Bengaluru, Karnataka, India
22 hours ago
Associate, Technology Risk and Control - Issue Management

The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC’s Corporate Third Party Oversight (CTPO) program.  SAS also supports JPMC’s Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC’s supply chain.  SAS is part of Global Supplier Services (GSS), reporting directly to JPMC’s Global Head of Corporate Third Party Oversight. SAS Risk Management function has been established to standardize and centralize Assessment quality oversight and Supplier Issue Management activities. 

Job Summary

As an Associate, Technology Risk and Control - Issue Management team within the Global Supplier Services (GSS), you will perform technology and cybersecurity control reviews.

Job responsibilities

Review Findings – making sure the description, severity justification, required evidence for closure description are in line with JPMC guidanceReview Closure Evidence" or "Ensure Closure EvidenceEngage with multiple internal stakeholders on addressing Issue Management queriesWork with the LOB Delivery Manager, Information Security Manager to resolve findings through Action Plans and Risk Acceptance Liaise with Business Partners to ensure that relevant Action 
Plans/ Risk Acceptances are remediated within agreed timeframes Understanding all aspects of the Supplier Risk Assessment processManaging entire Issue Lifecycle (identification, creation, modifications, extensions, and validate closure evidence) Identifying opportunities for process improvements Supporting internal education and best practices sharing with peers and colleagues

 

Required qualifications, capabilities, and skills

5+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, etc.)Strong written and verbal presentation skills at the senior management levelExperience debating issues with senior decision makers and pushing back when necessary

 

Preferred qualifications, capabilities, and skills

CISSP, CISA, CISM, CCSP or CRISC certification 
Confirmar seu email: Enviar Email