Vulnerability Management - Cybersecurity

Jpmorgan Chase & Co. Jersey City , NJ 07097

Posted 4 weeks ago

Vulnerability Management - Cybersecurity

Req #: 190008198

Location: Jersey City, NJ, US

Job Category: Technology

Job Description:

Cybersecurity Vulnerability Management Response Team is responsible for the initial vulnerability assessment, impact analysis firm wide, risk assessment for the firm, coordination & communication of critical vulnerabilities identified as impacting JPMorgan Chase applications and/or infrastructure components. This function is performed globally and at the scale of which JPMC operates by coordinating a response that could be firm wide or application specific. The response team's actions are driven based on the criticality of the vulnerability by balancing risk and the ability for our Line of Business partner to service their clients and customers globally.

Working in Cybersecurity takes a passion for balancing technology with determining the inherent risk of a vulnerability by balancing preventative controls against known exploits, and above all, vigilance in keeping JPMC technology secure for our customers & clients. You'll be on the front lines of managing vulnerabilities by making critical decisions on the inherent risk to the infrastructure or the application itself and thus the risk to the firm clients & customers. You will be working with a highly-motivated team laser-focused on analyzing, scoping, developing and delivering solutions built to stop adversaries and strengthen our security posture. Your research and work will ensure stability and resiliency of our current technology products, emerging technology and our vast application estate. Working in tandem with various internal team both in Cyber and various Line of Business partners, as well as technologists and innovators across our global network, by leading the positive actions that will stop adversaries and strengthen customer's confidence.


As a Vulnerability Management Response Analyst, you will work directly with all Line of Business App Teams, Subject matter experts, Production Management Teams, Product Owners, Senior Technology Management, and Risk and Control functions on:

  • Defining each new vulnerability

  • Work to define a CVSS score and initial risk to the firm

  • Identifying the list of assets and/or application(s) at risk

  • Document the vulnerability

  • Provide a detailed write up on the risk and exposure

  • Define the remediation activity if known

  • Define the final firm wide vulnerability rating

  • Depending on the final rating, actively manage the work effort to implement the remediation


  • Minimum of 5 years' experience in a Cyber Vulnerability management role with knowledge of operation practices supporting Vulnerability management.

  • Minimum of 3 years' experience of risk management processes with the ability to demonstrable comprehension of end to end Vulnerability Management workflow to include industry standards such as CVE, CPE, CVSS

  • Minimum of 3 years' experience in command & control practices like Incident Management and/or Cyber incident response methodologies

  • Experience with Cyber scanning tools including Qualys, BlackDuck, and Tanium.

  • Experience with Splunk, WireShark, Excel, and SQL.

  • Experience with Agile and experience working to manage remediation actions via an active backlog & Jira.

  • Sound awareness of leading vendor products/applications from Oracle [Java], Adobe and Microsoft to include product lifecycle & release schedules

  • Subject matter expert (SME) in one or multiple areas such as Windows, UNIX, mid-range, mainframe, database, Cloud, Big Data

  • Strong deductive reasoning, multi-tasking, critical thinking, problem solving, and prioritization skills

  • Previous 24 x 7 operations experience

  • BS/BA degree or equivalent experience

Your expertise in Cyber, combined with your desire to provide innovative security services, will be an asset to our Cybersecurity team. Help deliver high-quality secure solutions across all our lines of business around the world by creating, designing, implementing, and maintaining next-level technology. The work you'll do is vital, as it will protect over $18 trillion of assets under custody and $393 billion in deposits every day.

When you work at JPMorgan Chase & Co., you're not just working at a global financial institution. You're an integral part of one of the world's biggest tech companies. In 14 technology hubs worldwide, our team of 40,000+ technologists design, build and deploy everything from enterprise technology initiatives to big data and mobile solutions, as well as innovations in electronic payments, cybersecurity, machine learning, and cloud development. Our $9.5B+ annual investment in technology enables us to hire people to create innovative solutions that will not only transform the financial services industry, but also change the world.

At JPMorgan Chase & Co. we value the unique skills of every employee, and we're building a technology organization that thrives on diversity. We encourage professional growth and career development, and offer competitive benefits and compensation. If you're looking to build your career as part of a global technology team tackling big challenges that impact the lives of people and companies all around the world, we want to meet you.

@2017 JPMorgan Chase & Co. JPMorgan Chase is an equal opportunity and affirmative action employer Disability/Veteran

icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Director Of Cybersecurity Controls


Posted 2 weeks ago

VIEW JOBS 3/5/2019 12:00:00 AM 2019-06-03T00:00 The Technology Chief Controls Office (CCO Tech) is responsible for advice and support to Global Technology on all areas of technology risk. As well as supporting the design and implementation of all global and regional controls, CCO Tech leads controls-related engagements with internal audit and external regulators on a global and regional basis. The group consists of Global Business and Function aligned teams who act as the trusted partners to technology, and central functions who oversee the governance of control, provide subject matter expertise covering our control domains, and identify emerging threats and risks. The role of Director of Cybersecurity Controls for CCO Tech is part of the functionally aligned Cybersecurity team. The role reports into the Head of Technology Controls for Cybersecurity and will act as a subject matter expert for cybersecurity controls. This senior role will be a key change-agent and enabler as we enhance the support we provide to Cybersecurity in the design, implementation and ongoing assessment of cybersecurity controls. Key deliverables and responsibilities associated to this role: * Oversee the end to end health of the cybersecurity control environment * Manage audit (internal and external) and risk related regulatory engagement as the technology controls SME * Collaborate with control owners on initiatives to drive improvements to the Technology control environment including the effective design and operation of controls leading to their overall maturity. * Perform assessments of controls to determine level of effectiveness * Partner with the Cybersecurity management team to create effective design, analysis and remediation of control deficiencies * Provide risk and controls consultancy, advice and guidance to the Cybersecurity teams. * Participate at relevant governance forums, Audit and regulatory reviews etc. * Validate control measures include RCA, KRIs, KCIs, control operation, test approaches, reviews, audits, judgment based attestations. * Experience and familiarity with frameworks ISO27001, NIST, COBIT, Security Policies, Policy Implementation, Data Protection) * Information Security or IT Risk certifications (CISSP, CISM, CRISC etc.) * Strong interpersonal skills and the ability to confidently liaise and influence all levels of the business both in the UK and internationally. * In-depth knowledge and experience of cybersecurity related controls in one or more domains covering data security, network security, vulnerability management, incident response, security operations, event monitoring, intelligence, infrastructure security, secure application development, testing etc. * At least 10-15 years relevant experience preferably within a cybersecurity or risk management related role. * Degree in information security, computer science or computer engineering qualifications desirable EEO/AA/Minorities/Women/Disability/Veterans Hsbc Jersey City NJ

Vulnerability Management - Cybersecurity

Jpmorgan Chase & Co.