Supplier Cybersecurity Controls Assessor

6 miesięcy temu


Warsaw, Polska JPMorgan Chase & Co. Pełny etat

You are passionate about Technology/ Cybersecurity and you understand industry risk frameworkrs, you found the right team.

As a Supplier Cybersecurity Controls Assessor within the Supplier Assurance Services team, you will be responsible for conducting comprehensive risk assessments of suppliers as part of JPMorgan Chase & Co.'s Corporate Third Party Oversight program. Your role will also involve supporting JPMorgan Chase & Co.’s Cybersecurity and Technology functions by developing and implementing controls and processes to enhance the security posture of our supply chain. As a part of the Global Supplier Services team, you will report directly to the Global Head of Corporate Third Party Oversight at JPMorgan Chase & Co. Your duties will include performing technology and cybersecurity control assessments of supplier environments, reviewing infrastructure, application stacks, and other technologies to ensure compliance with JPMorgan Chase & Co. Corporate Policies & Standards. You will be tasked with validating that technical risks are managed by Issue Owners at JPMorgan Chase & Co. and that security controls are fully implemented. You will collaborate with JPMorgan Chase & Co.’s Global Cybersecurity and Technology team and the various Lines of Business to focus on the latest cyber risks identified in the industry. As a member of the Supplier Assurance Services team, you will assess action plans and risk acceptances across business lines where technology standards’ compliance cannot be achieved.

Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks. Liaising with JPMC and supplier’s senior managers to communicate and influence best risk practices. Driving compliance to adhere to best risk management practices throughout the organizations.

Job responsibilities 

Manage all aspects of the control assessment of suppliers including assessing completed questionnaires and supporting field work materials to ensure they are complete and meet JPMC expectations. Lead the onsite / virtual assessment, providing the overall technology and cybersecurity risk and controls expertise. Identify and document control breaks and vulnerabilities within suppliers’ IT environments and work with the Line of Business (LOB) Delivery Manager and Information Security Manager to resolve through action plans or seek risk acceptance approvals. Identify opportunities for process improvements to deliver increased operational efficiency and opportunities for improving supplier posture including expanded monitoring, key risk indicator tracking, etc. Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness Escalate issues associated with suppliers as needed.

Required qualifications, capabilities, and skills

5+ years of experience in Technology, Technology Risk & Controls, Technology Audit, Cybersecurity, Application Security, Cloud Security (SaaS, PaaS & IaaS), Network, Security, Cyber Resiliency and Third Party Outsourcing Risk Management within a large enterprise level environment. Understanding of industry risk frameworks (ISO27001, NIST Cybersecurity Framework, Strong written and verbal presentation skills at the senior management level Experience debating issues with senior decision makers and pushing back when necessary

Preferred qualifications, capabilities, and skills 

CISSP, CISA, CISM, CCSP or CRISC certification is a plus

Work schedule: the role is based in Warsaw and it requires 3 days in the office presence.



  • Warsaw, Polska Pharmiweb Pełny etat

    As a leading global contract research organization (CRO) with a passion for scientific rigor and decades of clinical development experience, Fortrea provides pharmaceutical, biotechnology, and medical device customers a wide range of clinical development, patient access and technology solutions across more than 20 therapeutic areas. With over 19,000 staff...


  • Warsaw, Polska Danone Pełny etat

    Short Intro and About the Job You will join Danone IT & Data as a  Senior Manager Cybersecurity - Europe and your key responsibilities will be to: Develop and implement a strategic cybersecurity program for the European zone to future proof Danone Create a zone cybersecurity risk map (. identifying high risk countries, high risk user groups etc)...


  • Warsaw, Polska Fortrea Pełny etat

    As a leading global contract research organization (CRO) with a passion for scientific rigor and decades of clinical development experience, Fortrea provides pharmaceutical, biotechnology, and medical device customers a wide range of clinical development, patient access and technology solutions across more than 20 therapeutic areas. With over 19,000 staff...

  • Senior Analyst

    2 miesięcy temu


    Warsaw, Polska Pharmiweb Pełny etat

    As a leading global contract research organization (CRO) with a passion for scientific rigor and decades of clinical development experience, Fortrea provides pharmaceutical, biotechnology, and medical device customers a wide range of clinical development, patient access and technology solutions across more than 20 therapeutic areas. With over 19,000 staff...

  • Information Security Mgmt

    6 miesięcy temu


    Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    We know that people want great value combined with an excellent experience from a bank they can trust, so we launched our digital bank, Chase UK, to revolutionise mobile banking with seamless journeys that our customers love. We're already trusted by millions in the US and we're quickly catching up in the UK – but how we do things here is a little...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    We know that people want great value combined with an excellent experience from a bank they can trust, so we launched our digital bank, Chase, to revolutionize mobile banking with seamless journeys that our customers love. We're already trusted by millions in the US and we're quickly catching up in the United Kingdom – but how we do things here is a...


  • Warsaw, Polska IQVIA Pełny etat

    Job Overview IQVIA Connected Devices is a service that accelerates trial outcomes by streamlining the selection and deployment of medical devices to collect and analyze data. It provides customized solutions to accelerate clinical development and commercialization in such things as diabetes trials with enhanced glucose data collection, closer to the...


  • Warsaw, Polska L'Oréal Pełny etat

    As Cybersecurity Officer you will be responsable for: Governance: Lead the implementation of a comprehensive Cybersecurity program. Convey the L’Oréal Group Cybersecurity framework and adapt it when required to specific constraints. Animate regular meetings with IT director and domain managers. Risk Management / Security in Project: Identify,...

  • Senior Audit Specialist

    6 miesięcy temu


    Warsaw, Polska SAP Pełny etat

    Bring out your best SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services...

  • Senior Compliance Risk

    6 miesięcy temu


    Warsaw, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and join our newly established Cyber Risk Team in Warsaw! The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm’s reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while...


  • Warsaw, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and join our newly established Cyber Risk Team in Warsaw! The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm’s reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while...


  • Warsaw, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and join our newly established Cyber Risk Team in Warsaw! The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm’s reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while...

  • Senior Vulnerability Manager

    3 miesięcy temu


    Warsaw, Polska Baloise Solution Hub Pełny etat

    As a Senior Vulnerability Manager for Baloise Solution Hub, you are working with the Team based in Switzerland. We are seeking an experienced and strategic professional to lead our Cyber Defence team . Additional experience with threat intelligence is a plus. In this role, you will oversee the identification, analysis , and management ...

  • Procurement & Tax Specialist

    2 miesięcy temu


    Warsaw, Polska Porsche Polska Pełny etat

    TasksTasks Establishing and enforcing appropriate procurement methods Optimizing performance by providing operational procurement support to the organization Supporting special projects / controls and business departments in providing best in class services•Preparing and conducting monthly, quarterly and annual Porsche group reportings in the area...

  • Principal Security Engineer

    6 miesięcy temu


    Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    We know that people want great value combined with an excellent experience from a bank they can trust, so we launched our digital bank, Chase, to revolutionise mobile banking with seamless journeys that our customers love. We're already trusted by millions in the US and we're quickly catching up in the United Kingdom – but how we do things here is a...


  • Warsaw, Polska myGwork Pełny etat

    This job is with Johnson & Johnson, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Lead, Operational Technology Cybersecurity Engineering Johnson & Johnson is currently recruiting for a Senior Engineer Operational Technology Cyber Security within...


  • Warsaw, Polska Circle K Pełny etat

    JOB DESCRIPTION Job Description Circle K Business Centre is a shared service center which supports Circle K Europe operations through a wide range of services within Finance & Control, Information Technologies, Human Resources, Transport Fuel and Customer Service. Circle K is part of the Canadian company Alimentation Couche Tard Inc. (Couche-Tard), one...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...

  • Security Project Coordinator

    7 miesięcy temu


    Warsaw, Polska EG Norge AS Pełny etat

    We think that security can be an exciting journey. With constantly evolving threat landscape and new technologies around, our success depends on our creativity in identifying new ways of securing what matters most to us. If you like to: work smart be creative deliver results develop yourself act as team player and really enjoy cybersecurity ,...


  • Warsaw, Polska IQVIA Pełny etat

    The Associate Director: Attack Surface Reduction role presents a dynamic opportunity to ensure the secure operation of the IQVIA global information technology (IT) infrastructure and processes through developing and implementing new cybersecurity safeguards, amending and improving existing safeguards, as well as contributing to implementation of necessary...