About this role
Join a team that plays a critical role in protecting JPMorgan Chase and its clients from emerging cybersecurity threats. As part of Supplier Assurance Services, you will assess the cybersecurity posture of third-party suppliers, influence risk decisions, and help strengthen the firm's global supply chain. This is an opportunity to combine deep technical expertise with stakeholder engagement while driving meaningful risk outcomes.
As a Supplier Cybersecurity Assessor in Supplier Assurance Services , you will conduct cybersecurity and technology risk assessments of third-party suppliers and cloud-hosted environments to help safeguard the confidentiality, integrity, and availability of firm data and services. You will partner with internal and external stakeholders to evaluate cybersecurity controls, identify risks, and support remediation efforts. You will also help drive enhancements to assessment practices, including the responsible use of approved AI-enabled tools to improve efficiency, consistency, and risk insight
Job Responsibilities
- Conduct cybersecurity and technology control assessments of supplier environments, including cloud-hosted services.
- Review supplier security architectures, controls, processes, and supporting evidence.
- Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures.
- Assess supplier adherence to cybersecurity industry standards and best practices.
- Document assessment findings, risk impacts, and remediation recommendations.
- Translate technical observations into clear business risk outcomes and recommendations.
- Monitor emerging cyber threats and industry developments to strengthen assessment quality.
- Drive continuous improvement initiatives across assessment methodologies, standards, and reporting.
- Leverage approved AI-enabled tools to enhance assessment preparation, documentation, and analysis while maintaining appropriate oversight.
- Support governance, escalation, and reporting activities related to supplier cybersecurity risks.
Required Qualifications, Capabilities, and Skills
- Minimum of 7 - 9 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines within a large enterprise environment.
- Strong expertise in one or more cybersecurity domains, including cloud security, application security, infrastructure security, identity and access management, cyber resiliency, incident management, or data protection.
- Strong understanding of industry security frameworks such as ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent standards.
- Ability to assess technical controls and evaluate evidence to support risk-based conclusions.
- Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions.
- Excellent written and verbal communication skills, including the ability to present technical topics to senior stakeholders.
- Strong analytical and problem-solving capabilities with sound judgment and attention to detail.
- Ability to manage multiple priorities in a fast-paced, highly regulated environment.
- Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes.
- CISSP, CISA, CISM, CCSP, or CRISC certification.
Preferred Qualifications, Capabilities, and Skills
- Experience assessing public cloud environments, including AWS, Microsoft Azure, or Google Cloud Platform.
- Cloud security or cloud architecture certifications.
- Experience working within the financial services industry or another highly regulated industry.