LOG IN
SIGN UP
Tech Job Finder - Find Software, Technology Sales and Product Manager Jobs.
Sign In
OR continue with e-mail and password
E-mail address
Password
Don't have an account?
Reset password
Join Tech Job Finder
OR continue with e-mail and password
E-mail address
First name
Last name
Username
Password
Confirm Password
How did you hear about us?
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Associate, Supplier Cybersecurity Controls Assessor

at J.P. Morgan

Back to all Cybersecurity jobs
J.P. Morgan logo
Bulge Bracket Investment Banks

Associate, Supplier Cybersecurity Controls Assessor

at J.P. Morgan

Tech LeadNo visa sponsorshipCybersecurity

Posted 15 days ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Bengaluru
Country
India

Join the Supplier Assurance Services team to perform virtual technical risk and control assessments of medium- and low-risk supplier environments, ensuring compliance with JPMC policies and validating implemented security controls. You will identify control gaps and vulnerabilities, document findings, and work with LOB Delivery Managers and Information Security to manage remediation via action plans or risk acceptances. The role involves liaising with senior stakeholders, driving supplier compliance improvements, and contributing to SAS program initiatives and process enhancements.

Location: Bengaluru, Karnataka, India

The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC’s Corporate Third Party Oversight (CTPO) program. SAS also supports JPMC’s Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC’s supply chain. SAS is part of Global Supplier Services (GSS), reporting directly to JPMC’s Global Head of Corporate Third Party Oversight. 

Job Summary 

As a Supplier Assurance Services (SAS) Supplier Control Assessor, within this role, you will be responsible for performing virtual technical risk and control assessments of medium and low risk supplier environments, including infrastructure, application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards and to validate that technical risks are managed and security controls are implemented. The Supplier Control Assessment (SCA) team will partner with CTC and Lines of Business (LOBs) to focus on performing assessment of supplier’s control environments.  The Team is also responsible for assessing action plans and risk acceptances across business lines where technology standards’ compliance cannot be achieved. This includes:

  • Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
  • Liaising with JPMC and supplier’s senior managers to communicate and influence best risk practices.
  • Driving compliance to adhere to best risk management practices throughout the organizations.

 

Job responsibilities  

  • Engage with multiple LOB Delivery Managers for firm-wide suppliers to ensure compliance with required assessments per the JPMC policy and procedures.
  • Drive all aspects of the control assessment of suppliers. 
  • Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead medium and low risk supplier virtual assessment, providing the overall IT and cybersecurity risk and controls expertise.
  • Identify control breaks and vulnerabilities within supplier’s IT environment.
  • Document findings and work with the LOB Delivery Manager, Information Security Manager to resolve those findings through action plans (APs) or seek risk acceptance (RA) approvals.
  • Validate evidence from supplier, before action plans are closed.
  • Escalate issues associated with suppliers as needed.
  • Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
  • Identify opportunities for improving supplier posture as well as JPMC's supplier management processes, including expanded monitoring, KRI tracking, etc.
  • Assist with various SAS program initiatives working closely with the SAS Leads. 

 

Required qualifications, capabilities, and skills 

  • 8+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment. 

  • Good understanding of relevant aspects of the Third-Party Oversight and Supplier Assurance Programs, lifecycle, execution best practices and supplier risk awareness. 

  • Experience working in Supplier Management, Risk and Controls Management, Technology Audit, or Information Security team(s). 

  • Strong written and verbal presentation skills at the senior management level 

Preferred qualifications, capabilities, and skills  

  • CISSP, CISA, CISM, CCSP or CRISC certification is a plus 

Supplier Cybersecurity Controls Assessor

Associate, Supplier Cybersecurity Controls Assessor

at J.P. Morgan

Back to all Cybersecurity jobs
J.P. Morgan logo
Bulge Bracket Investment Banks

Associate, Supplier Cybersecurity Controls Assessor

at J.P. Morgan

Tech LeadNo visa sponsorshipCybersecurity

Posted 15 days ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Bengaluru
Country
India

Join the Supplier Assurance Services team to perform virtual technical risk and control assessments of medium- and low-risk supplier environments, ensuring compliance with JPMC policies and validating implemented security controls. You will identify control gaps and vulnerabilities, document findings, and work with LOB Delivery Managers and Information Security to manage remediation via action plans or risk acceptances. The role involves liaising with senior stakeholders, driving supplier compliance improvements, and contributing to SAS program initiatives and process enhancements.

Location: Bengaluru, Karnataka, India

The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC’s Corporate Third Party Oversight (CTPO) program. SAS also supports JPMC’s Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC’s supply chain. SAS is part of Global Supplier Services (GSS), reporting directly to JPMC’s Global Head of Corporate Third Party Oversight. 

Job Summary 

As a Supplier Assurance Services (SAS) Supplier Control Assessor, within this role, you will be responsible for performing virtual technical risk and control assessments of medium and low risk supplier environments, including infrastructure, application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards and to validate that technical risks are managed and security controls are implemented. The Supplier Control Assessment (SCA) team will partner with CTC and Lines of Business (LOBs) to focus on performing assessment of supplier’s control environments.  The Team is also responsible for assessing action plans and risk acceptances across business lines where technology standards’ compliance cannot be achieved. This includes:

  • Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
  • Liaising with JPMC and supplier’s senior managers to communicate and influence best risk practices.
  • Driving compliance to adhere to best risk management practices throughout the organizations.

 

Job responsibilities  

  • Engage with multiple LOB Delivery Managers for firm-wide suppliers to ensure compliance with required assessments per the JPMC policy and procedures.
  • Drive all aspects of the control assessment of suppliers. 
  • Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead medium and low risk supplier virtual assessment, providing the overall IT and cybersecurity risk and controls expertise.
  • Identify control breaks and vulnerabilities within supplier’s IT environment.
  • Document findings and work with the LOB Delivery Manager, Information Security Manager to resolve those findings through action plans (APs) or seek risk acceptance (RA) approvals.
  • Validate evidence from supplier, before action plans are closed.
  • Escalate issues associated with suppliers as needed.
  • Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
  • Identify opportunities for improving supplier posture as well as JPMC's supplier management processes, including expanded monitoring, KRI tracking, etc.
  • Assist with various SAS program initiatives working closely with the SAS Leads. 

 

Required qualifications, capabilities, and skills 

  • 8+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment. 

  • Good understanding of relevant aspects of the Third-Party Oversight and Supplier Assurance Programs, lifecycle, execution best practices and supplier risk awareness. 

  • Experience working in Supplier Management, Risk and Controls Management, Technology Audit, or Information Security team(s). 

  • Strong written and verbal presentation skills at the senior management level 

Preferred qualifications, capabilities, and skills  

  • CISSP, CISA, CISM, CCSP or CRISC certification is a plus 

Supplier Cybersecurity Controls Assessor