JPMorgan Chase & Co. (NYSE: JPM) is a leading global financial services firm with assets of $2.6 trillion and operations worldwide. The firm is a leader in investment banking, financial services for consumers and small business, commercial banking, financial transaction processing, and asset management. A component of the Dow Jones Industrial Average, JPMorgan Chase & Co. serves millions of consumers in the United States and many of the world's most prominent corporate, institutional and government clients under its J.P. Morgan and Chase brands. Information about JPMorgan Chase & Co. is available at www.jpmorganchase.com.
Third Party Risk Management (TPRM) Shared Service team is part of the Global Supplier Services Team. The team provides IT risk management oversight on third party service providers in accordance to JPMorgan Chase (JPMC) Third Party Oversight (TPO) Standards. The TPRM Shared Service team supports a number of Line of Businesses (LOBs), including GTI (Global Technology Infrastructure), Mortgage Banking (MB), Corporate Technology (CT), Consumer & Business Banking (CBB), Corporate and Investment Banking (CIB) and Asset Management (AM).
As a Third Party Risk Assessment Lead, this position is responsible to ensure the Risk Assessments of third party’s system and infrastructure technology is performed to ensure they comply with JPMC Corporate Policies & Standards and technology risks are managed. The Shared Services assessment team will partner with Delivery Managers, Lines of Business TCO and TPO to ensure compliance to the JPMC TPRM policy and standards.
The Team is also responsible for assessing remediation plans and noncompliance acceptances across AM Third Parties where technology standards’ compliance cannot be achieved. This includes:
- Identifying opportunities to improve third party risk posture, developing creative solutions for mitigating risks.
- Liaising with JPMC and third party’s senior managers to communicate and influence best risk practices.
- Driving compliance to adhere to best risk management practices throughout the organizations.
As a Third Party Risk Assessment Lead within this group your day to day responsibilities will be to develop a schedule and execute risk assessments of processes, products or programs, with focus on consistency. This includes:
- Engage with LOB Delivery Managers for the third parties to ensure compliance with all required assessments per the JPMC policy and procedures.
- Drive all aspects of the risk assessment of third party service providers.
- Assess completed questionnaire and supporting field work materials to ensure they are complete and meet JPMC expectations.
- Lead the onsite assessment, providing the overall IT Risk expertise.
- Identify control breaks and vulnerabilities with a third party.
- Document findings and work with the LOB Delivery Manager to resolve those findings through Remediation Plans (RPs) or seek Non-Compliance Acceptance (NCA) approvals.
- Validate evidence from third party, before Remediation Plans are closed.
- Escalate issues associated with third parties as needed.
- Identify opportunities for process improvements to deliver increasing operational efficiency in the processes.
- Identify opportunities for improving third party risk posture as well as JPMC's third party risk management processes, including expanded monitoring, KRI tracking, etc.
- Assist with various Third Party Risk Management program initiatives working closely with the AM Third Party Risk Management Lead.
- Assist AM Third Party Risk Management Lead in scheduling, maintaining the AM Third Party Risk Assessment calendar, maintaining the data updates on various internal tools and systems; monitor, track process compliance through MIS, metrics.
- Support internal education and best practices sharing with peers and colleagues, as well as third party education & awareness, as needed
- 7-10 years of experience in Business Information Technology within a large enterprise level environment.
- 3-5 years of experience Risk Management, Technology Audit function or Information Security Risk
- Work experience in one or more areas of infrastructure (e.g. UNIX, Windows, and mainframe), databases (e.g. DB2, Oracle, SQL Server) and networks is preferred.
- Complete understanding of IT control policies.
- Experience debating issues with senior decision makers and pushing back when necessary.
- Strong written and verbal presentation skills at the senior management level across various business groups
- CISSP, CISM/CISA or CRISC certification is a plus.