Job Description :
DescriptionJPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm. The firm is a leader in investment banking, financial services for consumers and small business, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the World's most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Information about JPMorgan Chase & Co. is available at http://www.jpmorganchase.com/.
Cybersecurity & Technology Controls (CTC) is part of the broader Global Technology organization that also includes Global Technology Infrastructure, the Chief Technology Office and the Strategy, Innovation & Partnerships groups. CTC's mission is to ensure the security and resiliency of the computing environment, protect confidential information, comply with regulatory requirements, and manage IT Risk and Controls for the firm, globally. We accomplish this through strong information security leadership and active collaboration with line of business information security managers to provide high quality security solutions and services that are focused on improving the overall technology risk posture.
SummaryAs an experienced professional in our cybersecurity organization, you won't just watch over our data - you will find innovative new ways to protect it today and into the future. To do that, you'll focus on analyzing, designing, developing and delivering solutions built to stop adversaries and strengthen our security postures. You'll use your leadership skills to secure complex environments, guide others, advise on best practices and support our business and technology groups. You will be taking a lead architect role in the Greater China and Southeast regions. You'll help secure the firm thru secure design principals, harden reference architectures, best practices, new policies and emerging trends to strengthen our strategic roadmap. You will interface with staff at all levels of the organization and the ability to remain technical while managing business expectations is highly important. By presenting your findings to senior leaders, you'll sharpen your communication and presentation skills. As part of our global team of technologists and innovators, your work will have a critical impact on our company, as well as our clients and our business partners around the world.
This will be a globally aligned role, focused on the Greater China and Southeast regions. Hence, awareness of the China regulations and knowledge of Mandarin are good to have, but not mandatory.
What You Will Be Doing:- This is an enterprise security architect role, with domain expertise on IAM solutions.
- Partnering with CTC architecture and product teams to design secure identity and access management solutions on hybrid technology platforms to meet the business, security and regulatory requirements.
- Provide Subject Matter Expertise for multiple lines of business, technology forums and panels, internal and external auditors, business partners, and senior management.
- Introduce improvements in implementation patterns and architectural design concepts.
- Be a strong technologist and a natural collaborator across the firm.
- Research, design and apply latest security techniques.
- Manage individual project priorities, deadlines and deliverables.
- Partnering with the Global TechnologyInfrastructure (GTI), other technical teams and global CTC organization toensure area owners are advise and oversee security design and implementation are applied in a timely manner.
- Providing input to strategic discussions to stakeholders inside the group and across the firm associated with improvement opportunities.
Qualifications- BA/BS degree or equivalnet education qualification
- Minimum 10+ years of experience in Information security in an operation, engineering, or architect role.
- Minimum 5+ years of experience in Identity and Access Management systems and processes in an enterprise environment.
- Experience with Cloud solution and integration of IAM tools.
- Advanced knowledge of Identity Governance and Administration, Identity Federation, OAuth, SAML, Single-Sign-On, Active Directory & ADFS, Privileged Access Management, RBAC etc.
- Advanced knowledge of Encryption algorithms, Public Key Infrastructures (PKIs), Certification Authorities (CAs), as well as the corresponding hardware and software adhering to industry standards.
- Background in infrastructure, system administration, & secure software development lifecycle desired.
- Experience in security products, risk management, information security standards, security architecture principles, threats and vulnerabilities management, including incident response methodologies.
- Well versed in application secure design principles, common attack patterns, OWASP top 10 risks/vulnerabilities/solutions and frameworks, etc.
- Understanding of information security and risk management challenges, issues mitigations and remediation in a multi-national enterprise environment.
- Demonstrated experience operating as a leader and leading others either directly or through mentorship.