Information Security Assessor

Information Security Assessor

JP Morgan Chase & Co.
5-10 years
Not Specified

Job Description

Job Description :
Assist with the annual firm wide SOX / CCAP program, testing the evidence of the controls and identifying any
significant control deficiencies, working with the appropriate Assessment leads/ Technology Control Officer to identify
appropriate remediation to improve the controls as necessary.
. Assist in Application Risk Assessment (ARA) process that aims to gather risk specific information about an application.
. Assist with the firm wide PCI DSS compliance program and provide end-to-end control oversight, assurance of
compliance with requirements of the Data Security Standard, as well as risk and issue management and analysis.
. Support the Application Control Testing program including initial interviews regarding standard controls usage for
applications in scope assist with the identification and testing of shared controls. Perform testing of the evidence
submitted to validate it justifies control effectiveness.
. Work with technology teams to walk through, gather control design requirements facilitate discussions and bring to
closure control issues.
. Advise Lines of Business (LOBs), based on the testing their results to ensure they are in compliance with the Firm's
. Communicate issues and evaluate issues/findings and best practices with the rest of the team and manager.
. Perform QC reviews of control testing working papers.
. Work actively with the Assessment Leads/ Technology Controls Officers on the guidance and IT-related issues.
. Participate in additional key control projects related to enhancement of the Compliance and other assessment
. S upport internal education and best practices sharing with peers and colleagues, as well as information security
education & awareness, as needed.
Qualifications - Internal
. Bachelor's degree preferably in Computer Science or Information Technology.
. Minimum 5-10 years internal or external technology audit experience ('Big 4' experience preferred)
. Have a strong background in Auditing, understanding of internal controls, particularly General Computer Controls
. Have an ability to effectively develop and communicate recommendations based on SOX Corporate Office (SCO)
. Experience in Application assessment and control testing.
. Experience in PCI DCC compliance requirement and control testing.
. Be detail oriented with ability to evaluate processes, controls and issues to determine the risks.
. Have an ability to maintain high standards with a drive to achieve the right answer in difficult and/or ever changing
. Can work independently, collaborate within a team and is comfortable in a virtual environment.
. Proficient verbal and written communication skills, including the ability to effectively lead discussions and meetings
with internal management, external/ internal audit and peer groups.
. Strong interpersonal skills - verbal communications, written communications, and a good track record of collaboration.
. Proficient in MS Office - Microsoft Word, Excel, Access and PowerPoint.
. CISA, CISSP, CISM, CRISC certification will be an added advantage.
. Should have reasonable knowledge of APAC technology regulatory requirements

JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. In accordance with applicable law, we make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as any mental health or physical disability needs.

Similar Jobs

Career Advice to Find Better