JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $2.5 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small business, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world's most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com .
J.P. Morgan is a place for talented people from all backgrounds and perspectives because our clients come from all backgrounds and perspectives. We encourage a culture of inclusion, where everyone's opinion counts and all employees have the freedom to deliver their absolute best. This is why we work hard and invest in attracting and developing a diverse workforce. Learn more about our Business Resource Groups in how they help our employees build successful careers and reach their greatest potential.
Working in cybersecurity takes passion for technology, speed, a desire to learn, and vigilance in order to keep every asset safe. You'll be on the front lines of innovation, working with a highly motivated team focused on analyzing, designing, developing and delivering solutions built to stop adversaries and strengthen our operations. Your research and work will ensure stability, capacity and resiliency of our products. Working with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop crimes and strengthen our data.
Cybersecurity Intelligence Group (CIG) holds the global mandate for JPMorgan Chase's cyber intelligence collection, analysis, and dissemination of finished products to JPMorgan Chase's population of security operations teams, information technology teams, lines of business and overall executive decision makers.
CIG plays an integral role in the intelligence driven defense of JPMC. This team is responsible for external engagement with peer groups and information security circles regarding cyber threats, to address events such as intrusions, malware, DDoS, unauthorized access, insider attacks and loss of proprietary information. This includes developing a deep understanding of global threat actors.
CIG analysts provide intelligence support to Cybersecurity Operations investigations. Analysts need a sharp intellect, an eye for detail, a high analytical capability and a good technical/cyber underpinning. CIG Analysts are able to work autonomously, using sound judgment to decide which leads to pursue and prioritize investigations and workload accordingly. An interest in cyber, current affairs and technology is essential.
As a CIG Analyst, you will work closely with the senior analysts in the team and with partners across Cybersecurity Operations. You will build a thorough understanding of Global Cybersecurity and Technology Controls (CTC) at the firm in order to provide high impact intelligence to protect the firm. Prior experience in investment banking, asset management, consumer and/or commercial banking, will put you at a distinct advantage.
The responsibilities for this position include, but are not limited to, the following:
Conduct deep-dive intelligence analysis of suspicious activities and attempted attacks.
- Contribute to CIG Reports, providing detailed analysis on cyber events, including relevant political, economic and geopolitical variables. Provide a forward-looking view of the threat, predicting shifts in adversarial intent, goals and strategic objectives.
- Collaborate with peer cyber operations teams to understand events and support analysis of malicious cybersecurity incidents.
- Track potential threats associated with attempted intrusions, network & host-based attacks, and coordinate incident response efforts with cybersecurity teams.
- Maintain detailed threat actor profiles on adversaries of interest/relevance to the firm, covering tactics, techniques and procedures, intent, goals and strategic objectives.
- Maintain knowledge of the threat landscape by monitoring open and closed intelligence sources and contribute to quarterly threat landscape briefings.
- Contribute to regular written and verbal briefings and presentations for
- Global CTC partners and Lines of Businesses.
- Contribute from the cybersecurity perspective to discussions and decisions regarding JPMC global technology infrastructure and technology deployments.
The candidate will also need to learn to use of one or more High Security Access (HSA) systems. Users of these systems are subject to enhanced screening, which includes both criminal and credit background checks, and/or other enhanced screening at the time of accepting the position and on an annual basis thereafter. The enhanced screening will need to be successfully completed prior to commencing employment or assignment.
This role requires a wide variety of strengths and capabilities, including:
- Bachelor's degree or equivalent experience
- Foundational knowledge of cybersecurity organization practices, operations, risk management processes, principles, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies
- Ability to collaborate with high-performing Agile teams and individuals throughout the firm to accomplish goals
- Proficiency in the use of skills tools, staying current with skills, participating in multiple forums
- Ability to analyze vulnerabilities, threats, designs, procedures and architectural design, producing reports and sharing intelligence
- Foundational knowledge of: computer forensics; legal, government and jurisprudence as they relate to cybersecurity; operating systems; and methods for intelligence gathering and sharing
- Foundational knowledge of: cloud computing, computer network defense, external organizations and academic institutions dealing with cybersecurity issues, financial authorities and regulations, identity management, incident management, information assurance, information management, information systems and network security and infrastructure design
Essential Qualifications - Strong demonstrated knowledge of Cybersecurity and an understanding of the principles of intelligence analysis.
- Excellent understanding of networking concepts and Information Security, including emerging threats and attack methodologies.
- Excellent written and verbal communication skills.
Highly Desired
- Intelligence Community experience and/or experience at an international institution conducting cyber or security/intelligence related work.
- Coding (scripting) experience e.g. Perl, VB Script, Python etc.
Experience with Security Information and Event Management (SIEM) tools, Threat Intelligence platform/tools, etc.
- Working knowledge of global threats to international cyber security, and conversant in the tactics, techniques and procedures used by cyber adversaries.
- Professional working proficiency in one or more of the following languages: Russian, Mandarin, Spanish.
- Financial sector experience.