Supplier Cybersecurity Assessor - Vice President

  • Warsaw, Poland
  • On-site
  • Full-time
  • Posted
No Polish required
Apply from
Not stated
Polish
Not required
English
Working language
Visa sponsorship
Not stated
Relocation support
Not stated
Salary
Not disclosed

Join a team that plays a critical role in protecting JPMorgan Chase and its clients from emerging cybersecurity threats. As part of Supplier Assurance Services, you will assess the cybersecurity posture of third-party suppliers, influence risk decisions, and help strengthen the firm's global supply chain. This is an opportunity to combine deep technical expertise with stakeholder engagement while driving meaningful risk outcomes.

As a Supplier Cybersecurity Assessor in Supplier Assurance Services, you will conduct cybersecurity and technology risk assessments of third-party suppliers and cloud-hosted environments to help safeguard the confidentiality, integrity, and availability of firm data and services. You will partner with internal and external stakeholders to evaluate cybersecurity controls, identify risks, and support remediation efforts. You will also help drive enhancements to assessment practices, including the responsible use of approved AI-enabled tools to improve efficiency, consistency, and risk insight

Job Responsibilities

  • Conduct cybersecurity and technology control assessments of supplier environments, including cloud-hosted services.
  • Review supplier security architectures, controls, processes, and supporting evidence.
  • Partner with internal and external stakeholders to evaluate control effectiveness and identify risk exposures.
  • Assess supplier adherence to cybersecurity industry standards and best practices.
  • Document assessment findings, risk impacts, and remediation recommendations.
  • Translate technical observations into clear business risk outcomes and recommendations.
  • Monitor emerging cyber threats and industry developments to strengthen assessment quality.
  • Drive continuous improvement initiatives across assessment methodologies, standards, and reporting.
  • Leverage approved AI-enabled tools to enhance assessment preparation, documentation, and analysis while maintaining appropriate oversight.
  • Support governance, escalation, and reporting activities related to supplier cybersecurity risks.

Required Qualifications, Capabilities, and Skills

  • Minimum of 7 - 9 years of experience in cybersecurity, technology risk, technology controls, technology audit, cloud security, supplier risk management, or related disciplines within a large enterprise environment.
  • Strong expertise in one or more cybersecurity domains, including cloud security, application security, infrastructure security, identity and access management, cyber resiliency, incident management, or data protection.
  • Strong understanding of industry security frameworks such as ISO 27001, ISO 27002, NIST Cybersecurity Framework, or equivalent standards.
  • Ability to assess technical controls and evaluate evidence to support risk-based conclusions.
  • Experience challenging assumptions, influencing stakeholders, and driving risk-based decisions.
  • Excellent written and verbal communication skills, including the ability to present technical topics to senior stakeholders.
  • Strong analytical and problem-solving capabilities with sound judgment and attention to detail.
  • Ability to manage multiple priorities in a fast-paced, highly regulated environment.
  • Experience using approved AI-enabled productivity tools while maintaining accountability for accuracy, validation, and risk outcomes.
  • CISSP, CISA, CISM, CCSP, or CRISC certification.

Preferred Qualifications, Capabilities, and Skills

  • Experience assessing public cloud environments, including AWS, Microsoft Azure, or Google Cloud Platform.
  • Cloud security or cloud architecture certifications.
  • Experience working within the financial services industry or another highly regulated industry.

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we’re setting our businesses, clients, customers and employees up for success.


Global Supplier Services (GSS) manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk assessments and evaluating the customer experience. Global teams support sourcing, third party oversight, procurement and payment operations, supplier relationship management and customer experience.

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.

  

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

More jobs from JPMorgan Chase

View company