US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Tech Risk and Controls

Your expertise in cybersecurity compliance can make a real impact - not just for a team, but for one of the world's most complex and consequential financial institutions.

At JPMorganChase, we invest in our people, our technology, and our controls to stay ahead of an ever-evolving threat landscape.

This is your opportunity to grow your career at the intersection of regulatory compliance, emerging technology, and enterprise-scale risk management.

As an Assessments & Exercises Senior Associate at JPMorganChase within the Cybersecurity Technology Controls Global Regulatory Assessments team, you will play a hands-on role in supporting end-to-end Payment Card Industry (PCI) compliance assessments that directly support the firm's multi-level PCI compliance validation efforts.

You will collaborate with external assessor partners and internal control and application owners to ensure adherence to PCI Data Security Standard (PCI DSS) frameworks, while developing your technical depth and professional judgment in a high-impact, fast-paced environment.

This role offers meaningful exposure to senior assessors, cross-functional stakeholders, and emerging automation tools - positioning you for continued growth within the firm's cybersecurity organization.

Job responsibilities


* Support and collaborate on multiple concurrent PCI assessments, adhering to established methodology, firm standards, and time-sensitive milestones through effective project management and stakeholder coordination


* Capture, review, and analyze PCI-required documentation, ensuring quality and suitability that meets PCI Security Standards Council (SSC) requirements while exercising professional judgment on complex technical and compliance matters


* Prepare for assessment walkthroughs, organize evidence, document discussions, and track follow-up actions in support of Vice Presidents and senior assessors throughout the assessment lifecycle; monitor key risk parameters to proactively identify non-compliance and assist in remediation efforts, including the evaluation of potential compensating controls to address security, risk, and control gaps


* Provide guidance on remediation activities for assigned business areas, supporting appropriate resolution of issues, action plans, and closure verification processes


* Research PCI requirements, emerging guidance, and industry developments; synthesize findings and share informed perspectives with the broader assessment team


* Maintain remediation tracking by managing action items, following up with stakeholders, validating submitted documentation, and escalating delays or concerns to the assessment lead; participate in team quality reviews, incorporate feedback, and progressively take ownership of defined assessment activities as knowledge and experience develop


* Leverage approved automation and large language model (LLM) tools to assist with evidence organization, requirement mapping, workpaper drafting, quality...




Share Job