← JP Morgan Chase Interview Insights

JP Morgan Chase·Product Manager·Onsite - Product Sense / Strategy·Senior

Senior
Jun 2026

Summary

PM interview at JP Morgan Chase where they threw a pretty meaty strategy question at me around building out a DevSecOps platform. One question, but it had a lot of layers to unpack.

Questions Asked (1)

Q1

You're a PM owning a new internal DevSecOps platform at JP Morgan Chase. Define the OKRs, strategy, and goals for it.

Product StrategyRoadmap PrioritizationCross-functional Alignment
Author's notes

I started with goals because jumping straight to OKRs without grounding them in something felt backwards.

Create a free account to read the full note

AI HintsAI Generated

Suggested Approach

Start by clarifying the platform's mission and primary users (developers, security, operations) within JPMC's regulated environment. Then define OKRs that balance developer productivity, security compliance, and operational efficiency, and outline a phased strategy from foundational capabilities to advanced automation. Finally, tie goals to measurable business outcomes like reduced time-to-market and risk reduction.

Pro tip: Emphasize that in a regulated financial institution, security and compliance are non-negotiable, so frame OKRs to show how DevSecOps enables faster delivery without compromising risk controls. Use metrics like 'mean time to remediate vulnerabilities' and 'percentage of pipelines with automated security gates' to demonstrate tangible value.

1. Clarify Mission and Users

Define the platform's purpose: to enable secure, compliant, and efficient software delivery for internal development teams. Identify key user personas (developers, security engineers, SREs) and their pain points.

2. Define Strategic Pillars

Establish 3-4 strategic pillars such as 'Shift-Left Security', 'Developer Self-Service', 'Compliance Automation', and 'Observability & Feedback'. These pillars guide OKR creation and roadmap prioritization.

3. Craft OKRs

For each pillar, define 1-2 Objectives with 2-3 Key Results. Ensure KRs are measurable, outcome-based, and time-bound. Example: Objective: Accelerate secure delivery; KR1: Reduce average vulnerability remediation time from 30 to 7 days; KR2: Increase automated security gate coverage from 20% to 80% of pipelines.

4. Prioritize and Roadmap

Use a prioritization framework (e.g., RICE) to sequence initiatives. Start with foundational capabilities (CI/CD integration, secrets management) then layer on advanced security automation and self-service portals.

5. Align and Measure

Socialize OKRs with cross-functional stakeholders (engineering, security, compliance) to ensure alignment. Set up dashboards to track progress and iterate quarterly based on feedback and changing business needs.

Key Points to Mention

  • Alignment with JPMC's business goals: faster time-to-market, reduced risk, regulatory compliance (e.g., OCC, GDPR).
  • Developer experience: reducing friction, self-service, and clear documentation to drive adoption.
  • Security integration: automated scanning, policy-as-code, and shift-left practices without slowing down delivery.
  • Metrics: DORA metrics (deployment frequency, lead time, MTTR, change failure rate) plus security-specific KPIs.
  • Cross-functional collaboration: working with security, compliance, infrastructure, and application teams.
  • Phased approach: pilot with a few teams, gather feedback, then scale across the organization.

AI-generated suggestions, not part of the candidate's original notes. May be inaccurate — verify before relying on them.