Third Party Cyber Controls Assessor, Vp

Columbus, OH, United States

Job Description

b'


The Supplier Assurance Services (SAS) team is accountable for executing the global comprehensive risk management and assessment programs for all in-scope suppliers within JPMC\'s Corporate Third-Party Oversight (CTPO) program. SAS is also accountable for driving several programs that support the Cybersecurity and Technology (CTC) function, including implementing and operating controls and processes that further enhance the security posture of JPMC\'s supply chain. The Supplier Assurance Services (SAS) team is part of Global Supplier Services (GSS), reporting directly to JPMC\'s Chief Procurement Officer. The SAS team supports all Lines of Businesses (LOBs), and regions globally.

As a Supplier Assurance Services (SAS) Third Party Cyber Controls Assessor, this position is responsible for performing technical risk and control assessments of supplier environments, including infrastructure, application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards and to validate that technical risks are managed and security controls are implemented. The Supplier Control Assessment (SCA) team will partner with CTC and Lines of Business (LOBs) to focus on performing assessment of supplier\'s control environments. The Team is also responsible for assessing action plans and risk acceptances across business lines where technology standards\' compliance cannot be achieved. This includes:
  • Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
  • Liaising with JPMC and supplier\'s senior managers to communicate and influence best risk practices.
  • Driving compliance to adhere to best risk management practices throughout the organizations.

As a Third Party Cyber Controls Assessor within SAS, your day to day responsibilities will be to execute Supplier Control Assessments including risk identification, classification, and remediation. This includes:
  • Engage with multiple LOB Delivery Managers for firm-wide suppliers to ensure compliance with required assessments per the JPMC policy and procedures.
  • Drive all aspects of the control assessment of suppliers.
  • Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead the onsite / virtual assessment, providing the overall IT and cybersecurity risk and controls expertise.
  • Identify control breaks and vulnerabilities within supplier\'s IT environment.
  • Document findings and work with the LOB Delivery Manager, Information Security Manager to resolve those findings through action plans (APs) or seek risk acceptance (RA) approvals.
  • Validate evidence from supplier, before action plans are closed.
  • Escalate issues associated with suppliers as needed.
  • Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
  • Identify opportunities for improving supplier posture as well as JPMC\'s supplier management processes, including expanded monitoring, KRI tracking, etc.
  • Assist with various SAS program initiatives working closely with the SAS Leads.
  • Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness, as needed

Qualifications:
  • 5-7 years of experience in Risk Management, Technology Risk & Controls, Technology Audit, and Third-Party Outsourcing Risk Management within a large enterprise level environment.
  • 5-7 years of strong hands-on experiences and technical depth in one or more technology areas, including Data security, Infrastructure security, Endpoint/Platform security, Security Analytics, Authentication/Identity Management, Mobile Security, Application Security including strong understanding of application vulnerability scanning, penetration testing, static and dynamic scanning processes, Network Security, Cyber Resiliency, Incident Management, Cloud Security including strong understanding of cloud service, deployment models, encryption, key managementUnderstanding of industry risk frameworks (ISO27001, NIST etc.)
  • CISSP, CISA, CISM, CCSP or CRISC certification is a plus
  • AWS, Azure or Google Cloud developer / architect certifications would be a significant advantage
  • Experience debating issues with senior decision makers and pushing back when necessary.
  • Strong written and verbal presentation skills at the senior management level across various business groups
JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world\'s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management. We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. In accordance with applicable law, we make reasonable accommodations for applicants\' and employees\' religious practices and beliefs, as well as any mental health or physical disability needs. The health and safety of our colleagues, candidates, clients and communities has been a top priority in light of the COVID-19 pandemic. JPMorgan Chase was awarded the "WELL Health-Safety Rating" for all of our 6,200 locations globally based on our operational policies, maintenance protocols, stakeholder engagement and emergency plans to address a post-COVID-19 environment. As a part of our commitment to health and safety, we have implemented various COVID-related health and safety requirements for our workforce. Employees are expected to follow the Firm\'s current COVID-19 or other infectious disease health and safety requirements, including local requirements. Requirements include sharing information including your vaccine card in the firm\'s vaccine record tool, and may include mask wearing. Requirements may change in the future with the evolving public health landscape. JPMorgan Chase will consider accommodation requests as required by applicable law.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, discretionary incentive compensation which may be awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. Equal Opportunity Employer/Disability/Veterans

Beware of fraud agents! do not pay money to get a job

MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.


Related Jobs

Job Detail

  • Job Id
    JD4255003
  • Industry
    Not mentioned
  • Total Positions
    1
  • Job Type:
    Full Time
  • Salary:
    Not mentioned
  • Employment Status
    Permanent
  • Job Location
    Columbus, OH, United States
  • Education
    Not mentioned