As a Supplier Cybersecurity Controls Assessor within the Supplier Assurance Services team, you will be responsible for conducting comprehensive risk assessments of suppliers as part of JPMorgan Chase & Co.'s Corporate Third Party Oversight program. Your role will also involve supporting JPMorgan Chase & Co.’s Cybersecurity and Technology functions by developing and implementing controls and processes to enhance the security posture of our supply chain. As a part of the Global Supplier Services team, you will report directly to the Global Head of Corporate Third Party Oversight at JPMorgan Chase & Co. Your duties will include performing technology and cybersecurity control assessments of supplier environments, reviewing infrastructure, application stacks, and other technologies to ensure compliance with JPMorgan Chase & Co. Corporate Policies & Standards. You will be tasked with validating that technical risks are managed by Issue Owners at JPMorgan Chase & Co. and that security controls are fully implemented. You will collaborate with JPMorgan Chase & Co.’s Global Cybersecurity and Technology team and the various Lines of Business to focus on the latest cyber risks identified in the industry. As a member of the Supplier Assurance Services team, you will assess action plans and risk acceptances across business lines where technology standards’ compliance cannot be achieved.
- Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
- Liaising with JPMC and supplier’s senior managers to communicate and influence best risk practices.
- Driving compliance to adhere to best risk management practices throughout the organizations.
Job responsibilities
- Manage all aspects of the control assessment of suppliers including assessing completed questionnaires and supporting field work materials to ensure they are complete and meet JPMC expectations.
- Lead the onsite / virtual assessment, providing the overall technology and cybersecurity risk and controls expertise.
- Identify and document control breaks and vulnerabilities within suppliers’ IT environments and work with the Line of Business (LOB) Delivery Manager and Information Security Manager to resolve through action plans or seek risk acceptance approvals.
- Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring, key risk indicator tracking, etc.
- Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness
- Escalate issues associated with suppliers as needed.
Required qualifications, capabilities, and skills
- 5+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.
- Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, etc.)
- Strong written and verbal presentation skills at the senior management level
- Experience debating issues with senior decision makers and pushing back when necessary
Preferred qualifications, capabilities, and skills
- CISSP, CISA, CISM, CCSP or CRISC certification is a plus