drjobs Supplier Cybersecurity Controls Assessor

Supplier Cybersecurity Controls Assessor

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Columbus - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Description

Are you interested in joining an industryleading Third Party Risk Management team We are hiring cybersecurity risk professionals.

As a Supplier Cybersecurity Controls Assessor within our Supplier Assurance Services (SAS) team you will perform comprehensive risk assessments of suppliers within JPMCs Corporate Third Party Oversight (CTPO) program. The SAS team supports JPMCs Cybersecurity and Technology functions by designing and implementing controls and processes to enhance the security posture of JPMCs supply chain. As part of Global Supplier Services (GSS) and reporting directly to JPMCs Global Head of Corporate Third Party Oversight you will conduct technology and cybersecurity control assessments of supplier environments including services hosted in public cloud providers. You will evaluate the effectiveness of controls in supplier infrastructure application stacks cloud hosts and other technologies ensuring the confidentiality and integrity of JPMCs data stored in supplier environments and the availability of JPMCs services provided by suppliers. To effectively assess suppliers you will stay informed of the latest cyber risks in the industry and current adversarial tactics techniques and procedures. Your leadership skills and proven ability to function with minimal daytoday oversight will help you navigate complex stakeholder organizations and sensitive JPMC supplier relationships making your work in SAS a critical component of JPMCs overall defensive risk posture.

Job responsibilities

  • In partnership with internal and external stakeholders review supplier security stacks and conduct field work to ensure they are complete and meet JPMC expectations.
  • Provide cybersecurity risk and controls expertise during the onsite / virtual assessment of the supplier controls environment.
  • Identify cybersecurity risks and weaknesses within suppliers IT and hosted cloud environments and document remediation plans.
  • Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring key risk indicator tracking etc.

Required qualifications capabilities and skills

  • 710 years of experience in Technology Technology Risk & Controls Cyber Operations Application Security Cloud Security (SaaS PaaS & IaaS) Network Security or Cyber Resiliency within a large enterpriselevel environment.
  • Subject Matter Expertise of cybersecurity operations including defensive architectures and processes to combat adversarial activities
  • Proficient in techniques for incident management incident handling incident investigations root cause analysis and related processes
  • Strong written and verbal presentation skills at the senior management level including ability to describe cyber risks in terms relatable to business stakeholders
  • Experience debating issues with senior decision makers and pushing back when necessary

Preferred qualifications capabilities and skills

  • Handson practical experience in red teaming blue teaming or penetration testing is a plus
  • CISSP CCSP or similar certifications are a plus


Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.