Vulnerability Management Response Analyst at JPMorgan Chase Bank, N.A. in Wilmington, Delaware

Posted in General Business 5 days ago.

Type: Full-Time

Job Description:

Cybersecurity Vulnerability Management Response Team is responsible for the initial vulnerability assessment, impact analysis firm wide, risk assessment for the firm, coordination & communication of critical vulnerabilities identified as impacting JPMorgan Chase applications and/or infrastructure components. This function is performed globally and at the scale of which JPMC operates by coordinating a response that could be firm wide or application specific. The response team's actions are driven based on the criticality of the vulnerability by balancing risk and the ability for our Line of Business partner to service their clients and customers globally.

Working in Cybersecurity takes a passion for balancing technology with determining the inherent risk of a vulnerability by balancing preventative controls against known exploits, and above all, vigilance in keeping JPMC technology secure for our customers & clients. You'll be on the front lines of managing vulnerabilities by making critical decisions on the inherent risk to the infrastructure or the application itself and thus the risk to the firm clients & customers. You will be working with a highly-motivated team laser-focused on analyzing, scoping, developing and delivering solutions built to stop adversaries and strengthen our security posture. Your research and work will ensure stability and resiliency of our current technology products, emerging technology and our vast application estate. Working in tandem with various internal team both in Cyber and various Line of Business partners, as well as technologists and innovators across our global network, by leading the positive actions that will stop adversaries and strengthen customer's confidence.

High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters. Users in these roles are subject to enhanced pre-hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.


As a Vulnerability Management Response Analyst, you will work directly with all Line of Business App Teams, Subject matter experts, Production Management Teams, Product Owners, Senior Technology Management, and Risk and Control functions on:

• Defining each new vulnerability impact to the firm

• Work to define a CVSS score and initial risk to the firm

• Identifying the list of assets and/or application(s) at risk

• Research and document the vulnerability

• Provide a detailed write up on the risk and exposure

• Define the remediation activity if known

• Define the final firm wide vulnerability rating


  • Minimum of 2-4 years' experience in a Cyber Security Vulnerability management role with knowledge of operation practices supporting Vulnerability management.
  • Minimum of 3 years' experience of risk management processes with the ability to demonstrable comprehension of end to end Vulnerability Management workflow to include industry standards such as CVE, CPE, CVSS
  • Minimum of 5 years' experience in command & control practices like Incident Management and/or Cyber incident response methodologies
  • Familiarity with Cyber scanning tools including Qualys, BlackDuck, Snyk, Tenable and Tanium.
  • Knowledge or experience with Splunk, Phantom, WireShark, Excel, and SQL.

• Python development skillset with the ability to quickly understand a problem or use case and efficiently develop solutions taking a structured approach including Python coding, debugging, data structures, libraries, frameworks, and release packaging.

• Experience of databases, ORM, SQL, APIs and Splunk will be highly beneficial.

  • Experience with Agile and experience working to manage remediation actions via an active backlog & Jira.
  • Sound awareness of leading vendor products/applications from Oracle (Java), Adobe and Microsoft to include product lifecycle & release schedules
  • Strong deductive reasoning, multi-tasking, critical thinking, problem solving, and prioritization skills
  • Previous 24 x 7 operations experience
  • BS/BA degree or equivalent experience

Your expertise in Cyber, combined with your desire to provide innovative security services, will be an asset to our Cybersecurity team. Help deliver high-quality secure solutions across all our lines of business around the world by creating, designing, implementing, and maintaining next-level technology. The work you'll do is vital, as it will protect over $18 trillion of assets under custody and $393 billion in deposits every day.JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. In accordance with applicable law, we make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as any mental health or physical disability needs.

Equal Opportunity Employer/Disability/Veterans