You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm ...
You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm ...
You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm ...
You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm ...
Cybersecurity Compliance Analyst - Third Party Compliance (Hybrid - Houston, TX)
Houston, TX · On-site
$30 - $32/hr
The Cybersecurity Compliance Analyst will apply a risk-based approach to security assessment ... Support third party compliance evaluations and risk assessments. Contribute to the evidence-based ...
Quick apply
Cybersecurity Compliance Analyst - Third Party Compliance (Hybrid - Houston, TX)
Houston, TX · On-site
$30 - $32/hr
The Cybersecurity Compliance Analyst will apply a risk-based approach to security assessment ... Support third party compliance evaluations and risk assessments. Contribute to the evidence-based ...
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
Cybersecurity Risk Analyst
Houston, TX · On-site
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
Cybersecurity Risk Analyst
Houston, TX · On-site
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities : Cybersecurity Risk ...
Cybersecurity Manager
The Woodlands, TX · On-site
$140K - $160K/yr
The Cybersecurity Manager leads the organization's cybersecurity, risk, and compliance program ... This role oversees GRC, HIPAA compliance, third-party risk management, and security operations ...
Cybersecurity Manager
The Woodlands, TX · On-site
$140K - $160K/yr
The Cybersecurity Manager leads the organization's cybersecurity, risk, and compliance program ... This role oversees GRC, HIPAA compliance, third-party risk management, and security operations ...
CYBERSECURITY RISK ANALYST
Houston, TX · On-site +1
Job Summary The Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing ... Ensure compliance with security regulations (e.g., GDPR, CCPA, PCI DSS) and manage third-party ...
CYBERSECURITY RISK ANALYST
Houston, TX · On-site +1
Job Summary The Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing ... Ensure compliance with security regulations (e.g., GDPR, CCPA, PCI DSS) and manage third-party ...
Senior Program Manager - Cybersecurity Risk Management
Spring, TX · Hybrid
$130K - $205K/yr
The role includes partnering with teams within our supply chain organization and third-party partners to review business operations, identify areas of cybersecurity risk, and drive the implementation ...
Senior Program Manager - Cybersecurity Risk Management
Spring, TX · Hybrid
$130K - $205K/yr
The role includes partnering with teams within our supply chain organization and third-party partners to review business operations, identify areas of cybersecurity risk, and drive the implementation ...
Senior Program Manager - Cybersecurity Risk Management
Spring, TX · On-site
$130K - $205K/yr
The role includes partnering with teams within our supply chain organization and third-party partners to review business operations, identify areas of cybersecurity risk, and drive the implementation ...
Senior Program Manager - Cybersecurity Risk Management
Spring, TX · On-site
$130K - $205K/yr
The role includes partnering with teams within our supply chain organization and third-party partners to review business operations, identify areas of cybersecurity risk, and drive the implementation ...
Cybersecurity Risk Analyst
Irving, TX · On-site
Why GMF Cybersecurity? Innovation isn't just a talking point at GM Financial, it's how we operate ... Perform third party risk assessments * Partner with Application Custodians to perform application ...
Cybersecurity Risk Analyst
Irving, TX · On-site
Why GMF Cybersecurity? Innovation isn't just a talking point at GM Financial, it's how we operate ... Perform third party risk assessments * Partner with Application Custodians to perform application ...
Cybersecurity Risk Analyst
Irving, TX · Hybrid
Why GMF Cybersecurity? Innovation isn't just a talking point at GM Financial, it's how we operate ... Perform third party risk assessments * Partner with Application Custodians to perform application ...
Cybersecurity Risk Analyst
Irving, TX · Hybrid
Why GMF Cybersecurity? Innovation isn't just a talking point at GM Financial, it's how we operate ... Perform third party risk assessments * Partner with Application Custodians to perform application ...
Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. * Define risk-based tiering, minimum security requirements, and ...
Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. * Define risk-based tiering, minimum security requirements, and ...
Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. * Define risk-based tiering, minimum security requirements, and ...
Lead third-party and supply-chain cybersecurity risk governance, including vendor onboarding, assessments, and ongoing oversight. * Define risk-based tiering, minimum security requirements, and ...
Support third-party risk management processes, including vendor risk assessments and ongoing monitoring. * Collaborate with cybersecurity and technology teams to align security tooling, monitoring ...
Support third-party risk management processes, including vendor risk assessments and ongoing monitoring. * Collaborate with cybersecurity and technology teams to align security tooling, monitoring ...
Support third-party risk management processes, including vendor risk assessments and ongoing monitoring. * Collaborate with cybersecurity and technology teams to align security tooling, monitoring ...
Support third-party risk management processes, including vendor risk assessments and ongoing monitoring. * Collaborate with cybersecurity and technology teams to align security tooling, monitoring ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational Risk Department (ORD), a Second Line of Defense (2LoD) function. Operational Risk refers to the risk ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational Risk Department (ORD), a Second Line of Defense (2LoD) function. Operational Risk refers to the risk ...
Cybersecurity Engineer
Dallas, TX · On-site
Cybersecurity Risk Management * Perform cybersecurity risk assessments for medical device systems ... third-party libraries. * Prepare vulnerability mitigation plans and support development teams ...
Quick apply
Cybersecurity Engineer
Dallas, TX · On-site
Cybersecurity Risk Management * Perform cybersecurity risk assessments for medical device systems ... third-party libraries. * Prepare vulnerability mitigation plans and support development teams ...
Vendor Cybersecurity Auditor Location: Austin, Texas (onsite and telework - must live locally ... third-party risk - ideal for someone who thrives in detail-driven environments, values evidence ...
Vendor Cybersecurity Auditor Location: Austin, Texas (onsite and telework - must live locally ... third-party risk - ideal for someone who thrives in detail-driven environments, values evidence ...
Cyber Security Risk Treatment Senior Associate
Coppell, TX · Hybrid
$93K - $119K/yr
... a third day unique to each team or employee). The Impact you will have in this role ... Partner with Cyber Security Risk Office stakeholders to ensure consistent application of risk ...
Cyber Security Risk Treatment Senior Associate
Coppell, TX · Hybrid
$93K - $119K/yr
... a third day unique to each team or employee). The Impact you will have in this role ... Partner with Cyber Security Risk Office stakeholders to ensure consistent application of risk ...
Third Party Cybersecurity Risk information
What is the difference between Third Party Cybersecurity Risk vs Cybersecurity Analyst?
| Aspect | Third Party Cybersecurity Risk | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CompTIA Security+, CEH |
| Work Environment | Vendor assessments, risk management teams, client organizations | Security operations centers, IT departments, consulting firms |
| Industry Usage | Supply chain, vendor management, compliance | Network security, incident response, vulnerability assessment |
Third Party Cybersecurity Risk professionals focus on evaluating and managing risks from external vendors and partners, ensuring compliance and reducing supply chain vulnerabilities. Cybersecurity Analysts primarily monitor, analyze, and respond to security threats within an organization’s own systems. While both roles require security certifications and involve risk assessment, their focus areas and work environments differ significantly.
Full-time
Medical, Retirement
Posted 13 days ago
JPMorgan Chase & Co. rating
8.1
Based on 469 frontline employees who took The Breakroom Quiz
46th of 141 rated banks
Job description
This is a rare opportunity to operate at the intersection of deep technical cybersecurity expertise and enterprise-level risk strategy. As a senior technical authority, you will shape how the firm evaluates and manages cybersecurity risk across its most strategically significant supplier relationships. You will work alongside leaders across Cybersecurity, Technology, and Risk to drive meaningful improvements in third-party assurance outcomes. Your expertise will directly influence how the firm protects itself against emerging threats in an increasingly complex supplier landscape. If you are a cybersecurity leader who thrives on technical depth, credible challenge, and high-stakes decision-making, this role was built for you.
As an Executive Director at JPMorganChase within the Cybersecurity and Technology Controls Assessments and Exercises function, you will serve as the senior technical authority for third-party cybersecurity assurance, bringing deep hands-on expertise in cybersecurity architecture, cloud security, and enterprise control frameworks to critically evaluate the control maturity of the firm's most complex and strategically significant suppliers. Reporting to the Global Third-Party Assurance Lead, you will elevate the technical rigor, depth, and credibility of third-party assurance outcomes across the organization. You will translate complex technical findings into clear, business-relevant risk insights for senior stakeholders across Cybersecurity, Technology, Risk, and the Business. You will also act as a trusted escalation point for the most technically challenging assessments, ensuring the firm's third-party risk posture reflects the highest standards of technical scrutiny.
Job Responsibilities:
- Provide authoritative technical leadership across third-party cybersecurity assessments, bringing deep expertise in cybersecurity architecture, cloud-native and hybrid environments, application security, and enterprise control domains.
- Lead and personally conduct in-depth technical evaluations of supplier cybersecurity posture, control maturity, and architectural resilience, particularly for the firm's most critical and complex third-party relationships.
- Perform threat modelling against supplier environments to identify potential security risks and develop mitigation strategies tailored to the firm's risk appetite.
- Evaluate supplier security architectures across public cloud providers (AWS, Azure, Google Cloud), assessing the design and effectiveness of controls in cloud-native, hybrid, and on-premises environments.
- Act as the senior technical escalation point for complex supplier risks, control gaps, and remediation strategies, providing credible challenge and expert advisory input.
- Drive the evolution of the third-party assurance methodology by embedding deeper technical assessment capabilities, including architecture reviews, threat modelling, and cloud security posture evaluation.
- Translate complex technical cybersecurity risks and supplier control deficiencies into clear, actionable, business-relevant insights for senior leadership and non-technical audiences through detailed reports and presentations.
- Partner with Product Security, Cybersecurity Architecture, Technology Risk and Controls, and Cybersecurity pillar leads to ensure alignment in control intent, solution design, and third-party risk remediation.
- Lead thematic analysis to identify systemic technical weaknesses, emerging risks, and trends across the supplier landscape, and recommend strategic remediation approaches.
Required Qualifications, Capabilities, and Skills:
- 10 years of professional experience in cybersecurity, with demonstrated experience in senior technical or architecture-focused positions.
- Proven ability to assess and articulate the cybersecurity control maturity of complex technology environments, including enterprise, cloud-native, and hybrid architectures.
- Deep, hands-on expertise in cybersecurity architecture, threat modelling, and designing or evaluating secure controls for enterprise-level solutions.
- Strong understanding of industry cybersecurity frameworks and key control domains, including NIST CSF, ISO 27001, Federal Financial Institutions Examination Council (FFIEC) guidance, SOC 2, and GDPR.
- Thorough design and operational experience across one or more major public cloud providers, including AWS, Azure, or Google Cloud.
- Proficiency with Cloud Security Posture Management tools and cloud security assessment methodologies.
- Demonstrated ability to translate complex cybersecurity and technical findings into clear, business-relevant communications for audiences ranging from technical practitioners to executive and non-technical stakeholders.
Preferred Qualifications, Capabilities, and Skills:
- Relevant cloud or cybersecurity certifications such as CISSP, CCSP, or cloud provider certifications from AWS, Azure, or Google Cloud.
- Experience conducting cybersecurity assessments in support of strategic technology initiatives, such as blockchain, digital assets, or emerging technology platforms, including engagement at senior leadership forums.
- Demonstrated ability to influence and negotiate with external suppliers and internal senior stakeholders to drive remediation outcomes and control improvements without direct authority.
- Experience operating within or supporting a full lifecycle assessment model, with the ability to engage independently with suppliers and subject matter experts from an early stage while managing multiple concurrent assessments.
#CTC
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
What JPMorgan Chase & Co. employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About JPMorgan Chase & Co
Sourced by ZipRecruiter
Industry
Finance and insurance and banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
New York, NY, US