DescriptionThe Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMCs Corporate Third Party Oversight (CTPO) program. SAS also supports JPMCs Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMCs supply chain. SAS is part of Global Supplier Services (GSS) reporting directly to JPMCs Global Head of Corporate Third Party Risk Management function has been established to standardize and centralize Assessment quality oversight and Supplier Issue Management activities.
Job Summary
As an Associate Technology Risk and Control - Issue Management team within the Global Supplier Services (GSS) you will perform technology and cybersecurity control reviews.
Job responsibilities
- Review Findings making sure the description severity justification required evidence for closure description are in line with JPMC guidance
- Review Closure Evidence or Ensure Closure Evidence
- Engage with multiple internal stakeholders on addressing Issue Management queries
- Work with the LOB Delivery Manager Information Security Manager to resolve findings through Action Plans and Risk Acceptance
- Liaise with Business Partners to ensure that relevant Action
Plans/ Risk Acceptances are remediated within agreed timeframes - Understanding all aspects of the Supplier Risk Assessment process
- Managing entire Issue Lifecycle (identification creation modifications extensions and validate closure evidence)
- Identifying opportunities for process improvements
- Supporting internal education and best practices sharing with peers and colleagues
Required qualifications capabilities and skills
- 5 years of experience in Technology Technology Risk & Controls Technology Audit Cybersecurity Application Security Cloud Security (SaaS PaaS & IaaS) Network Security Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.
- Understanding of industry risk frameworks (ISO27001 NIST Cybersecurity Framework etc.)
- Strong written and verbal presentation skills at the senior management level
- Experience debating issues with senior decision makers and pushing back when necessary
Preferred qualifications capabilities and skills
- CISSP CISA CISM CCSP or CRISC certification
Required Experience:
IC