bachelor's degree in Computer Science, Management Information Systems, Accounting Information Systems, or a related field
  • Comprehensive knowledge and practical experience across technology infrastructure domains and PCI DSS requirements
  • Strong analytical, decision-making, time management, and prioritization capabilities with a detail-oriented approach to complex compliance matters
  • Effective oral and written communication skills, with the ability to articulate complex technical concepts to diverse audiences including non-technical business partners
  • Demonstrated ability to plan, coordinate, and execute across teams and functions to deliver quality outcomes within established timeframes
  • Proven aptitude for upskilling and adopting new technologies in response to evolving business and regulatory requirements

Preferred qualifications, capabilities, and skills

  • Experience working with a Qualified Security Assessor (QSA) firm or cybersecurity consulting organization
  • Proficiency in reviewing and evaluating technical and software documentation to assess control suitability and compliance alignment
  • Experience operating in heavily governed environments subject to compliance, regulatory, or risk-reduction controls, preferably within financial services
  • Working knowledge of IT risk and process frameworks such as COSO, COBIT, NIST Cybersecurity Framework, or ITIL
  • Familiarity with process-focused methodologies for IT activities including Change Management, Incident Management, and the Software Development Lifecycle (SDLC)
  • Demonstrated interest and practical application of artificial intelligence, automation, or emerging technologies to enhance compliance and assessment processes

#CTC

About Us
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Similar Jobs

23 Days Ago
Hybrid
Senior level
Senior level
Financial Services
Leads technology risk and controls activities, including risk identification, assessment, reporting, governance, control testing, issue management, and regulatory compliance. Partners with technology and business stakeholders to evaluate control effectiveness, address gaps, and strengthen the organization’s risk posture. Uses and validates enterprise-authorized AI capabilities to synthesize evidence and support audit-ready reporting while maintaining data security and regulatory standards. Provides technical guidance and influences executive decision-making.
Top Skills: Artificial Intelligence (Ai)Data Security
An Hour Ago
Hybrid
124K-335K Annually
Senior level
124K-335K Annually
Senior level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Lead federal mergers and acquisitions tax engagements involving due diligence, transaction structuring, restructuring, insolvency, financial modeling, tax risk analysis, and regulatory matters. Manage major projects, improve processes, advise senior clients, develop business strategies, and mentor multidisciplinary teams. Build client relationships, apply U.S. federal income tax law, use complex data to provide insights, and represent the firm externally.
An Hour Ago
Hybrid
2 Locations
155K-410K Annually
Expert/Leader
155K-410K Annually
Expert/Leader
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Leads consulting engagements focused on pricing, promotions, revenue management, and profitability optimization. Develops pricing strategies, analyzes market trends and customer profitability, oversees multiple projects, manages executive client relationships, drives business development, and mentors consulting teams. Uses pricing tools to evaluate performance, aligns promotional strategies with business objectives, and guides technological and business transformation initiatives.

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account