Bring your expertise to JPMorgan Chase, a global leader in financial services committed to innovation, integrity, and making a positive impact.
As part of our Third Party Application Security (TPAS) program within Corporate Third Party Oversight (CTPO), you’ll be at the heart of our mission to keep the firm’s supply chain strong and resilient.
Here, you’ll help anticipate and address new and emerging risks in third party software, cloud environments, and AI systems—using your skills to solve real-world challenges that affect our company, partners, and communities.
As a Third Party Application Security Associate within the Third Party Application Security (TPAS) program, you’ll play a pivotal role in protecting JPMorgan Chase’s supply chain.
You’ll lead efforts to monitor and strengthen third party applications by assessing Software Bill of Materials (SBOMs), Artificial Intelligence Bill of Materials (AI BOMs), and cloud security controls.
In this fast-paced environment, you’ll engage directly with suppliers, analyze risk data, and track remediation efforts.
You’ll collaborate with stakeholders across Lines of Business, Technology, Cybersecurity, and Cloud Engineering to streamline security assessments and validate controls—making a tangible impact on the security and resilience of our organization.
Job Responsibilities
Drive the transformation agenda, including business justification and program build out.Partner with internal risk teams to support business as usual risk activities, reporting and project initiatives.Ensure risk impacting the business is effectively identified, quantified, communicated and remediatedInfluence supplier adoption of the product vision, roadmap, and risk control objectivesOperationalize the Third Party Software Bill of Materials (SBOM) programRequired qualifications, capabilities and skills
Strong leadership skills, ability to multitask, sense of ownership, attention to detail and quality, and deliver on commitmentsUnderstanding of Secure Software Development Life Cycle (SSDLC) (., coding requirements, risk assessments, threat modeling, static code analysis, and dynamic application scanning)3+ years of experience in Third Party Risk Management (TPRM) or Governance, Risk Management, and Compliance (GRC), Cybersecurity, Application Security, Cloud Security Architecture (SaaS, PaaS & IaaS) within a large enterprise level environment3+ years of experience using a broad set of technologies (., servers, operating systems, applications, databases, hypervisors, virtualization management, containers, compute, storage, Bachelor’s degree in a relevant disciplineProficiency with Microsoft applications (., Word, Excel, Outlook, Visio, OneNote, SharePoint, Teams, Preferred qualifications, capabilities and skills
Certification in Public Cloud Technology from major Cloud Service Provider Experience with Software Bill of Materials (SBOM) CISSP, CISA, CISM, CCSP or CRISC certification