MyPage is a personalized page based on your interests.The page is customized to help you to find content that matters you the most.

I'm not curious

Global Supplier Services - Supplier Assurance Services (SAS) Information Risk Assessment Lead

Location Newark, United States
Posted 28-December-2018

JPMorgan Chase Co. (NYSE: JPM) is a leading global financial services
firm with assets of $2.6 trillion and operations worldwide. The firm
is a leader in investment banking, financial services for consumers
and small business, commercial banking, financial transaction
processing, and asset management. A component of the Dow Jones
Industrial Average, JPMorgan Chase Co. serves millions of consumers
in the United States and many of the worlds most prominent corporate,
institutional and government clients under its J.P. Morgan and Chase
brands. Information about JPMorgan Chase Co. is available at
*********************. The Corporate Third Party Oversight (CTPO) team
is responsible for developing, deploying, overseeing and ongoing
reporting of a program that drives the effective use of third parties
to accomplish JPMorgan Chases strategic goals. This includes building
awareness of the program at the firm and ensuring consistency globally
across both the Lines of Business (LOBs) and corporate groups. It also
includes understanding and dissemination of regulatory requirements
and reporting to regulators on the program and status. The major focus
of the program is to ensure our vendors are performing to the same
high standards that JPMorgan Chase holds itself accountable to
including client service, quality, control, regulatory compliance,
business resiliency and protection of information. The Supplier
Assurance Services (SAS) team is part of the JPMC Corporate Third
Party Oversight (CTPO) Program. The team provides IT risk management
oversight for third party service providers in accordance to JPMorgan
Chase (JPMC) Third Party Oversight (TPO) Standards. The SAS Shared
Service team supports all Lines of Businesses (LOBs), and regions
As a Supplier Assurance Services (SAS) Risk Assessment Lead, this
position is responsible for performing Risk Assessments of third
party s system and infrastructure technology to ensure they comply
with JPMC Corporate Policies Standards and technology risks are
managed. The firm-wide assessment team will partner with Lines of
Business to focus on firm-wide assessments of large technology service
providers. The Team is also responsible for assessing remediation
plans and non compliance acceptances across multiple business lines
where technology standards compliance cannot be achieved. This
* Identifying opportunities to improve third party risk posture,
developing creative solutions for mitigating risks.
* Liaising with JPMC and third party s senior managers to
communicate and influence best risk practices.
* Driving compliance to adhere to best risk management practices
throughout the organizations.
As a Supplier Assurance Services (SAS) Risk Assessment Lead within
this group your day to day responsibilities will be to develop and
execute firm-wide risk assessments of processes, products or programs,
with focus on consistency. This includes:
* Engage with multiple LOB Delivery Managers for firm-wide third
parties to ensure compliance with all required assessments per the
JPMC policy and procedures.
* Drive all aspects of the risk assessment of third party service
* Assess completed questionnaire and supporting field work materials
to ensure they are complete and meet JPMC expectations.
* Lead the onsite assessment, providing the overall IT Risk
* Identify control breaks and vulnerabilities with a third party.
* Document findings and work with the LOB Delivery Manager to
resolve those findings through Action Plans (APs) or seek Risk
Acceptance (RA) approvals.
* Validate evidence from third party, before Action Plans are
* Escalate issues associated with third parties as needed.
* Identify opportunities for process improvements to deliver
increasing operational efficiency in the processes.
* Identify opportunities for improving third party risk posture as
well as JPMCs third party risk management processes, including
expanded monitoring, KRI tracking, etc.
* Assist with various Third Party Risk Management program
initiatives working closely with the Third Party Risk Management
* Support internal education and best practices sharing with peers
and colleagues, as well as third party education awareness, as
* 7-10 years of experience in Business Information Technology within
a large enterprise level environment.
* 3-5 years of experience Risk Management, Technology Audit function
or Information Security Risk
* 5-7 years of work experience in one or more areas of
infrastructure (e.g. UNIX, Windows, mainframe), databases (e.g.
DB2, Oracle, SQL Server) and networks is required.
* Complete understanding of IT control policies.
* Experience debating issues with senior decision makers and pushing
back when necessary.
* Strong written and verbal presentation skills at the senior
management level across various business groups
* CISSP, CISM/CISA or CRISC certification is a plus.
* ability to travel at least 25% of the time

Awards & Accolades for MyTechLogy
Winner of
Top 100 Asia
Finalist at SiTF Awards 2014 under the category Best Social & Community Product
Finalist at HR Vendor of the Year 2015 Awards under the category Best Learning Management System
Finalist at HR Vendor of the Year 2015 Awards under the category Best Talent Management Software
Hidden Image Url