Application Controls Risk Analyst

JPMorgan Chase & Co   •  

Wilmington, DE

Industry: Accounting, Finance & Insurance


5 - 7 years

Posted 34 days ago

This job is no longer available.

The Cybersecurity & Technology Controls group at JPMorgan Chase aligns the firm’s cybersecurity, access management, controls and resiliency teams. The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls. The group’s number one priority is to enable the business by keeping the firm safe, stable and resilient.

Working in Cybersecurity takes pure passion for technology, speed, a constant desire to learn, and above all, vigilance in keeping every last asset safe and sound. You’ll be on the front lines of innovation, working with a highly-motivated team laser-focused on analyzing, designing, developing and delivering solutions built to stop adversaries and strengthen our operations. Your research and work will ensure stability, capacity and resiliency of our products and emerging industry trends. Working in tandem with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop adversaries and strengthen our data.

The Application Controls Risk Analyst role includes the responsibility to support the application assessment function, oversee the break management process, ensuring technology controls are adhered, and communicate test results with appropriate stakeholders. The analyst will have an eye for detail, ability to see the big picture, and recognize control issues. This individual will be working directly with software engineering teams to provide oversight of the controls and to identify and track control deficiencies, provide subject matter expertise to Application Owners, and software engineers. The analyst will work with Technology Control Officers for issues remediation, ensure evidence of compliance is sufficient to substantiate the remediation of control deficiencies, and participate in key control projects for enhancement of the Application Risk Assessment program.

This role requires a wide variety of strengths and capabilities, including:

• BS/BA degree or equivalent experience

• Knowledge of Cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies

• Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals

• Proficiency in the use of skills tools, staying current with skills, participating in multiple forums

• Experience with Agile and can work with at least one of the common frameworks is highly desired.

• Ability to analyze vulnerabilities, threats, designs, procedures and architectural design, producing reports and sharing intelligence

• 5-10 years’ experience in Information Technology and working in IT Risk, Audit, Compliance or Governance.

• Application SOX or RCSA IT control experience is preferred. Background in in Auditing and an understanding of internal controls, particularly General Computer Controls (GCC).

• History of success working across Lines of Business, countries and regions, balancing the needs of multiple organizations. Experience with working with virtual teams / teams geographically distributed is required.

• CISA, CISSP, CISM, CRISC or related certifications preferred

Req #: 180120573