Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director

JPMorgan Chase

Confirmed live today High trust

Quick summary

Work type
On-site
Location
New York, NY
Posted
4 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $198k
$151k most similar roles pay here $244k

This listing doesn't post a salary. Most similar roles pay $159,750–$235,412.

Based on 240 similar postings.

Employer

About JPMorgan Chase

JPMorgan Chase & Co. is a global financial services firm and one of the largest banks in the world, offering investment banking, commercial banking, asset management, and consumer financial services.

JPMorgan Chase currently has 1138 open roles on FindRole.

Most-posted roles

View all roles at JPMorgan Chase

At a glance

TL;DR · Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director

Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director is a high-visibility role focused on managing risk across a complex vendor ecosystem. You will synthesize third-party risk signals regarding data protection, cybersecurity, and operational resilience into executive-ready narratives to inform decisions on risk acceptance and remediation. Daily responsibilities include performing quality assurance on assessments, identifying portfolio themes like concentration hot spots, and evaluating cloud and software-as-a-service architectures for risks such as identity management and encryption. You will interpret technical evidence including SOC 2 reports, ISO 27001 certifications, and SIG or CAIQ questionnaires to define risk thresholds and reporting frameworks. The role requires expertise in the third-party lifecycle, advanced knowledge of operational resilience practices, and the ability to translate complex technical findings into actionable business outcomes for senior stakeholders.

What you'll do

  • Translate technical vendor security evidence into clear risk narratives and actionable business recommendations.
  • Synthesize third-party risk signals regarding data protection, cybersecurity, and operational resilience into executive-ready insights.
  • Establish and govern standards for risk statements, materiality thresholds, and issue taxonomy across the third-party lifecycle.
  • Perform quality assurance and constructive challenge of assessment outputs to ensure consistency and defensibility.
  • Identify and escalate recurring control gaps and concentration risks across the entire vendor portfolio.
  • Evaluate cloud and SaaS architectures to identify risks related to identity management, encryption, and data residency.
  • Develop risk insights frameworks including key performance indicators, trend analysis, and executive reporting.
  • Advise on business cases for new third-party engagements by identifying opportunities for standardizing controls and contractual levers.

What we're looking for

  • 8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a regulated industry.
  • Demonstrated experience across the third-party lifecycle including onboarding, assessment, monitoring, issue management, and exit.
  • Proven ability to synthesize assessment outputs into executive-ready insights, themes, and clear recommendations.
  • Strong cybersecurity and technology risk fluency to challenge vendor security posture using evidence like SOC 2 and ISO 27001.
  • Working knowledge of cloud and software-as-a-service control domains such as identity management, encryption, and vulnerability management.
  • Ability to translate technical risk into business decisions regarding trade-offs, materiality, and practical mitigation actions.
  • Experience defining and using key risk/key performance indicators, thresholds, and trend interpretation to drive visibility.
  • Strong stakeholder management skills to influence cross-functional partners and produce concise governance materials for senior stakeholders.
  • Experience building or running third-party risk portfolio reporting and governance routines (preferred).
  • Advanced knowledge of operational resilience practices (preferred).
  • Experience using automation, analytics, and/or AI-enabled approaches to improve monitoring and insights (preferred).
  • Strong executive presence and facilitation skills to drive alignment on remediation priorities (preferred).
  • Strong quantitative and narrative capability to combine metrics with storytelling for senior decision-makers (preferred).
  • Experience improving documentation and evidence standards for issue closure and audit-ready reporting (preferred).

More like this

Similar roles

Director, Risk Management: Cyber & Third Party Risk

Capital One Financial

McLean, VA +2 4 days ago $209,500$239,100
Third Party Risk Management Information Security Cloud Computing Risk Assessment Enterprise Risk Management CISSP CISM CISA PMP Lean Agile Six Sigma
7+ yrs exp

Senior Risk Specialist, Compliance Governance Analyst

Capital One Financial

McLean, VA +1 5 days ago $96,500$110,100
Risk Management Compliance Management Program Data Analysis Tableau Google Workspace Gemini NotebookLM AI Tools Process Management Project Management Audit Reporting Dashboard Governance Quality Assurance Change Management
3+ yrs exp

Tech Risk & Controls Lead, Continuous Controls Monitoring

JPMorgan Chase

Plano, TX 3 days ago
Identity and Access Management Continuous Control Monitoring AI Machine Learning Data Analytics Python SQL Power BI Tableau Alteryx Cybersecurity Risk Management Governance Automation Reporting SOX ITGC
5+ yrs exp

Control Manager Vice President

JPMorgan Chase

OH 3 days ago
Risk Management Control Frameworks Data Analytics Automation Agile Change Management Regulatory Compliance Audit Quality Assurance Governance Knowledge Management Business Transformation
7+ yrs exp

Control Manager Vice President

JPMorgan Chase

Wilmington, DE 4 days ago
Risk Management Control Frameworks Data Analytics Automation Machine Learning Root Cause Analysis Audit Compliance Cybersecurity Quality Assurance Issue Management Reporting Operational Risk Management
7+ yrs exp