Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Execu
Help shape how we make confident, well-governed decisions about third-party risk across a large, complex vendor ecosystem.
You'll turn technical assessment outputs into clear, executive-ready insights that protect clients, data, and operations.
In this role, you will influence how we identify emerging risk patterns, prioritize remediation, and set consistent control expectations.
You'll partner across risk, technology, legal, procurement, and compliance in a highly visible role with meaningful impact.
As an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank, you will synthesize, challenge, and communicate key risks and control considerations across the third-party lifecycle (onboarding, change, ongoing monitoring, and exit).
You will ensure risk conclusions and decision artifacts are consistent, defensible, and aligned to agreed standards, thresholds, and risk appetite.
You will translate vendor security evidence into clear risk narratives, business impact, and actionable recommendations.
You will help leaders make informed decisions on risk acceptance, remediation prioritization, and safe vendor adoption.
Job responsibilities
* Aggregate and analyze third-party risk signals with a focus on data protection, cybersecurity, and operational resilience, translating findings into business process impacts and operational risk outcomes.
* Set and govern standards for risk statements, residual risk framing, materiality thresholds, issue taxonomy, and escalation expectations across the third-party lifecycle.
* Own quality assurance and constructive challenge of third-party assessment and monitoring outputs to ensure completeness, consistency, and defensibility of conclusions and remediation expectations.
* Identify and elevate themes across the third-party portfolio (recurring control gaps, common failure modes, concentration hot spots) through appropriate governance forums.
* Produce decision-grade materials that clearly articulate residual risk, recommended mitigations, and defined decision points tailored to business criticality.
* Review and advise on business cases for new or expanded third-party engagements, including opportunities to reuse existing vendors and standardize controls or contractual levers.
* Interpret vendor security evidence (for example, SOC 2 reports, ISO 27001 certification, and industry questionnaires such as Standardized Information Gathering (SIG) and the Consensus Assessments Initiative Questionnaire (CAIQ)) and convert it into clear risk narratives and control gap assessments.
* Evaluate cloud and software-as-a-service architectures to identify material risks (identity and access management, encryption/key management, logging/monitoring, segmentation, data residency, dependency chains, and concentration risk).
* Define and maintain a risk insights framework, including risk taxonomy mapping, key risk/key performance indicators,...
- Rate: Not Specified
- Location: New York, US-NY
- Type: Permanent
- Industry: Finance
- Recruiter: JPMorgan Chase Bank, N.A.
- Contact: Not Specified
- Email: to view click here
- Reference: 210788264
- Posted: 2026-09-11 11:03:56 -
- View all Jobs from JPMorgan Chase Bank, N.A.
More Jobs from JPMorgan Chase Bank, N.A.
- Lagermitarbeiter / Lagerhelfer in Teilzeit Spätdienst (m/w/d)
- Strategic Planning Lead
- ADMINISTRATIVE ASSISTANT
- Senior Project Engineer
- Postbote / Zusteller für Pakete und Briefe (m/w/d)
- Postbote / Zusteller für Pakete und Briefe (m/w/d)
- Forward Deployed Engineer
- Learning and Development Manager
- Account Manager - Corrugated
- Electrical Field Superintendent
- Production Supervisor-Mailers
- SAP Integration Lead
- Postbote für Pakete und Briefe (m/w/d)
- Fall 2026 - Buyer Co-op
- 2nd Shift Electrical Technician
- Multi Craft Maintenance Technician
- Machinist
- Operations Technician
- Electrical Maintenance Technician
- Environmental Engineering Intern