The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC’s Corporate Third Party Oversight (CTPO) program. SAS also supports JPMC’s Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC’s supply chain. SAS is part of Global Supplier Services (GSS), reporting directly to JPMC’s Global Head of Corporate Third Party Oversight. SAS Risk Management function has been established to standardize and centralize Assessment quality oversight and Supplier Issue Management activities.
Job Summary
As an Associate, Technology Risk and Control - Issue Management team within the Global Supplier Services (GSS), you will perform technology and cybersecurity control reviews.
Job responsibilities
Review Findings – making sure the description, severity justification, required evidence for closure description are in line with JPMC guidanceReview Closure Evidence" or "Ensure Closure EvidenceEngage with multiple internal stakeholders on addressing Issue Management queriesWork with the LOB Delivery Manager, Information Security Manager to resolve findings through Action Plans and Risk Acceptance Liaise with Business Partners to ensure that relevant ActionPlans/ Risk Acceptances are remediated within agreed timeframes Understanding all aspects of the Supplier Risk Assessment processManaging entire Issue Lifecycle (identification, creation, modifications, extensions, and validate closure evidence) Identifying opportunities for process improvements Supporting internal education and best practices sharing with peers and colleagues
Required qualifications, capabilities, and skills
5+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, etc.)Strong written and verbal presentation skills at the senior management levelExperience debating issues with senior decision makers and pushing back when necessary
Preferred qualifications, capabilities, and skills
CISSP, CISA, CISM, CCSP or CRISC certification