Help strengthen security outcomes across a global supplier ecosystem. In this role, you will influence risk decisions by turning complex evidence into clear control insights. You will partner with stakeholders to drive practical remediation and continuous improvement. You will help evolve assessment approaches to improve consistency, efficiency, and impact.
Job summary
As a Supplier Cybersecurity Controls Assessor Vice President in Supplier Assurance Services, you will lead technology and cybersecurity control assessments of supplier environments to help manage third-party risk. You will evaluate evidence, document control gaps, and collaborate with stakeholders to drive remediation plans or support risk acceptance decisions when needed. You will communicate clearly with senior stakeholders and help improve assessment approaches over time.
Job responsibilities
- Review supplier assessment questionnaires and supporting evidence to confirm completeness and quality
- Lead on-site or virtual supplier assessments and facilitate assessment discussions
- Assess supplier infrastructure, applications, and security practices against defined control expectations
- Identify, document, and communicate control gaps and vulnerabilities in supplier environments
- Partner with stakeholders to develop remediation action plans and track progress to closure
- Evaluate risk acceptance requests when control compliance cannot be achieved and document rationale
- Recommend practical risk mitigation options that improve supplier security posture
- Identify process improvement opportunities that increase assessment efficiency and consistency
- Support education and knowledge sharing on supplier cybersecurity risk and controls
- Escalate significant supplier issues in a timely manner through appropriate channels
Required qualifications, capabilities and skills
- 7 years of experience in technology risk and controls, technology audit, cybersecurity, or third-party risk management within a large enterprise environment
- Experience performing technology and cybersecurity control assessments of third parties or external suppliers
- Working knowledge of industry risk and control frameworks (e.g., ISO 27001, NIST Cybersecurity Framework)
- Experience assessing one or more of the following domains: application security, cloud security (SaaS, PaaS, IaaS), network security, or cyber resiliency
- Demonstrated ability to identify control gaps, document findings, and translate technical issues into clear risk statements
- Experience developing or evaluating remediation action plans and validating control implementation
- Strong written communication skills, including concise reporting and stakeholder-ready summaries
- Strong verbal communication and presentation skills with senior stakeholders
- Demonstrated ability to challenge and influence decisions appropriately, including constructive pushback when needed
Preferred qualifications, capabilities and skills
- One or more current certifications: CISSP, CISA, CISM, CCSP, or CRISC
- Experience interpreting third-party assurance artifacts (e.g., SOC 2 reports, ISO 27001 certification evidence, ISAE 3402 Type II reports) to assess control design and operating effectiveness
- Ability to translate technical control issues into business impact, clear risk statements, and crisp remediation recommendations for senior stakeholders
- Working knowledge of common AI failure modes—including hallucinations, overconfidence, bias, and data contamination—and the ability to recognize how they can degrade document extraction and classification results
Internal Application Eligibility Requirements
TENURE:
• Must meet minimum employment tenure requirement. Specific roles require longer tenure in current position to be eligible to apply. Unless established for specific positions by the line of business, the standard tenure requirement is 12 months.
PERFORMANCE:
• Meets satisfactory performance standards as defined by the firm
You affirm that you meet the Internal Application Eligibility Requirements. This includes checking or declaring potential conflict of interest as stipulated in the Employment of Relatives and Employees in Personal Relationships Policy.
By submitting an application and/or joining the interview, you affirm to meet the Internal Mobility Eligibility Requirements as stated in the Applying for Internal Positions Firmwide Standard. You are expected to provide true and accurate information to the Company during the recruitment and application process. Knowingly giving false or misleading information shall be subjected to the imposition of appropriate corrective action, following the firm's Human Resource (HR) Policies and Guidelines.
Consult your Manager for any specific guidelines for your line of business or if you're unsure about your eligibility for an internal application.
Make sure your profile is updated in the new me@jpmc > Hiring and discuss internal mobility plans with your Manager at the soonest time possible. Attaching your updated resume is encouraged.
In partnership, Hiring Managers and Recruiters will review applications to determine which candidates best meet the required skills and experience specified in the job description. While not every application will result in an interview, applications will be acknowledged.