JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $2.5 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small business, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world's most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com .
J.P. Morgan is a place for talented people from all backgrounds and perspectives because our clients come from all backgrounds and perspectives. We encourage a culture of inclusion, where everyone's opinion counts and all employees have the freedom to deliver their absolute best. This is why we work hard and invest in attracting and developing a diverse workforce. Learn more about our Business Resource Groups in how they help our employees build successful careers and reach their greatest potential.
The Third Party Operations and Controls (TPOC) team is responsible for developing, deploying, overseeing and ongoing reporting of a program that drives the effective use of suppliers to accomplish JPMorgan Chase's strategic goals. This includes building awareness of the program at the firm and ensuring consistency globally across both the Lines of Business (LOBs) and corporate groups. It also includes understanding and dissemination of regulatory requirements and reporting to regulators on the program and status. The major focus of the program is to ensure our vendors are performing to the same high standards that JPMorgan Chase holds itself accountable to including client service, quality, control, regulatory compliance, business resiliency and protection of information.
The Supplier Assurance Services (SAS) team is part of the JPMC Third Party Operations and Controls (TPOC) Organization. The team provides risk management oversight for suppliers in accordance to JPMorgan Chase (JPMC) Third Party Oversight (TPO) Standards. The SAS team supports all Lines of Businesses (LOBs), and regions globally.
As the Supplier Assurance Services (SAS) Risk Manager, your primary responsibility will be to manage a portfolio of third party risk assessments and to provide Third Party Oversight support to the LOBs. You will play a lead role in engaging and leading business areas that use the third parties to assess the risk of the engagements.
PRIMARY DUTIES AND RESPONSIBILITIES:
Engage with LOB Delivery Managers to ensure compliance with all required assessments per the JPMC policy and procedures.
Drive all aspects of the risk assessment of third party providers.
Engage and lead Line of Businesses (LOBs) that use the third party in lesser risked engagements and incorporate the other LOBs assessment criteria into the assessment.
Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
Lead the onsite assessment, providing the overall IT Risk expertise.
Identify control breaks and vulnerabilities with a third party.
Document findings and work with the LOB Delivery Manager to resolve those findings through Remediation Plans (RPs) or seek Non-Compliance Acceptance (NCA) approvals.
Escalate issues associated with third parties as needed
Manage the Shared Service Quality Assurance team and work with the global assessor teams to ensure that the remediation plans (RP)/ non compliance acceptances (NCA) are reviewed and feedback is provided to the assessors
To have the finalized RPs / NCAs appropriately included / updated in risk systems and metrices
To ensure that the relevant and sufficient evidence are reviewed for the purpose of closure of any RPs / NCAs and regular reporting of open RPs and NCAs
Validate evidence from third party, before Remediation Plans are closed.
Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
Identify opportunities for improving third party risk posture as well as JPMC's third party risk management processes, including expanded monitoring, KRI tracking, etc.
Assist with various Third Party Risk Management program initiatives working closely with the Third Party Risk Management Leads.
Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness, as needed
Support Emerging Technology assessment team by partnering with Line of Business stakeholders and our Technology Control partners to assess Emerging and Financial Technology (FinTech) suppliers to introduce new and emerging technology to the firm. Provide consultative expertise to assist suppliers to mitigate risk for Emerging and Financial Technology (FinTech) suppliers.
Mandarin Language mandatory
Should have 12+ years of experience in IT
5+ years of experience in IT Risk management, audit or equivalent
Proficient technical skills, including: audit, business analysis, change management, IT Risk Management, operation systems and data sources knowledge, performance metrics and reporting, technical problem resolution, project management, and vendor management.
Proficient working knowledge within the following risk domains/technologies: o Database and application security o IDS/IPS technologies o System/Access Administration o Firewall technologies o Network Architecture o Security Event Logging & Monitoring o Key Management/Tokenization o Database/Application/Network Layer Secure Protocols o Physical and Environmental Security o Secure Software/Code Development o Change Management o Vulnerability Management o Cloud Architecture & Technology o Emerging and Financial Technology (FinTech)
Proficient verbal and written communication skills, including the ability to effectively lead discussions and meeting
Proficient risk assessment, interpretation, analytical and negotiation skills.
Excellent organizational skills
IT Risk Management/Audit industry certification (such as CISSP, CISA,CRISC, etc.) required