Join a team that plays a critical role in protecting JPMorgan Chase and its clients from emerging cybersecurity threats. As part of Supplier Assurance Services, you will assess the cybersecurity posture of third-party suppliers, influence risk decisions, and help strengthen the firm's global supply chain. This is an opportunity to combine deep technical expertise with stakeholder engagement while driving meaningful risk outcomes.
As a Supplier Cybersecurity Assessor in Supplier Assurance Services, you will conduct cybersecurity and technology risk assessments of third-party suppliers and cloud-hosted environments to help safeguard the confidentiality, integrity, and availability of firm data and services. You will partner with internal and external stakeholders to evaluate cybersecurity controls, identify risks, and support remediation efforts. You will also help drive enhancements to assessment practices, including the responsible use of approved AI-enabled tools to improve efficiency, consistency, and risk insight
Job Responsibilities
- Conduct cybersecurity and technology control assessments of supplier environments, including cloud-hosted services.
- Review supplier security architectures, controls, processes, and supporting evidence.
- Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures.
- Assess supplier adherence to cybersecurity industry standards and best practices.
- Document assessment findings, risk impacts, and remediation recommendations.
- Translate technical observations into clear business risk outcomes and recommendations.
- Monitor emerging cyber threats and industry developments to strengthen assessment quality.
- Drive continuous improvement initiatives across assessment methodologies, standards, and reporting.
- Leverage approved AI-enabled tools to enhance assessment preparation, documentation, and analysis while maintaining appropriate oversight.
- Support governance, escalation, and reporting activities related to supplier cybersecurity risks.
Required Qualifications, Capabilities, and Skills
- Minimum of 7 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines within a large enterprise environment.
- Strong expertise in one or more cybersecurity domains, including cloud security, application security, infrastructure security, identity and access management, cyber resiliency, incident management, or data protection.
- Strong understanding of industry security frameworks such as ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent standards.
- Ability to assess technical controls and evaluate evidence to support risk-based conclusions.
- Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions.
- Excellent written and verbal communication skills, including the ability to present technical topics to senior stakeholders.
- Strong analytical and problem-solving capabilities with sound judgment and attention to detail.
- Ability to manage multiple priorities in a fast-paced, highly regulated environment.
- Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes.
- CISSP, CISA, CISM, CCSP, or CRISC certification.
Preferred Qualifications, Capabilities, and Skills
- Experience assessing public cloud environments, including AWS, Microsoft Azure, or Google Cloud Platform.
- Cloud security or cloud architecture certifications.
- Experience working within the financial services industry or another highly regulated industry.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
JPMorganChase San Francisco, California, USA Office
San Francisco, CA, United States
Similar Jobs
What you need to know about the San Francisco Tech Scene
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine



