Tech Risk and Controls Lead - Cloud Foundational Services - Governance
Full-time
London, UK
Posted on Sep 8, 2026
- Own and deliver executive-ready materials (PowerPoint and written narratives) for control governance forums, ensuring they present a clear, accurate, and independent view of the product line's technology risk posture, control health, and open exposures.
- Lead the end-to-end meeting production process by setting timelines, requesting inputs, tracking actions, managing deadlines, maintaining version control, and ensuring materials are complete, accurate, and submitted on time while escalating delivery risks appropriately.
- Own issue and action-plan management as a discipline — driving prioritization, action-plan definition, progress tracking, and validation of remediation outcomes, and challenging owners where remediation is insufficient or overdue.
- Define, monitor, and report on control metrics, KRIs, and KPIs that measure control effectiveness, surfacing trends, thresholds breached, and the "so what" for senior management.
- Synthesize complex inputs into decision-oriented insights and storylines, articulating changes, impacts, key risks and controls, dependencies, decisions required, and recommended actions.
- Provide high-level review and quality assurance on metrics commentary, issue trackers, and risk and control updates, applying professional judgment to test whether they hold up to scrutiny.
- Maintain and enhance recurring reporting and meeting artifacts — templates, trackers, action logs, minutes, and follow-up items — while identifying opportunities for process improvement and standardization.
- Partner across lines of business and functions, and lead through influence, to strengthen governance routines and deliver effective oversight across the product line.
- Leverage enterprise-authorized AI and automation capabilities to accelerate the drafting, synthesis, and quality review of governance content — reducing manual effort while applying human validation and handling data in line with sensitivity and security requirements.
Required Qualifications, Capabilities, and Skills
- Experience in technology risk, controls, governance, or a related field, including supporting senior leadership and control governance forums.
- Working knowledge of technology risk and control concepts — control design and operating effectiveness, issue and action-plan management, and remediation validation — with the judgment to test whether risk and control representations hold up to scrutiny.
- Familiarity with cloud risk and control concepts and the risks specific to a public cloud environment.
- Experience defining, monitoring, and reporting control metrics, KRIs, and KPIs, and translating them into meaningful insight for senior audiences.
- Advanced PowerPoint skills with strong executive storytelling capabilities and the ability to translate complex technical topics into clear, senior-level narratives.
- Strong report creation and presentation skills, capable of speaking credibly to all levels of the organization.
- Demonstrated ability to lead cross-functional meetings and engage diverse line-of-business, control, and technology stakeholders.
- Exceptional organizational and execution skills, with the ability to manage multiple deliverables, tight deadlines, and diverse stakeholder groups.
- Strong analytical and quality assurance skills, including experience working with metrics, issue tracking, and reporting tools.
- Strong written and verbal communication skills, with the ability to build relationships, drive input collection, and navigate competing viewpoints.
- Experience using enterprise-authorized AI capabilities to support risk, controls, or reporting workflows — validating outputs before use, escalating when uncertain, and applying awareness of data sensitivity and auditability.
- Demonstrated adaptability, ownership, and a continuous improvement mindset while consistently delivering high-quality work.
- High attention to detail, strong professional judgment, and the ability to handle sensitive information with discretion.
- Strong control and governance mindset.
J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
Operating within the Cloud Foundational Services (CFS) product line, a part of Infra Platforms(IP), you will provide a pivotal role in ensuring our public cloud capabilities are operating safely and securely for. You will manage the overall book of work for ensuring the compliance of our public cloud platform, facing off to regulators, auditors, and our Cybersecurity & Technology Control function. You will partner closely with both the product management and engineering functions to ensure the work is appropriately prioritized to ensure the technology landscape is operating within the risk appetite, and provide transparent reporting to senior management on the overall risk position of the product line. Responsibilities: As a Vice President in the CFS TRC Governance team, you will provide senior-level execution leadership and day-to-day partnership for the Chief Control Manager, owning the preparation of executive-ready materials and insights for critical control forums. You will play




