Principal Cybersecurity Architect, Third-Party Assurance

JPMorganChase

Not Interested
Bookmark
Report This Job

profile Job Location:

Plano, TX - USA

profile Monthly Salary: Not Disclosed
Posted on: 19 hours ago
Vacancies: 1 Vacancy

Job Summary

Description

This is a rare opportunity to operate at the intersection of deep technical cybersecurity expertise and enterprise-level risk strategy. As a senior technical authority you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier relationships. You will work alongside leaders across Cybersecurity Technology and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm protects itself against emerging threats in an increasingly complex supplier landscape. If you are a cybersecurity leader who thrives on technical depth credible challenge and high-stakes decision-making this role was built for you.

As an Executive Director at JPMorganChase within the Cybersecurity and Technology Controls Assessments and Exercises function you will serve as the senior technical authority for third-party cybersecurity assurance bringing deep hands-on expertise in cybersecurity architecture cloud security and enterprise control frameworks to critically evaluate the control maturity of the firms most complex and strategically significant suppliers. Reporting to the Global Third-Party Assurance Lead you will elevate the technical rigor depth and credibility of third-party assurance outcomes across the organization. You will translate complex technical findings into clear business-relevant risk insights for senior stakeholders across Cybersecurity Technology Risk and the Business. You will also act as a trusted escalation point for the most technically challenging assessments ensuring the firms third-party risk posture reflects the highest standards of technical scrutiny.

Job Responsibilities:

  • Provide authoritative technical leadership across third-party cybersecurity assessments bringing deep expertise in cybersecurity architecture cloud-native and hybrid environments application security and enterprise control domains.
  • Lead and personally conduct in-depth technical evaluations of supplier cybersecurity posture control maturity and architectural resilience particularly for the firms most critical and complex third-party relationships.
  • Perform threat modelling against supplier environments to identify potential security risks and develop mitigation strategies tailored to the firms risk appetite.
  • Evaluate supplier security architectures across public cloud providers (AWS Azure Google Cloud) assessing the design and effectiveness of controls in cloud-native hybrid and on-premises environments.
  • Act as the senior technical escalation point for complex supplier risks control gaps and remediation strategies providing credible challenge and expert advisory input.
  • Drive the evolution of the third-party assurance methodology by embedding deeper technical assessment capabilities including architecture reviews threat modelling and cloud security posture evaluation.
  • Translate complex technical cybersecurity risks and supplier control deficiencies into clear actionable business-relevant insights for senior leadership and non-technical audiences through detailed reports and presentations.
  • Partner with Product Security Cybersecurity Architecture Technology Risk and Controls and Cybersecurity pillar leads to ensure alignment in control intent solution design and third-party risk remediation.
  • Lead thematic analysis to identify systemic technical weaknesses emerging risks and trends across the supplier landscape and recommend strategic remediation approaches.

Required Qualifications Capabilities and Skills:

  • 10 years of professional experience in cybersecurity with demonstrated experience in senior technical or architecture-focused positions.
  • Proven ability to assess and articulate the cybersecurity control maturity of complex technology environments including enterprise cloud-native and hybrid architectures.
  • Deep hands-on expertise in cybersecurity architecture threat modelling and designing or evaluating secure controls for enterprise-level solutions.
  • Strong understanding of industry cybersecurity frameworks and key control domains including NIST CSF ISO 27001 Federal Financial Institutions Examination Council (FFIEC) guidance SOC 2 and GDPR.
  • Thorough design and operational experience across one or more major public cloud providers including AWS Azure or Google Cloud.
  • Proficiency with Cloud Security Posture Management tools and cloud security assessment methodologies.
  • Demonstrated ability to translate complex cybersecurity and technical findings into clear business-relevant communications for audiences ranging from technical practitioners to executive and non-technical stakeholders.

Preferred Qualifications Capabilities and Skills:

  • Relevant cloud or cybersecurity certifications such as CISSP CCSP or cloud provider certifications from AWS Azure or Google Cloud.
  • Experience conducting cybersecurity assessments in support of strategic technology initiatives such as blockchain digital assets or emerging technology platforms including engagement at senior leadership forums.
  • Demonstrated ability to influence and negotiate with external suppliers and internal senior stakeholders to drive remediation outcomes and control improvements without direct authority.
  • Experience operating within or supporting a full lifecycle assessment model with the ability to engage independently with suppliers and subject matter experts from an early stage while managing multiple concurrent assessments.



Required Experience:

Staff IC

DescriptionThis is a rare opportunity to operate at the intersection of deep technical cybersecurity expertise and enterprise-level risk strategy. As a senior technical authority you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier r...
View more view more

About Company

Company Logo

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans ov ... View more

View Profile View Profile