LOG IN
SIGN UP
Tech Job Finder - Find Software, Technology Sales and Product Manager Jobs.
Sign In
OR continue with e-mail and password
E-mail address
Password
Don't have an account?
Reset password
Join Tech Job Finder
OR continue with e-mail and password
E-mail address
First name
Last name
Username
Password
Confirm Password
How did you hear about us?
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Vice President - Third Party Assessment & Exercises

at J.P. Morgan

Back to all Cybersecurity jobs
J.P. Morgan logo
Bulge Bracket Investment Banks

Vice President - Third Party Assessment & Exercises

at J.P. Morgan

Mid LevelNo visa sponsorshipCybersecurity

Posted a month ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Columbus
Country
United States

Senior cybersecurity leader responsible for the quality, consistency, and effectiveness of third-party cybersecurity assurance across the region. Lead and develop a team of senior assessors, design and execute offensive testing and simulation exercises, and ensure alignment to global methodology and regulatory requirements. Translate technical risk into clear, business-relevant insights and act as a deputy for the Global Third-Party Assurance Lead when required. Drive continuous improvement of third-party assurance processes, reporting, and stakeholder engagement.

Location: Columbus, OH, United States

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

As a Vice President - Third Party Assessment & Exercises in CTC, you will be accountable for the quality, consistency, and effectiveness of third-party cybersecurity assurance outcomes across the region. You will lead and develop a senior team of assessors across multiple locations, act as a trusted escalation point, and represent the function with senior stakeholders. You will translate complex technical risk into clear, business-relevant insights and act as deputy to the Global Third-Party Assurance Lead when required, ensuring continuity of leadership and decision-making.

Job responsibilities

  • Design and execute testing and simulations – such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
  • Collaborate closely with cross-functional teams to develop comprehensive assessment reports – including detailed findings, risk assessments, and remediation recommendations – making data-driven decisions that encourage continuous improvement
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics
  • Lead, coach and develop a team of senior Third-Party Cybersecurity Assessors across multiple North America locations, driving accountability and performance
  • Own regional delivery quality and consistency, including quality assurance over assessment outputs and alignment to global methodology and standards
  • Act as the primary escalation point for complex supplier risks, delivery challenges, and stakeholder issues
  • Serve as leadership proxy for the Global Third-Party Assurance Lead, representing the function and owning decisions when required
  • Drive service development and continuous improvement of third-party assurance processes, tools, and ways of working
  • Translate complex technical cybersecurity risks into clear, actionable insights and engage effectively with senior stakeholders across Cybersecurity, Technology, Risk and the Business

Required qualifications, capabilities, and skills

  • Obtain 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels
  • Proven experience leading high-performing cybersecurity, cyber risk or assurance teams, preferably across multiple locations
  • Demonstrated strength as a people manager, capable of leading experienced and senior professionals
  • Strong experience and technical depth in cybersecurity control assessment, assurance, or risk management
  • Strong understanding of industry cybersecurity frameworks and key control domains (e.g. NIST CSF, ISO 27001)
  • Proven ability to influence senior stakeholders and communicate cyber risk clearly to business audiences

Preferred qualifications, capabilities, and skills

  • Hold relevant industry certifications – such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Offensive Security Certified Professional (OSCP)– showcasing advanced expertise in cybersecurity and offensive testing methodologies or resiliency
  • Knowledge/experience in modern programming language


 

Enhance the firm's cybersecurity posture through advanced assessments of people, processes, and technology.

Vice President - Third Party Assessment & Exercises

at J.P. Morgan

Back to all Cybersecurity jobs
J.P. Morgan logo
Bulge Bracket Investment Banks

Vice President - Third Party Assessment & Exercises

at J.P. Morgan

Mid LevelNo visa sponsorshipCybersecurity

Posted a month ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Columbus
Country
United States

Senior cybersecurity leader responsible for the quality, consistency, and effectiveness of third-party cybersecurity assurance across the region. Lead and develop a team of senior assessors, design and execute offensive testing and simulation exercises, and ensure alignment to global methodology and regulatory requirements. Translate technical risk into clear, business-relevant insights and act as a deputy for the Global Third-Party Assurance Lead when required. Drive continuous improvement of third-party assurance processes, reporting, and stakeholder engagement.

Location: Columbus, OH, United States

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

As a Vice President - Third Party Assessment & Exercises in CTC, you will be accountable for the quality, consistency, and effectiveness of third-party cybersecurity assurance outcomes across the region. You will lead and develop a senior team of assessors across multiple locations, act as a trusted escalation point, and represent the function with senior stakeholders. You will translate complex technical risk into clear, business-relevant insights and act as deputy to the Global Third-Party Assurance Lead when required, ensuring continuity of leadership and decision-making.

Job responsibilities

  • Design and execute testing and simulations – such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements
  • Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
  • Collaborate closely with cross-functional teams to develop comprehensive assessment reports – including detailed findings, risk assessments, and remediation recommendations – making data-driven decisions that encourage continuous improvement
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics
  • Lead, coach and develop a team of senior Third-Party Cybersecurity Assessors across multiple North America locations, driving accountability and performance
  • Own regional delivery quality and consistency, including quality assurance over assessment outputs and alignment to global methodology and standards
  • Act as the primary escalation point for complex supplier risks, delivery challenges, and stakeholder issues
  • Serve as leadership proxy for the Global Third-Party Assurance Lead, representing the function and owning decisions when required
  • Drive service development and continuous improvement of third-party assurance processes, tools, and ways of working
  • Translate complex technical cybersecurity risks into clear, actionable insights and engage effectively with senior stakeholders across Cybersecurity, Technology, Risk and the Business

Required qualifications, capabilities, and skills

  • Obtain 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels
  • Proven experience leading high-performing cybersecurity, cyber risk or assurance teams, preferably across multiple locations
  • Demonstrated strength as a people manager, capable of leading experienced and senior professionals
  • Strong experience and technical depth in cybersecurity control assessment, assurance, or risk management
  • Strong understanding of industry cybersecurity frameworks and key control domains (e.g. NIST CSF, ISO 27001)
  • Proven ability to influence senior stakeholders and communicate cyber risk clearly to business audiences

Preferred qualifications, capabilities, and skills

  • Hold relevant industry certifications – such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Offensive Security Certified Professional (OSCP)– showcasing advanced expertise in cybersecurity and offensive testing methodologies or resiliency
  • Knowledge/experience in modern programming language


 

Enhance the firm's cybersecurity posture through advanced assessments of people, processes, and technology.