Supplier Cybersecurity Controls Assessor, Vice President

Posted Yesterday
Be an Early Applicant
2 Locations
Remote or Hybrid
Senior level
Financial Services
We’re one of the world’s biggest technology-driven companies
The Role
Lead cybersecurity and technology control assessments of supplier environments. Review questionnaires and evidence, evaluate infrastructure, applications, and security practices, identify control gaps, and communicate risk findings. Partner with stakeholders on remediation plans, validate implementation, assess risk acceptance requests, recommend mitigations, and escalate significant issues. The role also improves assessment processes, supports knowledge sharing, and presents concise risk insights to senior stakeholders.
Summary Generated by Built In

Help strengthen security outcomes across a global supplier ecosystem. In this role, you will influence risk decisions by turning complex evidence into clear control insights. You will partner with stakeholders to drive practical remediation and continuous improvement. You will help evolve assessment approaches to improve consistency, efficiency, and impact.

Job summary

As a Supplier Cybersecurity Controls Assessor Vice President in Supplier Assurance Services, you will lead technology and cybersecurity control assessments of supplier environments to help manage third-party risk. You will evaluate evidence, document control gaps, and collaborate with stakeholders to drive remediation plans or support risk acceptance decisions when needed. You will communicate clearly with senior stakeholders and help improve assessment approaches over time.

Job responsibilities
  • Review supplier assessment questionnaires and supporting evidence to confirm completeness and quality
  • Lead on-site or virtual supplier assessments and facilitate assessment discussions
  • Assess supplier infrastructure, applications, and security practices against defined control expectations
  • Identify, document, and communicate control gaps and vulnerabilities in supplier environments
  • Partner with stakeholders to develop remediation action plans and track progress to closure
  • Evaluate risk acceptance requests when control compliance cannot be achieved and document rationale
  • Recommend practical risk mitigation options that improve supplier security posture
  • Identify process improvement opportunities that increase assessment efficiency and consistency
  • Support education and knowledge sharing on supplier cybersecurity risk and controls
  • Escalate significant supplier issues in a timely manner through appropriate channels
Required qualifications, capabilities and skills
  • 7 years of experience in technology risk and controls, technology audit, cybersecurity, or third-party risk management within a large enterprise environment
  • Experience performing technology and cybersecurity control assessments of third parties or external suppliers
  • Working knowledge of industry risk and control frameworks (e.g., ISO 27001, NIST Cybersecurity Framework)
  • Experience assessing one or more of the following domains: application security, cloud security (SaaS, PaaS, IaaS), network security, or cyber resiliency
  • Demonstrated ability to identify control gaps, document findings, and translate technical issues into clear risk statements
  • Experience developing or evaluating remediation action plans and validating control implementation
  • Strong written communication skills, including concise reporting and stakeholder-ready summaries
  • Strong verbal communication and presentation skills with senior stakeholders
  • Demonstrated ability to challenge and influence decisions appropriately, including constructive pushback when needed
Preferred qualifications, capabilities and skills
  • One or more current certifications: CISSP, CISA, CISM, CCSP, or CRISC
  • Experience interpreting third-party assurance artifacts (e.g., SOC 2 reports, ISO 27001 certification evidence, ISAE 3402 Type II reports) to assess control design and operating effectiveness
  • Ability to translate technical control issues into business impact, clear risk statements, and crisp remediation recommendations for senior stakeholders
  • Working knowledge of common AI failure modes—including hallucinations, overconfidence, bias, and data contamination—and the ability to recognize how they can degrade document extraction and classification results

Internal Application Eligibility Requirements

TENURE:
• Must meet minimum employment tenure requirement. Specific roles require longer tenure in current position to be eligible to apply. Unless established for specific positions by the line of business, the standard tenure requirement is 12 months.
PERFORMANCE:
• Meets satisfactory performance standards as defined by the firm

You affirm that you meet the Internal Application Eligibility Requirements. This includes checking or declaring potential conflict of interest as stipulated in the Employment of Relatives and Employees in Personal Relationships Policy.
By submitting an application and/or joining the interview, you affirm to meet the Internal Mobility Eligibility Requirements as stated in the Applying for Internal Positions Firmwide Standard. You are expected to provide true and accurate information to the Company during the recruitment and application process. Knowingly giving false or misleading information shall be subjected to the imposition of appropriate corrective action, following the firm's Human Resource (HR) Policies and Guidelines.
Consult your Manager for any specific guidelines for your line of business or if you're unsure about your eligibility for an internal application.
Make sure your profile is updated in the new me@jpmc > Hiring and discuss internal mobility plans with your Manager at the soonest time possible. Attaching your updated resume is encouraged.
In partnership, Hiring Managers and Recruiters will review applications to determine which candidates best meet the required skills and experience specified in the job description. While not every application will result in an interview, applications will be acknowledged.

About UsJ.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
  
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
About the TeamOur professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.

Skills Required

  • At least 7 years of experience in technology risk and controls, technology audit, cybersecurity, or third-party risk management within a large enterprise environment
  • Experience performing technology and cybersecurity control assessments of third parties or external suppliers
  • Working knowledge of industry risk and control frameworks, such as ISO 27001 and the NIST Cybersecurity Framework
  • Experience assessing application security, cloud security, network security, or cyber resiliency
  • Ability to identify control gaps, document findings, and translate technical issues into clear risk statements
  • Experience developing or evaluating remediation action plans and validating control implementation
  • Strong written communication skills, including concise reporting and stakeholder-ready summaries
  • Strong verbal communication and presentation skills with senior stakeholders
  • Ability to challenge and influence decisions appropriately, including constructive pushback
  • Current CISSP, CISA, CISM, CCSP, or CRISC certification
  • Experience interpreting SOC 2 reports, ISO 27001 certification evidence, or ISAE 3402 Type II reports
  • Ability to translate technical control issues into business impact, risk statements, and remediation recommendations
  • Working knowledge of AI failure modes, including hallucinations, overconfidence, bias, and data contamination
  • Meet the firm's minimum internal employment tenure requirement
  • Meet satisfactory performance standards

JPMorganChase Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JPMorganChase and has not been reviewed or approved by JPMorganChase.

  • Healthcare Strength Medical, dental, vision, and mental-health coverage are broad, with wellness incentives, on-site or virtual care, and an EAP offering coaching and counseling. Plan materials emphasize accessible options, including multiple medical choices and tools to manage costs.
  • Parental & Family Support Paid parental leave extends up to 16 weeks for all parents, supplemented by paid Critical Caregiver Leave. Family resources include backup childcare via Bright Horizons, lactation support and milk-shipping, family-building assistance, and even a free five-month SNOO rental for newborns.
  • Retirement Support Retirement programs include a 401(k) with an annual company match and automatic pay credits for most employees, with a legacy pension available to earlier hires. An Employee Stock Purchase Plan at a 5% discount further supports long-term savings.

JPMorganChase Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
289,097 Employees
Year Founded: 1799

What We Do

JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $3.7 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small businesses, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world’s most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Technology fuels every aspect of our company and is at the heart of everything we do. With over 50,000 technologists globally and an annual tech spend of $12 billion, we are dedicated to improving the design, analytics, development, coding, testing and application programming that goes into creating high quality software and new products. Learn more about technology at our firm, explore resources from our Distinguished Engineers, AI & ML researchers, and other experts; access the latest episode of our TechTrends podcast, and more at www.jpmorgan.com/technology. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com. ©2023 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase is an Equal Opportunity Employer, including Disability/Veterans.

Why Work With Us

Our technologists work on a diverse range of solutions that include strategic technology initiatives, big data, mobile, electronic payments, machine learning, cybersecurity, enterprise cloud development, and other state-of-the-art technologies.

Gallery

Gallery

Similar Jobs

CrowdStrike Logo CrowdStrike

Account Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Philippines
11000 Employees

Sailor Health Logo Sailor Health

Insurance Authorization Specialist

Healthtech • Social Impact • Telehealth
Remote
Philippines
20 Employees
1K-1K Annually

Optum Logo Optum

HR Intern - Quezon City

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
Metro Manila, PHL
160000 Employees

Smartly Logo Smartly

Creative Onboarding Specialist

AdTech • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • Software • Generative AI
Easy Apply
Remote or Hybrid
Philippines
805 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account