Jobs and Careers
JP

Assessments & Exercises Vice President - Red Team Lead

JPMorgan Chase & Co.
Washington, United Statesfull_timeVerifiedPosted 9 Oct 2024

About the role

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

As an Assessments & Exercises Vice President in the Cybersecurity and Tech Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Design and deploy risk-driven tests and simulations (or manage a highly-skilled team that does) and inform analysis to clearly outline root-causes. In this role, you will evaluate preventative controls, incident response processes, and detection capabilities, and advise cross-functional teams on security strategy and risk management.

JPMC’s Assurance Operations organization is looking to expand its Cybersecurity Red Team with a North America Lead position. The North America Lead is tasked with managing and providing critical support to the firm’s internal team of highly skilled and qualified Red Team members who conduct advanced adversary emulation operations to replicate relevant cyber security threats targeting the firm. Your track record in leading advanced network exploitation operations, to include Red Team operations will lead you to excel. You will utilize your experience in Information Securitypeople managementwritten and oral communication, and project management. This position is anticipated to require the use of one or more High Risk Role (HRR) systems, which mandates successful completion of enhanced screening, including criminal and credit background checks, before starting employment and annually thereafter.

Job responsibilities 

  • Manage and develop an effective team of technical Red Team operators, providing leadership, coaching, guidance, and performance evaluations. Ensure team members are effectively trained and equipped to operate safely in highly-sensitive environments. 
  • Develop and implement comprehensive strategies to enhance the effectiveness of the Red Team program in alignment with team or organizational goals.
  • Oversee a diverse portfolio of adversary simulation engagements, ensuring each project is meticulously planned and executed. Coordinate with stakeholders to define objectives, scope, and deliverables for each engagement. Manage engagements to test and improve the organization's security defenses, and provide detailed reports and recommendations based on findings to enhance overall cybersecurity resilience
  • Design and execute testing and simulations – such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
  • Collaborate closely with cross-functional teams to develop comprehensive assessment reports – including detailed findings, risk assessments, and remediation recommendations – making data-driven decisions that encourage continuous improvement
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics

Required qualifications, capabilities, and skills

  • 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
  • Proven ability with at least 2+ years of experience managing teams of technical staff, or ability to create long term strategic plans, and experience conducting process improvement based on operational lessons learned and threat intelligence inputs. Should have a strong understanding of networking fundamentals (all OSI layers, protocols), Windows/Linux/Unix/Mac operating systems, system and software vulnerabilities and exploitation techniques, and web application vulnerabilities and exploitation techniques
  • Technical knowledge or experience developing in house scripting, using interpreted languages such as Ruby, Python, or Perl, compiled languages such as C, C++, C#, or Java, and security tools or technology such as Firewalls, IDS/IPS, EDR, Web Proxies, DLP and the ability to articulate and visually present complex penetration testing and Red Team results 
  • Excellent command of Cy

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

JPMorgan Chase & Co.

View company profile →