Search jobs > Columbus, OH > Third cybersecurity

Assessments & Exercises - Third-Party Cybersecurity Assessment Architect

JPMorgan Chase & Co.
Columbus, OH, United States
Full-time

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.

As an Assessments & Exercises Vice President in Cybersecurity and Technology Controls organization, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology.

Design and deploy risk-driven tests and simulations (or manage a highly-skilled team that does) and inform analysis to clearly outline root-causes.

In this role, evaluate preventative controls, incident response processes, and detection capabilities, and advise cross-functional teams on security strategy and risk management.

In this role you will help to assess the health and security of JPMC’s Third-Party suppliers, identifying risks and gaps in their control maturity.

You will evaluate suppliers’ infrastructure, application and control environments providing transparency into the cyber resilience, recoverability and operational / data risks associated with key relationships.

This role involves a high-degree of stakeholder engagement, suiting an individual with excellent leadership skills who is able to navigate complex organizations and build relationships across Business and Technology teams.

As part of our global team of technologists and innovators, your work will have a critical impact on our company, as well as our clients and our business partners around the world.

Successful candidates will help to shape the future of Third-Party cybersecurity assessments for JPMC.

Job responsibilities

  • Design and execute testing and simulations such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm’s strategy and compliance with regulatory requirements
  • Evaluate supplier compliance with cybersecurity standards and exposure to industry risks, provide insights into corrective actions and mitigations that will help to strengthen cyber resilience.
  • Assess supplier controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
  • Collaborate closely with cross-functional teams to conduct detailed evaluations and develop comprehensive assessment reports of security controls and practices including detailed findings, risk assessments, and remediation recommendations making data-driven decisions that utilize continuous improvement.
  • Provide guidance and advice to Business, Technology and Third-Party supplier groups on cybersecurity best practices
  • Support development of supplier risk metrics to articulate the efficacy of suppliers security arrangements
  • Participate in thematic analysis, identifying trends / common issues in supplier security posture
  • Partner with Product Security, Tech Risk & Controls and Risk Pillar leads to raise awareness and drive improvements in Third-Party control implementations
  • Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations.

Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics

Required qualifications, capabilities, and skills

  • 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of control delivery, security testing, assessments, or simulation exercises
  • Deep understanding of key cybersecurity principles and control implementations that mitigate common threat actor techniques (Email, Network, Endpoint, Resiliency & Recovery (incl.

response plans), Monitoring, End User Awareness, Vulnerability Management, and / or Identity and Access Management)

  • Process engineering and re-engineering skills.
  • Ability to clearly translate and communicate cyber risk via written, verbal and presentation formats to a variety of stakeholders in Cyber, Technology and the Business
  • Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
  • Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (.

Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents

  • Highly Analytical, tenacious and inquisitive mindset
  • Self-starter with drive to deliver results and continuous improvement mindset
  • Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels

Preferred qualifications, capabilities, and skills

  • Hold relevant industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Offensive Security Certified Professional (OSCP) showcasing advanced expertise in cybersecurity and offensive testing methodologies or resiliency
  • Knowledge / experience in modern programming language
  • Background in Product Security, Incident Response, Technology / Cyber Audit
  • 30+ days ago
Related jobs
JPMorgan Chase & Co.
Columbus, Ohio

The Cyber security and Technology controls Adoption Readiness Assessment team manages planning and execution of technology platform assessments as well as ensure readiness and remediation across all applicable technology platforms at the bank. Lead the execution of multiple controls adoption readine...

JPMorgan Chase & Co.
Columbus, Ohio

The Cyber security and Technology Controls Adoption Readiness Assessment team manages planning and execution of technology platform assessments as well as ensure readiness and remediation across all applicable technology platforms at the bank. The associate role involves managing technology platform...

JPMorgan Chase & Co.
Columbus, Ohio

As an Assessments & Exercises Vice President in Cyber and Tech Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities...

Promoted
System One
Columbus, Ohio

We are seeking a detail-oriented and proactive IT Business Operations Analyst for a 6-month contract position based in Columbus, OH. ...

Promoted
D Aceto Services LLC
Columbus, Ohio

D Aceto Services LLC is seeking a motivated and detail-oriented Entry-Level Data Analyst to join our team. Help maintain data integrity and accuracy within databases. In this remote position, you will work closely with various departments to analyze data, generate insights, and support decision-maki...

Promoted
NSC Technologies
Columbus, Ohio

DoD 8570 Compliant for CSSP Analyst: Obtain a CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, PenTest+, or SCYBER certification within 6 months of start date. Job Title: Cyber Security Analyst. Conducts cyber threat intelligence analysis, develops correlation techniques, c...

Promoted
Gifthealth
Columbus, Ohio

Data Analyst - This Role is Hybrid in Columbus, OH. BS in Statistics, Mathematics, Economics or comparable quantitative field and relevant work experience as a Data Analyst. Consistently introduce strong, data-driven business and technical judgment to the decision process. Develop and maintain docum...

Promoted
ODW Logistics
Columbus, Ohio

Analyst, Business Analytics will use data analytics and technology to provide insight and information to the operators and decision-makers within ODW. Aids in identifying areas of the business that can be optimized. Designs technical queries Creates and updates business intelligence reporting and vi...

Promoted
Leidos Inc
Whitehall, Ohio

The Leidos Digital Modernization sector is continuously looking for cleared Cyber Security Analysts who are interested in joining the DISA GSM-O II program in Columbus, OH. In this position, you will be joining a team providing 24x7 cybersecurity monitoring services for Department of Defense network...

Promoted
Leidos Holding
Columbus, Ohio

The selected candidate will provide support for Security Analysts and will be expected to actively engage with personnel, partner with them, anticipate their needs, and deliver innovating solutions to challenging defensive cybersecurity issues. Leidos has a current job opportunity for a Cyber Securi...