As a senior technical authority, you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier relationships. You will work alongside leaders ...
As a senior technical authority, you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier relationships. You will work alongside leaders ...
Cyber Strategy, Risk & Compliance - AI Engineering for Cybersecurity - Manager
Dallas, TX · On-site
$99K - $232K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Manager & Summary At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing ...
Cyber Strategy, Risk & Compliance - AI Engineering for Cybersecurity - Manager
Dallas, TX · On-site
$99K - $232K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Manager & Summary At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing ...
If yes, consider joining Baker Tilly (BT) as an Cybersecurity & IT Risk Director ! Our Risk ... Managing sales pursuits and the sales pipeline, helping the team in identifying, qualifying and ...
If yes, consider joining Baker Tilly (BT) as an Cybersecurity & IT Risk Director ! Our Risk ... Managing sales pursuits and the sales pipeline, helping the team in identifying, qualifying and ...
IT Audit, Cybersecurity & Risk Advisory Senior (HITRUST)
Frisco, TX · On-site
$84K - $115K/yr
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
IT Audit, Cybersecurity & Risk Advisory Senior (HITRUST)
Frisco, TX · On-site
$84K - $115K/yr
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
If yes, consider joining Baker Tilly (BT) as an Cybersecurity & IT Risk Director ! Our Risk ... Managing sales pursuits and the sales pipeline, helping the team in identifying, qualifying and ...
If yes, consider joining Baker Tilly (BT) as an Cybersecurity & IT Risk Director ! Our Risk ... Managing sales pursuits and the sales pipeline, helping the team in identifying, qualifying and ...
Sr. Risk Manager, Data Protection This position represents a unique opportunity for those with ... At least 5 years of experience in cybersecurity or enterprise data management * At least 3 years of ...
Sr. Risk Manager, Data Protection This position represents a unique opportunity for those with ... At least 5 years of experience in cybersecurity or enterprise data management * At least 3 years of ...
Senior Associate - Cyber Risk & Analysis, Technology Audit
Plano, TX · On-site
$77K - $95K/yr
Responsibilities: -Execute test procedures of critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management. -Perform risk ...
Senior Associate - Cyber Risk & Analysis, Technology Audit
Plano, TX · On-site
$77K - $95K/yr
Responsibilities: -Execute test procedures of critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management. -Perform risk ...
Execute major components of audits, including critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management, as well as the ...
Execute major components of audits, including critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management, as well as the ...
Responsibilities: -Execute test procedures of critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management. -Perform risk ...
Responsibilities: -Execute test procedures of critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management. -Perform risk ...
Execute major components of audits, including critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management, as well as the ...
Execute major components of audits, including critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management, as well as the ...
What you'll be doing Strategic Risk Leadership * Lead identification, articulation, and management of material cybersecurity risks across assigned business domains * Translate technical risks into ...
What you'll be doing Strategic Risk Leadership * Lead identification, articulation, and management of material cybersecurity risks across assigned business domains * Translate technical risks into ...
What you'll be doing Strategic Risk Leadership * Lead identification, articulation, and management of material cybersecurity risks across assigned business domains * Translate technical risks into ...
What you'll be doing Strategic Risk Leadership * Lead identification, articulation, and management of material cybersecurity risks across assigned business domains * Translate technical risks into ...
Oversee adherence to cybersecurity standards (e.g., NIST, CMMC as applicable) in the supply base ... Strong knowledge of third-party risk management, supplier risk, and operational resilience
Oversee adherence to cybersecurity standards (e.g., NIST, CMMC as applicable) in the supply base ... Strong knowledge of third-party risk management, supplier risk, and operational resilience
Your expertise will help drive improvements in our supplier risk posture and support the firm ... Proficiency in incident management, incident handling, investigations, and root cause analysis.
Your expertise will help drive improvements in our supplier risk posture and support the firm ... Proficiency in incident management, incident handling, investigations, and root cause analysis.
Lead or support cybersecurity risk assessments, IT internal audits, and regulatory readiness ... Provide guidance on security architecture, identity and access management (IAM), data protection ...
Lead or support cybersecurity risk assessments, IT internal audits, and regulatory readiness ... Provide guidance on security architecture, identity and access management (IAM), data protection ...
Own enterprise cybersecurity risk management: maintain a security risk register, drive prioritization, ensure remediation tracking, and provide executive-level risk reporting and metrics. * Direct ...
Own enterprise cybersecurity risk management: maintain a security risk register, drive prioritization, ensure remediation tracking, and provide executive-level risk reporting and metrics. * Direct ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
Own enterprise cybersecurity risk management: maintain a security risk register, drive prioritization, ensure remediation tracking, and provide executive-level risk reporting and metrics. * Direct ...
Own enterprise cybersecurity risk management: maintain a security risk register, drive prioritization, ensure remediation tracking, and provide executive-level risk reporting and metrics. * Direct ...
Cybersecurity strategy * Data governance and information management * Business continuity and disaster recovery * Facilitate HIPAA Security Risk Assessments and compliance readiness initiatives
Cybersecurity strategy * Data governance and information management * Business continuity and disaster recovery * Facilitate HIPAA Security Risk Assessments and compliance readiness initiatives
vCIO - Healthcare IT
Allen, TX · On-site
$100K - $120K/yr
Cybersecurity strategy * Data governance and information management * Business continuity and disaster recovery * Facilitate HIPAA Security Risk Assessments and compliance readiness initiatives
Quick apply
vCIO - Healthcare IT
Allen, TX · On-site
$100K - $120K/yr
Cybersecurity strategy * Data governance and information management * Business continuity and disaster recovery * Facilitate HIPAA Security Risk Assessments and compliance readiness initiatives
Cybersecurity Risk Management information
See Prosper, TX salary details
$52.2K - $62.9K
1% of jobs
$62.9K - $73.7K
4% of jobs
$73.7K - $84.4K
5% of jobs
$84.4K - $95.2K
9% of jobs
$101.1K is the 25th percentile. Wages below this are outliers.
$95.2K - $105.9K
11% of jobs
$105.9K - $116.6K
10% of jobs
The median wage is $120.8K / yr.
$116.6K - $127.4K
28% of jobs
$133.6K is the 75th percentile. Wages above this are outliers.
$127.4K - $138.1K
14% of jobs
$138.1K - $148.9K
11% of jobs
$148.9K - $159.6K
4% of jobs
$159.6K - $170.3K
4% of jobs
$52.2K
$121.8K
$170.3K
How much do cybersecurity risk management jobs pay per year?
What is the role of a risk manager in cybersecurity?
Is security risk management a good career?
What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?
What is cybersecurity risk management?
What is risk management in cyber security?
Can you make $500,000 a year in cyber security?
Full-time
Medical, Retirement
Posted 13 days ago
JPMorgan Chase & Co. rating
8.1
Based on 469 frontline employees who took The Breakroom Quiz
46th of 141 rated banks
Job description
This is a rare opportunity to operate at the intersection of deep technical cybersecurity expertise and enterprise-level risk strategy. As a senior technical authority, you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier relationships. You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm protects itself against emerging threats in an increasingly complex supplier landscape. If you are a cybersecurity leader who thrives on technical depth, credible challenge, and high-stakes decision-making, this role was built for you.
As an Executive Director at JPMorganChase within the Cybersecurity and Technology Controls Assessments and Exercises function, you will serve as the senior technical authority for third-party cybersecurity assurance, bringing deep hands-on expertise in cybersecurity architecture, cloud security, and enterprise control frameworks to critically evaluate the control maturity of the firm's most complex and strategically significant suppliers. Reporting to the Global Third-Party Assurance Lead, you will elevate the technical rigor, depth, and credibility of third-party assurance outcomes across the organization. You will translate complex technical findings into clear, business-relevant risk insights for senior stakeholders across Cybersecurity, Technology, Risk, and the Business. You will also act as a trusted escalation point for the most technically challenging assessments, ensuring the firm's third-party risk posture reflects the highest standards of technical scrutiny.
Job Responsibilities:
- Provide authoritative technical leadership across third-party cybersecurity assessments, bringing deep expertise in cybersecurity architecture, cloud-native and hybrid environments, application security, and enterprise control domains.
- Lead and personally conduct in-depth technical evaluations of supplier cybersecurity posture, control maturity, and architectural resilience, particularly for the firm's most critical and complex third-party relationships.
- Perform threat modelling against supplier environments to identify potential security risks and develop mitigation strategies tailored to the firm's risk appetite.
- Evaluate supplier security architectures across public cloud providers (AWS, Azure, Google Cloud), assessing the design and effectiveness of controls in cloud-native, hybrid, and on-premises environments.
- Act as the senior technical escalation point for complex supplier risks, control gaps, and remediation strategies, providing credible challenge and expert advisory input.
- Drive the evolution of the third-party assurance methodology by embedding deeper technical assessment capabilities, including architecture reviews, threat modelling, and cloud security posture evaluation.
- Translate complex technical cybersecurity risks and supplier control deficiencies into clear, actionable, business-relevant insights for senior leadership and non-technical audiences through detailed reports and presentations.
- Partner with Product Security, Cybersecurity Architecture, Technology Risk and Controls, and Cybersecurity pillar leads to ensure alignment in control intent, solution design, and third-party risk remediation.
- Lead thematic analysis to identify systemic technical weaknesses, emerging risks, and trends across the supplier landscape, and recommend strategic remediation approaches.
Required Qualifications, Capabilities, and Skills:
- 10 years of professional experience in cybersecurity, with demonstrated experience in senior technical or architecture-focused positions.
- Proven ability to assess and articulate the cybersecurity control maturity of complex technology environments, including enterprise, cloud-native, and hybrid architectures.
- Deep, hands-on expertise in cybersecurity architecture, threat modelling, and designing or evaluating secure controls for enterprise-level solutions.
- Strong understanding of industry cybersecurity frameworks and key control domains, including NIST CSF, ISO 27001, Federal Financial Institutions Examination Council (FFIEC) guidance, SOC 2, and GDPR.
- Thorough design and operational experience across one or more major public cloud providers, including AWS, Azure, or Google Cloud.
- Proficiency with Cloud Security Posture Management tools and cloud security assessment methodologies.
- Demonstrated ability to translate complex cybersecurity and technical findings into clear, business-relevant communications for audiences ranging from technical practitioners to executive and non-technical stakeholders.
Preferred Qualifications, Capabilities, and Skills:
- Relevant cloud or cybersecurity certifications such as CISSP, CCSP, or cloud provider certifications from AWS, Azure, or Google Cloud.
- Experience conducting cybersecurity assessments in support of strategic technology initiatives, such as blockchain, digital assets, or emerging technology platforms, including engagement at senior leadership forums.
- Demonstrated ability to influence and negotiate with external suppliers and internal senior stakeholders to drive remediation outcomes and control improvements without direct authority.
- Experience operating within or supporting a full lifecycle assessment model, with the ability to engage independently with suppliers and subject matter experts from an early stage while managing multiple concurrent assessments.
#CTC
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
What JPMorgan Chase & Co. employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About JPMorgan Chase & Co
Sourced by ZipRecruiter
Industry
Finance and insurance and banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
New York, NY, US