Supplier Cybersecurity Assessor - Vice President
JPMorgan Chase & Co. Columbus, Ohio, United States
Financial Services · 10,001+ employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
Conduct cybersecurity and technology control assessments of third-party suppliers and cloud-hosted environments to identify risks and evaluate control effectiveness. Partner with internal and external stakeholders to drive remediation efforts and enhance assessment methodologies using AI-enabled tools.
What they look for
Requirements
Requires a minimum of 7 years of experience in cybersecurity, technology risk, or related disciplines within a large enterprise environment. Candidates must possess strong expertise in cybersecurity domains and hold relevant certifications such as CISSP, CISA, CISM, CCSP, or CRISC.
Benefits
Full description
Join a team that plays a critical role in protecting JPMorgan Chase and its clients from emerging cybersecurity threats. As part of Supplier Assurance Services, you will assess the cybersecurity posture of third-party suppliers, influence risk decisions, and help strengthen the firm's global supply chain. This is an opportunity to combine deep technical expertise with stakeholder engagement while driving meaningful risk outcomes.
As a Supplier Cybersecurity Assessor in Supplier Assurance Services, you will conduct cybersecurity and technology risk assessments of third-party suppliers and cloud-hosted environments to help safeguard the confidentiality, integrity, and availability of firm data and services. You will partner with internal and external stakeholders to evaluate cybersecurity controls, identify risks, and support remediation efforts. You will also help drive enhancements to assessment practices, including the responsible use of approved AI-enabled tools to improve efficiency, consistency, and risk insight
Job Responsibilities
- Conduct cybersecurity and technology control assessments of supplier environments, including cloud-hosted services.
- Review supplier security architectures, controls, processes, and supporting evidence.
- Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures.
- Assess supplier adherence to cybersecurity industry standards and best practices.
- Document assessment findings, risk impacts, and remediation recommendations.
- Translate technical observations into clear business risk outcomes and recommendations.
- Monitor emerging cyber threats and industry developments to strengthen assessment quality.
- Drive continuous improvement initiatives across assessment methodologies, standards, and reporting.
- Leverage approved AI-enabled tools to enhance assessment preparation, documentation, and analysis while maintaining appropriate oversight.
- Support governance, escalation, and reporting activities related to supplier cybersecurity risks.
Required Qualifications, Capabilities, and Skills
- Minimum of 7 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines within a large enterprise environment.
- Strong expertise in one or more cybersecurity domains, including cloud security, application security, infrastructure security, identity and access management, cyber resiliency, incident management, or data protection.
- Strong understanding of industry security frameworks such as ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent standards.
- Ability to assess technical controls and evaluate evidence to support risk-based conclusions.
- Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions.
- Excellent written and verbal communication skills, including the ability to present technical topics to senior stakeholders.
- Strong analytical and problem-solving capabilities with sound judgment and attention to detail.
- Ability to manage multiple priorities in a fast-paced, highly regulated environment.
- Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes.
- CISSP, CISA, CISM, CCSP, or CRISC certification.
Preferred Qualifications, Capabilities, and Skills
- Experience assessing public cloud environments, including AWS, Microsoft Azure, or Google Cloud Platform.
- Cloud security or cloud architecture certifications.
- Experience working within the financial services industry or another highly regulated industry.
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.
Global Supplier Services (GSS) manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk assessments and evaluating the customer experience. Global teams support sourcing, third party oversight, procurement and payment operations, supplier relationship management and customer experience.
Similar roles
-
IT Infrastructure & CyberSecurity Administrator
BALL HORTICULTURAL COMPANY West Chicago, Illinois, United States · $95K–$120K/yr
-
Cybersecurity Compliance Analyst II
APTNEXUS Washington, District of Columbia, United States · $80K–$100K/yr
-
Cybersecurity Compliance Analyst I
APTNEXUS Washington, District of Columbia, United States · $65K–$75K/yr
-
Cybersecurity Manager
Banner Engineering New Hope, Minnesota, United States · $133K–$193K/yr
-
Senior Product Security Engineer
Emerson Shakopee, Minnesota, United States · $115K–$140K/yr
-
Senior Senior Security Engineer, OCONUS, Google Pub Sector
Google Reston, Virginia, United States · $174K–$252K/yr