drjobs Associate, Supplier Cybersecurity Controls Assessor

Associate, Supplier Cybersecurity Controls Assessor

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Bengaluru - India

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Description

The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMCs Corporate Third Party Oversight (CTPO) program. SAS also supports JPMCs Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMCs supply chain. SAS is part of Global Supplier Services (GSS) reporting directly to JPMCs Global Head of Corporate Third Party Oversight.

Job Summary

As an Associate Supplier Cybersecurity Controls within the Supplier Assurance Services you will perform technology and cybersecurity control assessments of supplier environments. These assessments review infrastructure application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards. You will validate those technical risks are managed by JPMC Issue Owners and security controls are fully implemented. You will partner with JPMCs Global Cybersecurity and Technology team and JPMCs Lines of Business (LOBs) to focus on the latest cyber risks identified in the industry. As a SAS team member you will assess action plans and risk acceptances across business lines where technology standards compliance cannot be achieved. This includes:

  • Identifying opportunities to improve third party risk posture developing creative solutions for mitigating risks.
  • Liaising with JPMC and suppliers senior managers to communicate and influence best risk practices.
  • Driving compliance to adhere to best risk management practices throughout the organizations.

Job responsibilities

  • Manage all aspects of the control assessment of suppliers including assessing completed questionnaires and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead the onsite / virtual assessment providing the overall technology and cybersecurity risk and controls expertise.
  • Identify and document control breaks and vulnerabilities within suppliers IT environments and work with the LOB Delivery Manager and Information Security Manager to resolve through action plans or seek risk acceptance approvals.
  • Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring key risk indicator tracking etc.
  • Support internal education and best practices sharing with peers and colleagues as well as third party education & awareness
  • Escalate issues associated with suppliers as needed.

Required qualifications capabilities and skills

  • 5 years of experience in Technology Technology Risk & Controls Technology Audit Cybersecurity Application Security Cloud Security (SaaS PaaS & IaaS) Network Security Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.
  • Understanding of industry risk frameworks (ISO27001 NIST Cybersecurity Framework etc.)
  • Strong written and verbal presentation skills at the senior management level
  • Experience debating issues with senior decision makers and pushing back when necessary

Preferred qualifications capabilities and skills

  • CISSP CISA CISM CCSP or CRISC certification



Required Experience:

IC

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.