JP Morgan Chase & Co.

Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director

JP Morgan Chase & Co.$180K — $220K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in control management, operational risk, technology risk, or cybersecurity risk in the financial services sector or similar industry.
  • Demonstrated knowledge of the third-party lifecycle, including onboarding, assessment, monitoring, and exit.
  • Ability to translate complex risk assessments into clear, actionable executive insights.
  • Strong background in cybersecurity, including challenging vendor security postures using SOC 2 and ISO 27001 evidence.
  • Familiarity with cloud and software-as-a-service control areas such as identity and access management and encryption.
  • Experience in defining and interpreting key risk and performance indicators for effective risk visibility and prioritization.
  • Strong stakeholder management and communication skills, especially with senior stakeholders.

Responsibilities

  • Aggregate and analyze third-party risk signals focusing on data protection, cybersecurity, and operational resilience.
  • Set and govern standards for risk statements and escalation expectations throughout the third-party lifecycle.
  • Ensure quality assurance of third-party assessments for consistency and defensibility of conclusions.
  • Identify and elevate recurring themes or issues within the third-party portfolio to governance forums.
  • Produce decision-grade materials presenting risks and recommendations clearly tailored to business needs.
  • Review business cases for third-party engagements, advocating for efficiencies and standard controls.
  • Interpret vendor security evidence and translate it into clear risk narratives for stakeholder understanding.
  • Evaluate risks related to cloud and software-as-a-service architectures, focusing on critical factors like access management and encryption.

Benefits

  • Opportunity to influence vendor risk management in a dynamic financial environment.
  • High visibility role with meaningful impact across various corporate functions.
  • Collaborative work environment with cross-functional partnerships.
  • Access to advanced tools and strategies for monitoring and improving risk processes.
  • Professional development and opportunities for career advancement.
Full Job Description
JOB DESCRIPTION

Help shape how we make confident, well-governed decisions about third-party risk across a large, complex vendor ecosystem. You’ll turn technical assessment outputs into clear, executive-ready insights that protect clients, data, and operations. In this role, you will influence how we identify emerging risk patterns, prioritize remediation, and set consistent control expectations. You’ll partner across risk, technology, legal, procurement, and compliance in a highly visible role with meaningful impact.

As an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank, you will synthesize, challenge, and communicate key risks and control considerations across the third-party lifecycle (onboarding, change, ongoing monitoring, and exit). You will ensure risk conclusions and decision artifacts are consistent, defensible, and aligned to agreed standards, thresholds, and risk appetite. You will translate vendor security evidence into clear risk narratives, business impact, and actionable recommendations. You will help leaders make informed decisions on risk acceptance, remediation prioritization, and safe vendor adoption.

Job responsibilities
  • Aggregate and analyze third-party risk signals with a focus on data protection, cybersecurity, and operational resilience, translating findings into business process impacts and operational risk outcomes.
  • Set and govern standards for risk statements, residual risk framing, materiality thresholds, issue taxonomy, and escalation expectations across the third-party lifecycle.
  • Own quality assurance and constructive challenge of third-party assessment and monitoring outputs to ensure completeness, consistency, and defensibility of conclusions and remediation expectations.
  • Identify and elevate themes across the third-party portfolio (recurring control gaps, common failure modes, concentration hot spots) through appropriate governance forums.
  • Produce decision-grade materials that clearly articulate residual risk, recommended mitigations, and defined decision points tailored to business criticality.
  • Review and advise on business cases for new or expanded third-party engagements, including opportunities to reuse existing vendors and standardize controls or contractual levers.
  • Interpret vendor security evidence (for example, SOC 2 reports, ISO 27001 certification, and industry questionnaires such as Standardized Information Gathering (SIG) and the Consensus Assessments Initiative Questionnaire (CAIQ)) and convert it into clear risk narratives and control gap assessments.
  • Evaluate cloud and software-as-a-service architectures to identify material risks (identity and access management, encryption/key management, logging/monitoring, segmentation, data residency, dependency chains, and concentration risk).
  • Define and maintain a risk insights framework, including risk taxonomy mapping, key risk/key performance indicators, thresholds, trends, and executive-ready reporting.
  • Drive consistency in issue management by setting expectations for classification, documentation quality, evidence standards for closure, and transparent reporting of overdue actions and residual risk.
  • Partner and influence across control management, technology, procurement, legal, compliance, and operational risk to maintain a single, consistent narrative and improve decision usefulness.
Required qualifications, capabilities and skills
  • 8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a similarly regulated industry.
  • Demonstrated experience across the third-party lifecycle (onboarding, assessment, monitoring, issue management, and exit).
  • Proven ability to synthesize assessment outputs into executive-ready insights, including themes, emerging risks, residual risk framing, and clear recommendations.
  • Strong cybersecurity and technology risk fluency, including the ability to challenge vendor security posture using evidence such as SOC 2 and ISO 27001.
  • Working knowledge of cloud and software-as-a-service control domains (identity and access management, encryption, logging/monitoring, vulnerability management, incident response, and secure development controls).
  • Ability to translate technical risk into business decisions, including trade-offs, materiality, and practical mitigation actions.
  • Experience defining and using key risk/key performance indicators, thresholds, and trend interpretation to drive risk visibility and prioritization.
  • Strong stakeholder management skills, with the ability to influence cross-functional partners and challenge constructively when outputs are not decision-useful.
  • Excellent written and verbal communication skills, including producing concise governance materials for senior stakeholders.
Preferred qualifications, capabilities and skills
  • Experience building or running third-party risk portfolio reporting and governance routines, including taxonomy design, thresholds, and thematic reporting.
  • Advanced knowledge of operational resilience practices (service mapping concepts, recovery expectations, dependency analysis, and vendor failure-mode translation).
  • Experience using automation, analytics, and/or AI-enabled approaches to improve monitoring, signal detection, and insights generation (subject to approved tools and controls).
  • Strong executive presence and facilitation skills to drive alignment on remediation priorities, timelines, and risk acceptance decisions.
  • Strong quantitative and narrative capability to combine metrics with clear storytelling for senior decision-makers.
  • Experience improving documentation and evidence standards for issue closure and audit-ready reporting.

About JP Morgan Chase & Co.

JP Morgan Chase & Co. stands at the forefront of the global financial services industry. They offer an expansive array of products and services to a diverse clientele, including individuals, corporations, governments, and institutions. Ever since the merger of J.P. Morgan & Co. and Chase Manhattan Corporation in 2000, this industry-leading entity has become renowned for its comprehensive portfolio encompassing consumer and community banking, corporate and investment banking, commercial banking, as well as asset and wealth management. Headquartered in the vibrant city of New York, JP Morgan Chase & Co. boasts a formidable presence across over 100 countries worldwide.

Unveiling Employment Opportunities at JP Morgan Chase & Co.

Vacancies and Hiring Initiatives

JP Morgan Chase & Co. is continuously on the lookout for talented individuals eager to contribute to its legacy of excellence. The company's recruitment efforts are geared towards identifying candidates with the right blend of skills and qualifications to drive forward its various business segments. Whether you are a seasoned professional or a recent graduate, JP Morgan Chase offers a plethora of job openings across multiple disciplines.

High-Demand Positions

Among the myriad of roles, certain positions stand out for their attractive compensation packages and career advancement prospects. Notably, high-paying jobs at JP Morgan Chase & Co. include Relationship Manager, Branch Manager, and Software Engineer. These roles are critical to the firm's operations and offer lucrative opportunities for those with the requisite expertise.

Navigating the Job Market at JP Morgan Chase & Co.

Leveraging Job Portals and Job Alerts

For job seekers aiming to tap into the opportunities at JP Morgan Chase, staying updated through job portals and subscribing to job alerts is crucial. These tools can provide timely information about job openings, job fairs, and recruitment events, enabling candidates to apply promptly and prepare adequately for interviews.

Preparing Your Job Application

Your job application, comprising your resume and cover letter, is your ticket to securing an interview at JP Morgan Chase. Highlight your qualifications, skills, and experiences that align with the job listing, ensuring you stand out in the competitive job market.

Acing the Interview

Preparation is key to succeeding in your interview with JP Morgan Chase. Familiarize yourself with the company's business segments, values, and recent achievements. Demonstrating how your background and aspirations match the company's goals can significantly increase your chances of employment. A World of Job Opportunites in the Financial Services Industry JP Morgan Chase & Co. offers a world of job opportunities for those seeking to make their mark in the financial services industry. With competitive salaries, comprehensive benefits, and endless possibilities for growth, positions at JP Morgan Chase are highly coveted. By staying informed through job sites, tailoring your applications, and preparing thoroughly for interviews, you can enhance your prospects of joining the esteemed ranks of JP Morgan Chase employees. Explore the job board, seize the job opportunities, and embark on a rewarding career journey with one of the world's leading financial institutions.
Learn more about JP Morgan Chase & Co.
Size
661 employees
Market Cap
$384.5 billion
Industry
Net Income
$29.1 billion
Founded
1823
5 Year Trend
+0.7%
Revenue
$261.5 million
NASDAQ

Similar Jobs

More Jobs at JP Morgan Chase & Co.

More Finance & Insurance Jobs

Find similar Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director jobs: