This listing doesn't post a salary. Most similar roles pay
$159,750–$235,412.
Based on 240 similar postings.
Employer
About JPMorgan Chase
JPMorgan Chase & Co. is a global financial services firm and one of the largest banks in the world, offering investment banking, commercial banking, asset management, and consumer financial services.
JPMorgan Chase currently has
1138 open roles
on FindRole.
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director is a high-visibility role focused on managing risk across a complex vendor ecosystem. You will synthesize third-party risk signals regarding data protection, cybersecurity, and operational resilience into executive-ready narratives to inform decisions on risk acceptance and remediation. Daily responsibilities include performing quality assurance on assessments, identifying portfolio themes like concentration hot spots, and evaluating cloud and software-as-a-service architectures for risks such as identity management and encryption. You will interpret technical evidence including SOC 2 reports, ISO 27001 certifications, and SIG or CAIQ questionnaires to define risk thresholds and reporting frameworks. The role requires expertise in the third-party lifecycle, advanced knowledge of operational resilience practices, and the ability to translate complex technical findings into actionable business outcomes for senior stakeholders.
Translate technical vendor security evidence into clear risk narratives and actionable business recommendations.
Synthesize third-party risk signals regarding data protection, cybersecurity, and operational resilience into executive-ready insights.
Establish and govern standards for risk statements, materiality thresholds, and issue taxonomy across the third-party lifecycle.
Perform quality assurance and constructive challenge of assessment outputs to ensure consistency and defensibility.
Identify and escalate recurring control gaps and concentration risks across the entire vendor portfolio.
Evaluate cloud and SaaS architectures to identify risks related to identity management, encryption, and data residency.
Develop risk insights frameworks including key performance indicators, trend analysis, and executive reporting.
Advise on business cases for new third-party engagements by identifying opportunities for standardizing controls and contractual levers.
What we're looking for
8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a regulated industry.
Demonstrated experience across the third-party lifecycle including onboarding, assessment, monitoring, issue management, and exit.
Proven ability to synthesize assessment outputs into executive-ready insights, themes, and clear recommendations.
Strong cybersecurity and technology risk fluency to challenge vendor security posture using evidence like SOC 2 and ISO 27001.
Working knowledge of cloud and software-as-a-service control domains such as identity management, encryption, and vulnerability management.
Ability to translate technical risk into business decisions regarding trade-offs, materiality, and practical mitigation actions.
Experience defining and using key risk/key performance indicators, thresholds, and trend interpretation to drive visibility.
Strong stakeholder management skills to influence cross-functional partners and produce concise governance materials for senior stakeholders.
Experience building or running third-party risk portfolio reporting and governance routines (preferred).
Advanced knowledge of operational resilience practices (preferred).
Experience using automation, analytics, and/or AI-enabled approaches to improve monitoring and insights (preferred).
Strong executive presence and facilitation skills to drive alignment on remediation priorities (preferred).
Strong quantitative and narrative capability to combine metrics with storytelling for senior decision-makers (preferred).
Experience improving documentation and evidence standards for issue closure and audit-ready reporting (preferred).
Identity and Access Management
Continuous Control Monitoring
AI
Machine Learning
Data Analytics
Python
SQL
Power BI
Tableau
Alteryx
Cybersecurity
Risk Management
Governance
Automation
Reporting
SOX
ITGC