Tech Risk and Controls Associate - Cybersecurity - Data Loss Prevention
About this role
Job Description
Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.
As a Tech Risk & Controls DLP Content Developer in Cybersecurity and Technology Controls (CTC) you will contribute to the successful management of technology-aligned aspects of Governance, Risk, and Compliance in line with the firm's standards. Leverage your broad knowledge in risk management principles and practices to assess and monitor risks and implement effective controls. You’ll work with a highly motivated team focused on delivering solutions built to stop adversaries and strengthen our operations. Your work will contribute to identify and build indicators of insider threats and prevent sensitive data loss through world class tools and technologies.
Our Data Loss Prevention (DLP) team performs many functions in support of data security at the firm. The team develops world class solutions for detection and prevention of sensitive information leaving the firm based on in-depth analysis. In addition, the team develops new data identifiers, builds and maintains tools and capabilities for data loss triage prioritization, analyzes trends and patterns of DLP activity and works with stakeholders to reduce the risk of data loss across all lines of business.
Job responsibilities
- Support implementation of effective controls in collaboration with cross-functional teams and stakeholders
- Evaluate the effectiveness of existing controls, identify gaps, and recommend improvements to mitigate risks and enhance the firm's risk posture
- Analyze complex situations, provide advice on risk management strategies, and support the implementation of risk mitigation measures
- Design, configure and implement DLP policies on Microsoft Information Protection (Microsoft Purview) suite and Symantec DLP
- Automate deployment and run maintenance smoothly using scripting skills and analytical capabilities
- Provide expertise and guidance in management, configuration and optimizations of Microsoft O365 security solutions
- Contribute to development of new data identifiers, data governance policies, standards and procedures ensuring compliance and data integrity
- Collaborate with stakeholders, business and technology groups to provide guidance, advice on best practices, define data management requirements, establish effective controls, practices and procedures
- Use knowledge and expertise to respond to incidents, perform risk reviews, vulnerability assessments and identify new and emerging threats
- Assist in technology and process improvement efforts, with a goal to refine detection and prioritization
- Support the AWM and Global Technology activity with IT and Cyber risk identification and control of infrastructure and applications
- Support requests from control functions such as internal and external IT audit in line with regulatory expectations as well as company-wide standards.
Required qualifications, capabilities, and skills
- 3+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessment, and mitigation
- Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards
- Demonstrated ability to analyze complex issues, develop and implement risk mitigation strategies, and communicate effectively with senior stakeholders
- Proficient knowledge of risk management frameworks, regulations, and industry best practices
- Scripting skills and analytical capabilities
- Expertise in management, configuration, and optimizations of Microsoft O365 security solutions
- Knowledge and expertise to respond to incidents, perform risk reviews, vulnerability assessments, and identify new and emerging threats
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or other industry-recognized risk certifications
- Expertise to deliver cost-effective solutions and leverage communication and presentation skills to engage senior leaders on important issues and updates
About Us
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.