Are you interested in joining an industry-leading Third Party Risk Management team? We are hiring cybersecurity risk professionals.
As a Supplier Cybersecurity Controls Assessor in Supplier Assurance Services, you will perform technology and cybersecurity control assessments of supplier environments. These assessments review infrastructure, application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards. You will validate those technical risks are managed by JPMC Issue Owners and security controls are fully implemented. You will partner with JPMC’s Global Cybersecurity and Technology team and JPMC’s Lines of Business (LOBs) to focus on the latest cyber risks identified in the industry. As a SAS team member, you will assess action plans and risk acceptances across business lines where technology standards’ compliance cannot be achieved. he Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC’s Corporate Third Party Oversight (CTPO) program.
Job responsibilities
Manage all aspects of the control assessment of suppliers including assessing completed questionnaires and supporting field work materials to ensure they are complete and meet JPMC expectations. Lead the onsite / virtual assessment, providing the overall technology and cybersecurity risk and controls expertise. Identify and document control breaks and vulnerabilities within suppliers’ IT environments and work with the LOB Delivery Manager and Information Security Manager to resolve through action plans or seek risk acceptance approvals. Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring, key risk indicator tracking, etc. Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness Escalate issues associated with suppliers as needed.Required qualifications, capabilities, and skills
5-7 years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment. Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, etc.) Strong written and verbal presentation skills at the senior management level Experience debating issues with senior decision makers and pushing back when necessaryPreferred qualifications, capabilities, and skills
CISSP, CISA, CISM, CCSP or CRISC certification is a plus