Skip to main content
AfterDuty

Tech Risk and Controls Director - Audit

JPMorganChase · Glasgow, Scotland

Type
Full-time
Posted
9 days ago

Overview

Your incident command and multi-agency coordination experience is relevant, but this senior tech risk role demands deep cloud and audit expertise.

About this role

Job Description

Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.

As a Technology Risk and Controls Director within our Cloud Foundational Services Function, you will be passionate about operational risk management and control solutions for computing environments. You will partner with one or more disciplines, lines of business, regions and locations to respond to evolving business requirements and emerging threats. You will leverage your expert knowledge of today's ever-changing technology risk landscape and controls environment to advise and support IT operations across the firm. You will partner with process owners to respond to internal and external audit and regulatory requests for information, while ensuring senior stakeholders are kept updated on the risk posture for the organization. you will report directly to the Technology, Risk & Controls Portfolio Lead and will be responsible for a small team.

Lead the strategic development and implementation of technology risk management in a dynamic, evolving tech landscape. Cloud Technology Risk & Controls Lead (Executive Director) who helps teams run cloud services safely and reliably. You'll work with partners across the firm to spot new risks, strengthen day‑to‑day controls, and keep leaders informed on overall risk health. You'll also coordinate responses to audits and regulatory requests, and guide IT teams on security, resiliency, and high‑availability design. The role covers key areas like access management, incident response, vulnerability management, and data protection, with a strong understanding of public cloud environments..

Job Responsibilities

  • Develop and implement technology risk management strategies, policies, and processes to identify, assess, and mitigate risks, and drive strategic projects and initiatives to enhance the firm's technology risk management capabilities, in line with industry best practices and the firm's standards and regulatory requirements
  • Sets reuse-first expectations for enterprise-authorized AI adoption within the work environment across technology risk and controls operations to accelerate evidence synthesis, issue analysis, and executive reporting, with human-in-the-loop validation and appropriate handling of sensitive data.
  • Identify and escalate emerging and upstream technology risk through execution of the Firm's management framework tools, including risk event management, reporting, and action plan tracking, and provide expert counsel to stakeholders and constituents regarding their security obligations, facilitating acceptable outcomes
  • Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards
  • Manage reporting and governance of overall controls, policies, issue management, and measurements, etc., providing insight to senior leaders into effectiveness of controls and inform governance work
  • Establishes governance standards for AI-assisted workflows used in risk reporting and issue/action-plan management, ensuring traceability/auditability and alignment to security, resiliency, and regulatory expectations. Operational risk management subject matter expert.
  • Direct oversight and management of Audits for Cloud Foundational Services.
  • Supports and advises process owners in managing operational risk and provides transparency to stakeholders.
  • Ensures alignment with regulatory and firmwide control obligations and industry standards. Audit engagement and response management.

Required Qualifications, Capabilities, And Skills

  • Significant experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on managing risk identification, assessment, and mitigation
  • Demonstrated experience leading safe adoption of enterprise-authorized AI capabilities within the work environment within technology risk and controls workflows, including validation practices and awareness of data sensitivity.
  • Ability to define review/approval and escalation expectations for AI-assisted recommendations while maintaining security, auditability, and regulatory compliance outcomes.
  • Demonstrated expertise in risk management frameworks, industry standards, and regulatory requirements relevant to the financial industry
  • Proven ability to lead large teams, manage cross-functional projects, influence executive-level strategic decision-making, and effectively translate technology insights to business strategy in communications with senior executives
  • Advanced knowledge and experience leading data security, risk assessment & reporting, and control evaluation, design, and governance, with a track record of implementing effective risk mitigation strategies.
  • Bachelor's degree or equivalent experience.
  • Strong leadership skills with exceptional communication and presence.
  • Advanced knowledge of multiple IT control and project management practices and experience working across large environments.
  • Ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals.
  • Expertise in application and infrastructure high-availability and resiliency architectures with demonstrated experience in business.
  • Proficiency in information security domains, including policies and standards, risk and control assessments, access controls, regulatory compliance, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, and data protection.
  • Understanding of Public Cloud environments.

ABOUT US

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

About The Team

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.

About risk & resilience roles for ex-police

Risk management, business continuity and emergency-planning roles. Contingency planning, threat assessment and multi-agency coordination experience from policing is directly transferable.

See all risk & resilience jobs in Glasgow

Why this fits a police background

  • Incident command & response
  • Risk & threat assessment
  • Working to legislation & regulation
  • Security operations

What risk & resilience roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Resilience / BC analyst£35,000–£48,000
Business continuity / resilience manager£50,000–£70,000
Crisis management lead£65,000–£85,000
Head of resilience£80,000–£110,000+
Full risk & resilience salary guide →

More risk & resilience jobs for ex-police

  • Enterprise Risk Manager

    LiveMore Mortgages · Glasgow

    Full-time

    Your experience in contingency planning, threat assessment, and multi-agency coordination transfers directly to this enterprise risk management role.

    Posted 9 days ago

  • Risk Manager

    Altrad UK, Ireland & Nordics · Glasgow

    Full-time

    Your threat assessment and multi-agency coordination experience from policing directly supports this risk management role.

    Posted 9 days ago

  • Full-time

    Your incident command and multi-agency coordination experience directly applies to managing operational resilience and risk frameworks.

    Posted 10 days ago

  • Enterprise Risk Manager

    SSEN Transmission · Glasgow

    Contract

    Your incident command and threat assessment experience directly maps to managing enterprise risk in a regulated environment.

    Posted 16 days ago