Application Security Specialist, Asia Asset Management Technology recruitment
J.P. Morgan Asset Management is the global brand for asset management activities of J.P. Morgan Chase Co. and a global leader in asset management services. With a global network of over 740 investment professionals located in 41 locations worldwide and assets under management of over US$1.3 trillion, we are one of the largest asset and wealth managers in the world.
In the Asia Pacific region, J.P. Morgan Asset Management has seven offices, including a joint venture in China, all delivering a wide range of investment products and services to retail and institutional clients.
The Role
This role's primary function is to assist the business managers to identify and manage any areas of risk within the IT environment for the Asia Pacific ex Japan region, with a focus on Internet and application security. Act as primary contact when IT risk-related consultancy is required, this role requires active interaction with the application and infrastructure technology teams as well as other business and control functions within the firm. The role will:
- Provide first line security consulting to the business in implementing technology control practices for business projects;
- Conduct security and control reviews for applications and underlying infrastructures, including technical architecture and security implementation such as authentication, authorization, session management, encryption, transaction and interface integrity, auditing and resiliency.
- Coordinate with the corporate IT risk management group to perform security tests including source code scanning and penetration test;
- Plan and coordinate the awareness training on technology control policies, practices and standards;
- Support the business in participating in the security processes (risk classification, application certification, Third Party Relationship (TPR) review, connectivity to the intra and internet);
- Work with the corporate IT risk management group to identify the appropriate corporate security solutions and arrange with the technology teams for deployment;
- Facilitate Control Self Assessment process and reporting;
- Facilitate internal, external or regulatory audits;
- Plan and coordinate reviews of TPRs. Verify that each TPR has a program in place to comply with the firm's policy and standards.
Skills
- Strong knowledge of Internet and application security. Hands-on application penetration testing, application development experience related to the security modules for enterprise applications and/or implementation experience of different security products is preferred;
- At least 5 years application security experience, ideally with banking exposure
- Knowledge in emerging technologies (e.g. mobile, cloud computing, use of social media, etc.), its risk involved and the security countermeasures is preferred.
- knowledge of the business' data flows, products and operations for investment management business is an advantage;
- Strong communication skills (written and verbal);
- A team player yet able to work independently when required;
- Ability to drill down into issues in a positive manner and make recommendations after evaluating the risks;
- CISSP, CISA, CEH and/or other IT auditing and information security qualifications is an advantage.
- Exemplary communication skills, high fluency in English, Cantonese and Mandarin