Information Risk Lead - Vice President

JPMorgan Chase & Co.

Experience
Company Type
Qualifications
Workhours
POSITION SUMMARY:
 

The Supplier Assurance Services organization is part of the JPMC Global Supplier Services (GSS) / Corporate Third Party Oversight (CTPO) organization. The SAS team provides IT risk management oversight on third party service providers in accordance to JPMorgan Chase (JPMC) Third Party Oversight (TPO) Standards and Global Technology Standards.  The SAS Shared Service team supports number of Line of Businesses (LOBs), including Mortgage Banking (MB), Corporate Sector Functions and Technology (CS) and Consumer & Business Banking (CBB), Corporate & Investment Bank (CIB) and Asset Management (AM).

 
As the Third Party Information Risk Manager, your primary responsibility will be to manage a portfolio of third party risk assessments and to provide Third Party Oversight support to the LOBs.  You will play a lead role in engaging and leading business areas that use the third parties to assess the risk of the engagements.
 
PRIMARY DUTIES AND RESPONSIBILITIES:
 
  • Engage with LOB Delivery Managers to ensure compliance with all required assessments per the JPMC policy and procedures.
  • Drive all aspects of the risk assessment of third party providers. 
  • Engage and lead Line of Businesses (LOBs) that use the third party in lesser risked engagements and incorporate the other LOBs assessment criteria into the assessment.
  • Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
  • Lead the onsite assessment, providing the overall IT Risk expertise.
  • Identify control breaks and vulnerabilities with a third party.
  • Document findings and work with the LOB Delivery Manager to resolve those findings through Remediation Plans (RPs) or seek Non-Compliance Acceptance (NCA) approvals.
  • Escalate issues associated with third parties as needed
  • Manage the Shared Service Quality Assurance team and work with the global assessor teams to ensure that the remediation plans (RP)/ non compliance acceptances (NCA) are reviewed and feedback is provided to the assessors
  • To have the finalized RPs / NCAs appropriately included / updated in risk systems and metrices
  • To ensure that the relevant and sufficient evidence are reviewed for the purose of closure of any RPs / NCAs and regular reporting of open RPs and NCAs
  • Validate evidence from third party, before Remediation Plans are closed
  • Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
  • Identify opportunities for improving third party risk posture as well as JPMC’s third party risk management processes, including expanded monitoring, KRI tracking, etc.
  • Assist with various Third Party Risk Management program initiatives working closely with the Third Party Risk Management Leads.
  • Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness, as needed
QUALIFICATIONS:
 
  • Should have 12+ years of experience in IT
  • 5+ years of experience in IT Risk management, audit or equivalent
  • Proficient technical skills, including: audit, business analysis, change management, IT Risk Management,  operation systems and data sources knowledge, performance metrics and reporting, technical problem resolution, project management, and vendor management.
  • Proficient working knowledge within the following risk domains/technologies:
    • Database and application security
    • IDS/IPS technologies
    • System/Access Administration
    • Firewall technologies
    • Network Architecture 
    • Security Event Logging & Monitoring 
    • Key Management/Tokenization
    • Database/Application/Network Layer Secure Protocols
    • Physical and Environmental Security 
    • Secure Software/Code Development
    • Change Management
    • Vulnerability Management
  • Proficient verbal and written communication skills, including the ability to effectively lead discussions and meeting
  • Proficient risk assessment, interpretation, analytical and negotiation skills.
  • Excellent organizational skills
  • IT Risk Management/Audit industry certification (such as CISSP, CISA,CRISC, etc.) required
  • Masters degree preferred, Bachelors degree required or equivalent technical experience

Project Assurance

      • Resiliency
      • Security Configuration
      • Technology Asset Management
      • Application security
        • Security features review
        • Threat modelling and Security Architectural reviews
        • Dynamic code / Blackbox scanning vs Static code / Whitebox scanning
        • Defects Management
        • Vulnerability Management
        • Penetration testing
        • Source code management
    • Secure Software/Code Development

·         Proficient verbal and written communication skills, including the ability to effectively lead discussions and meeting

·         Proficient risk assessment, interpretation, analytical and negotiation skills.

·         Excellent organizational skills

·         IT Risk Management/Audit industry certification (such as CISSP, CISA,CRISC, etc.) required

·         Masters degree preferred, Bachelors degree required or equivalent technical experience

·         Knowledge of tools like Fortify, Veracode desirable

Read Full DescriptionHide Full Description
Confirmed 7 hours ago. Posted 30+ days ago.

Discover Similar Jobs

Suggested Articles

One Step Register
Need an account? Sign Up