Supplier Cybersecurity Controls Assessor

3 weeks ago


Dallas, United States JPMorganChase Full time

Job Description
The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC's Corporate Third Party Oversight (CTPO) program. SAS also supports JPMC's Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC's supply chain. SAS is part of Global Supplier Services (GSS), reporting directly to JPMC's Global Head of Corporate Third Party Oversight.
As a SAS team member, you will perform technology and cybersecurity control assessments of supplier environments. These assessments review infrastructure, application stacks and other technologies to ensure compliance with JPMC Corporate Policies & Standards. You will validate those technical risks are managed by JPMC Issue Owners and security controls are fully implemented. You will partner with JPMC's Global Cybersecurity and Technology team and JPMC's Lines of Business (LOBs) to focus on the latest cyber risks identified in the industry. As a SAS team member, you will assess action plans and risk acceptances across business lines where technology standards' compliance cannot be achieved. This includes:

  • Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
  • Liaising with JPMC and supplier's senior managers to communicate and influence best risk practices.
  • Driving compliance to adhere to best risk management practices throughout the organizations.


Job responsibilities

  • Manage all aspects of the control assessment of suppliers including assessing completed questionnaires and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead the onsite / virtual assessment, providing the overall technology and cybersecurity risk and controls expertise.
  • Identify and document control breaks and vulnerabilities within suppliers' IT environments and work with the LOB Delivery Manager and Information Security Manager to resolve through action plans or seek risk acceptance approvals.
  • Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring, key risk indicator tracking, etc.
  • Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness
  • Escalate issues associated with suppliers as needed.


Required qualifications, capabilities, and skills

  • 5-7 years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment.
  • Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, etc.)
  • Strong written and verbal presentation skills at the senior management level
  • Experience debating issues with senior decision makers and pushing back when necessary


Preferred qualifications, capabilities, and skills

  • CISSP, CISA, CISM, CCSP or CRISC certification is a plus


About Us
JPMorgan Chase & Co., one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set, and location. For those in eligible roles, we offer discretionary incentive compensation which may be awarded in recognition of firm performance and individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans
About the Team
Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.
Global Supplier Services (GSS) manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk assessments and evaluating the customer experience. Global teams support sourcing, third party oversight, procurement and payment operations, supplier relationship management and customer experience.



  • Dallas, Texas, United States JPMorganChase Full time

    Job Description The Supplier Assurance Services (SAS) team performs comprehensive risk assessments of suppliers within JPMC's Corporate Third Party Oversight (CTPO) program. SAS also supports JPMC's Cybersecurity and Technology functions by designing and implementing controls and processes to further enhance the security posture of JPMC's supply chain. SAS...

  • Cybersecurity - Senior

    2 months ago


    Dallas, United States Metasys Technologies, Inc. Full time

    Cybersecurity - Senior12+Month ContractDallas, TX (onsite)Overview:Seeking a specialist to document and define IAM controls and governance models, enhancing cybersecurity controls and governance.Responsibilities: Document and refine IAM controls and governance models. Collect and analyze current controls, control processes, metrics, KRIs, and KPIs. Define...


  • Dallas, United States Spectral MD Full time

    Position Summary: Spectral MD, Inc. is seeking a cybersecurity engineer to join our growing team in Dallas, TX. The cybersecurity engineer should have experience in analyzing, identifying, and measuring the security related threats and vulnerabilities for the protection of data, software application systems and device network connectivity, both on premise...


  • Dallas, United States Saxon Global Full time

    Title: Microsoft-Stack Azure Cybersecurity EngineerLocation: North Dallas, Texas (Onsite: Tuesday, Wednesday, & Thursday)Duration: 12 Months Contract Overview: The Microsoft-Stack Azure Cybersecurity Engineer will be responsible for working independently at times, and within a team setting to oversee and mitigate cybersecurity threats across the...


  • Dallas, United States Saxon Global Full time

    Title: Microsoft-Stack Azure Cybersecurity EngineerLocation: North Dallas, Texas (Onsite: Tuesday, Wednesday, & Thursday)Duration: 12 Months Contract Overview: The Microsoft-Stack Azure Cybersecurity Engineer will be responsible for working independently at times, and within a team setting to oversee and mitigate cybersecurity threats across the...


  • Dallas, United States Vaco Full time

    Cybersecurity Engineer | 414654 DETAILS Location: Dallas, TX 75254 (3-days per week onsite [T / W / TH]) Position Type: 6M C2H Hourly / Salary: BOE!JOB SUMMARY Vaco Technology is currently seeking a Cybersecurity Engineer for a 6M C2H opportunity located in Dallas, TX 75254 (3-days per week onsite [T / W / TH]). The Cybersecurity Engineer will execute the...


  • Dallas, United States Vaco Full time

    Cybersecurity Engineer | 414654 DETAILS Location: Dallas, TX 75254 (3-days per week onsite [T / W / TH]) Position Type: 6M C2H Hourly / Salary: BOE!JOB SUMMARY Vaco Technology is currently seeking a Cybersecurity Engineer for a 6M C2H opportunity located in Dallas, TX 75254 (3-days per week onsite [T / W / TH]). The Cybersecurity Engineer will execute the...


  • Dallas, United States Vaco Full time

    Cybersecurity Engineer | 414654 DETAILS Location: Dallas, TX 75254 (3-days per week onsite [T / W / TH]) Position Type: 6M C2H Hourly / Salary: BOE! JOB SUMMARY Vaco Technology is currently seeking a Cybersecurity Engineer for a 6M C2H opportunity located in Dallas, TX 75254 (3-days per week onsite [T / W / TH]). The Cybersecurity Engineer will execute the...


  • Dallas, Texas, United States JPMorganChase Full time

    Job Description Join one of the world's most influential companies and leverage your skills in cybersecurity to have a real impact on the financial industry.As a Lead Cybersecurity Architect at JPMorgan Chase within the Cybersecurity and Technology Controls organization, you will be a key player in developing top-notch cybersecurity solutions for various...


  • Dallas, United States CECO Environmental Full time

    Job DescriptionJob DescriptionJOB SUMMARY: The Cybersecurity Engineer is responsible for the execution of the Cybersecurity and IAM strategy, identifying and mitigating cyber threats to the Company. Responsible for designing, documenting, implementing, and maintaining cybersecurity systems and processes. This role will also ensure that CECO users, devices,...


  • Dallas, United States CECO Environmental Full time

    Job DescriptionJob DescriptionJOB SUMMARY: The Cybersecurity Engineer is responsible for the execution of the Cybersecurity and IAM strategy, identifying and mitigating cyber threats to the Company. Responsible for designing, documenting, implementing, and maintaining cybersecurity systems and processes. This role will also ensure that CECO users, devices,...


  • Dallas, United States CECO Environmental Full time

    Job DescriptionJob DescriptionJOB SUMMARY: The Cybersecurity Engineer is responsible for the execution of the Cybersecurity and IAM strategy, identifying and mitigating cyber threats to the Company. Responsible for designing, documenting, implementing, and maintaining cybersecurity systems and processes. This role will also ensure that CECO users, devices,...

  • Controls Engineer

    2 weeks ago


    Dallas, United States ParkPoint Controls, LLC Full time

    This is a level II position in the field of controls engineering. The role of the Controls Engineer is to design, program and install control systems for a variety of systems including Conveyor, Life Safety and Pharmaceutical. The duties include electrical design, both control panel and system, PLC and HMI design and programming, field work including...


  • Dallas, Texas, United States JPMorganChase Full time

    Job Description With your experience as a security engineer, you belong among the elite talents in your industry. Join a vital team at one of the world's most renowned financial institutions.As a Cybersecurity Architect III at JPMorgan Chase within the Cybersecurity and Technology Controls organization, you will be a key player in delivering top-notch...


  • Dallas, United States Leidos Full time

    Description Leidos has an opening for a highly qualified Cybersecurity Engineer for the Multi-Domain Solutions Division. This is an exciting opportunity to support large-scale weapon systems, Information Technology Systems, and Command and Control Systems to realize the Department of Defense Joint All-Domain Command and Control (JADC2). In this role, you...

  • Technology Risk

    6 days ago


    Dallas, United States JPMorganChase Full time

    Job Description Join a role that's central to our technological resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance.As a Tech Risk & Controls Director in Cybersecurity and Technology Controls organization, you will play a pivotal role in shaping and implementing the firm's technology...


  • Dallas, United States Capco, a Wipro Company Full time

    **About the Team:** At Capco, we believe in fostering an inclusive work environment where you can #BeYourselfAtWork. Our Cybersecurity team is dynamic and dedicated to evaluating, strategizing, and implementing risk-aware solutions for top-tier organizations in the Financial Services sector. We tailor enterprise risk management strategies to address...


  • Dallas, United States Booz Allen Hamilton Full time

    Job Number: R0185293 Cybersecurity Architect, Lead The Opportunity : Everyone knows security needs to be "baked in" to a system architecture, but you actually know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface. What if you could use your cyber engineering skills to design and build secure systems for...


  • Dallas, United States Southwest Airlines Full time

    Job Description: Job Summary All of Southwest's People come together to deliver on our Purpose; Connecting People to what's important in their lives through friendly, reliable, and low-cost air travel. The Senior Cybersecurity Analyst delivers on our Purpose by joining the Cybersecurity Vulnerability Management Team, working to provide advanced technical...


  • Dallas, United States Capco, a Wipro Company Full time

    **About the Team:** At Capco, we believe in fostering an inclusive work environment where you can #BeYourselfAtWork. Our Cybersecurity team is dynamic and dedicated to evaluating, strategizing, and implementing risk-aware solutions for top-tier organizations in the Financial Services sector. We tailor enterprise risk management strategies to address...