DescriptionBring your expertise to JPMorgan Chase a global leader in financial services committed to innovation integrity and making a positive impact. As part of our Third Party Application Security (TPAS) program within Corporate Third Party Oversight (CTPO) youll be at the heart of our mission to keep the firms supply chain strong and resilient. Here youll help anticipate and address new and emerging risks in third party software cloud environments and AI systemsusing your skills to solve real-world challenges that affect our company partners and communities.
As a Third Party Application Security Associate within the Third Party Application Security (TPAS) program youll play a pivotal role in protecting JPMorgan Chases supply chain. Youll lead efforts to monitor and strengthen third party applications by assessing Software Bill of Materials (SBOMs) Artificial Intelligence Bill of Materials (AI BOMs) and cloud security this fast-paced environment youll engage directly with suppliers analyze risk data and track remediation efforts. Youll collaborate with stakeholders across Lines of Business Technology Cybersecurity and Cloud Engineering to streamline security assessments and validate controlsmaking a tangible impact on the security and resilience of our organization.
Job Responsibilities
- Drive the transformation agenda including business justification and program build out.
- Partner with internal risk teams to support business as usual risk activities reporting and project initiatives.
- Ensure risk impacting the business is effectively identified quantified communicated and remediated
- Influence supplier adoption of the product vision roadmap and risk control objectives
- Operationalize the Third Party Software Bill of Materials (SBOM) program
Required qualifications capabilities and skills
- Strong leadership skills ability to multitask sense of ownership attention to detail and quality and deliver on commitments
- Understanding of Secure Software Development Life Cycle (SSDLC) (e.g. coding requirements risk assessments threat modeling static code analysis and dynamic application scanning)
- 3 years of experience in Third Party Risk Management (TPRM) or Governance Risk Management and Compliance (GRC) Cybersecurity Application Security Cloud Security Architecture (SaaS PaaS & IaaS) within a large enterprise level environment
- 3 years of experience using a broad set of technologies (e.g. servers operating systems applications databases hypervisors virtualization management containers compute storage etc.)
- Bachelors degree in a relevant discipline
- Proficiency with Microsoft applications (e.g. Word Excel Outlook Visio OneNote SharePoint Teams etc.)
Preferred qualifications capabilities and skills
- Certification in Public Cloud Technology from major Cloud Service Provider
- Experience with Software Bill of Materials (SBOM)
- CISSP CISA CISM CCSP or CRISC certification
Required Experience:
Exec
DescriptionBring your expertise to JPMorgan Chase a global leader in financial services committed to innovation integrity and making a positive impact. As part of our Third Party Application Security (TPAS) program within Corporate Third Party Oversight (CTPO) youll be at the heart of our mission to...
DescriptionBring your expertise to JPMorgan Chase a global leader in financial services committed to innovation integrity and making a positive impact. As part of our Third Party Application Security (TPAS) program within Corporate Third Party Oversight (CTPO) youll be at the heart of our mission to keep the firms supply chain strong and resilient. Here youll help anticipate and address new and emerging risks in third party software cloud environments and AI systemsusing your skills to solve real-world challenges that affect our company partners and communities.
As a Third Party Application Security Associate within the Third Party Application Security (TPAS) program youll play a pivotal role in protecting JPMorgan Chases supply chain. Youll lead efforts to monitor and strengthen third party applications by assessing Software Bill of Materials (SBOMs) Artificial Intelligence Bill of Materials (AI BOMs) and cloud security this fast-paced environment youll engage directly with suppliers analyze risk data and track remediation efforts. Youll collaborate with stakeholders across Lines of Business Technology Cybersecurity and Cloud Engineering to streamline security assessments and validate controlsmaking a tangible impact on the security and resilience of our organization.
Job Responsibilities
- Drive the transformation agenda including business justification and program build out.
- Partner with internal risk teams to support business as usual risk activities reporting and project initiatives.
- Ensure risk impacting the business is effectively identified quantified communicated and remediated
- Influence supplier adoption of the product vision roadmap and risk control objectives
- Operationalize the Third Party Software Bill of Materials (SBOM) program
Required qualifications capabilities and skills
- Strong leadership skills ability to multitask sense of ownership attention to detail and quality and deliver on commitments
- Understanding of Secure Software Development Life Cycle (SSDLC) (e.g. coding requirements risk assessments threat modeling static code analysis and dynamic application scanning)
- 3 years of experience in Third Party Risk Management (TPRM) or Governance Risk Management and Compliance (GRC) Cybersecurity Application Security Cloud Security Architecture (SaaS PaaS & IaaS) within a large enterprise level environment
- 3 years of experience using a broad set of technologies (e.g. servers operating systems applications databases hypervisors virtualization management containers compute storage etc.)
- Bachelors degree in a relevant discipline
- Proficiency with Microsoft applications (e.g. Word Excel Outlook Visio OneNote SharePoint Teams etc.)
Preferred qualifications capabilities and skills
- Certification in Public Cloud Technology from major Cloud Service Provider
- Experience with Software Bill of Materials (SBOM)
- CISSP CISA CISM CCSP or CRISC certification
Required Experience:
Exec
View more
View less