Assessments & Exercises Director - Third Party Assurance

JPMorganChase

Bournemouth

On-site

GBP 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

J.P. Morgan in the United Kingdom is seeking an Executive Director to lead third‑party cybersecurity assurance within the Cybersecurity and Technology Controls (CTC) Assessments & Exercises function.

You will serve as the senior technical authority on control maturity for the firm's most complex suppliers. You will translate technical findings into business risk insights for senior stakeholders, drive methodological improvements, and collaborate with cross‑functional leads to ensure alignment of

Qualifications

  • 10+ years of professional experience in cybersecurity, with senior technical or architecture-focused roles.
  • Ability to assess and articulate the cybersecurity control maturity of complex environments (enterprise, cloud-native, hybrid).
  • Deep hands-on expertise in cybersecurity architecture, threat modelling, and secure controls design for enterprise solutions.
  • Strong understanding of industry frameworks and control domains (NIST CSF, ISO 27001, FFIEC, SOC 2, GDPR).
  • Experience across major cloud providers (AWS, Azure, Google Cloud) with relevant certifications advantageous.
  • Proficiency with CSPM tools and cloud security assessment methodologies.

Responsibilities

  • Provide authoritative technical leadership across third-party cybersecurity assessments.
  • Lead and conduct in-depth evaluations of supplier cybersecurity posture and architectural resilience.
  • Perform threat modelling against supplier environments and develop mitigation strategies.
  • Evaluate supplier cloud architectures across AWS, Azure, and Google Cloud.
  • Act as senior technical escalation point for complex supplier risks and remediation strategies.
  • Drive evolution of third-party assurance methodology with deeper technical assessment capabilities.
  • Translate technical risks into clear risk insights for senior leadership.
  • Collaborate with Product Security and Cybersecurity teams to align controls and remediation.
  • Lead thematic analysis to identify systemic weaknesses and remediation approaches.

Skills

Cybersecurity architecture
Cloud security
Threat modelling
Enterprise controls
NIST CSF ISO 27001 GDPR
Public cloud (AWS Azure GCP)
CSPM tools
Technical leadership

Job description

Job Summary

As an Executive Director within the Cybersecurity and Technology Controls (CTC) Assessments & Exercises function, you will serve as the senior technical authority for third‑party cybersecurity assurance. You will bring deep, hands‑on expertise in cybersecurity architecture, cloud security, and enterprise control frameworks to critically evaluate the control maturity of the firm's most complex and strategically significant suppliers.

Job Description

As an Executive Director within the Cybersecurity and Technology Controls (CTC) Assessments & Exercises function, you will serve as the senior technical authority for third‑party cybersecurity assurance. You will bring deep, hands‑on expertise in cybersecurity architecture, cloud security, and enterprise control frameworks to critically evaluate the control maturity of the firm's most complex and strategically significant suppliers. Reporting to the Global Third‑Party Assurance Lead, you help to elevate the technical rigor, depth, and credibility of third‑party assurance outcomes. You will translate complex technical findings into clear, business‑relevant risk insights for senior stakeholders across Cybersecurity, Technology, Risk, and the Business, and will act as a trusted escalation point for the most technically challenging assessments.

Job Responsibilities
  • Provide authoritative technical leadership across third‑party cybersecurity assessments, bringing deep expertise in cybersecurity architecture, cloud‑native and hybrid environments, application security, and enterprise control domains.
  • Lead and personally conduct in‑depth technical evaluations of supplier cybersecurity posture, control maturity, and architectural resilience, particularly for the firm's most critical and complex third‑party relationships.
  • Perform threat modelling against supplier environments to identify potential security risks and develop mitigation strategies tailored to the firm's risk appetite.
  • Evaluate supplier security architectures across public cloud providers (AWS, Azure, Google Cloud), assessing the design and effectiveness of controls in cloud‑native, hybrid, and on‑premises environments.
  • Act as the senior technical escalation point for complex supplier risks, control gaps, and remediation strategies, providing credible challenge and expert advisory input.
  • Drive the evolution of the third‑party assurance methodology by embedding deeper technical assessment capabilities, including architecture reviews, threat modelling, and cloud security posture evaluation.
  • Translate complex technical cybersecurity risks and supplier control deficiencies into clear, actionable, business‑relevant insights for senior leadership and non‑technical audiences through detailed reports, presentations, and other appropriate methods.
  • Partner with Product Security, Cybersecurity Architecture, Technology Risk & Controls, and Cybersecurity pillar leads to ensure alignment in control intent, solution design, and third‑party risk remediation.
  • Lead thematic analysis to identify systemic technical weaknesses, emerging risks, and trends across the supplier landscape, and recommend strategic remediation approaches.
Required Qualifications, Capabilities, And Skills
  • 10+ years of professional experience in cybersecurity, with significant depth in senior technical and/or architecture‑focused positions.
  • Proven ability to assess and articulate the cybersecurity control maturity of complex technology environments, including enterprise, cloud‑native, and hybrid architectures.
  • Deep, hands‑on expertise in cybersecurity architecture, threat modelling, and designing or evaluating secure controls for enterprise‑level solutions.
  • Strong understanding of industry cybersecurity frameworks and key control domains (e.g., NIST CSF, ISO 27001, FFIEC, SOC 2, GDPR).
  • Thorough design and operational experience across one or more major public cloud providers (AWS, Azure, Google Cloud), with relevant certifications advantageous.
  • Proficiency with Cloud Security Posture Management (CSPM) tools and cloud security assessment methodologies.
ABOUT US

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world's most prominent corporations, governments, wealthy individuals and institutional investors. Our first‑class business in a first‑class way approach to serving clients drives everything we do. We strive to build trusted, long‑term partnerships to help our clients achieve their business objectives.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

About The Team

The Cybersecurity & Technology Controls group at JPMorganChase aligns the firm's cybersecurity, access management, controls and resiliency teams. The group proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls; deliver processes and solutions efficiently and consistently; and drive automation of controls. The group's number one priority is to enable the business by keeping the firm safe, stable and resilient.

High Risk Roles (HRR) are sensitive roles within the technology organization that require high assurance of the integrity of staff by virtue of 1) sensitive cybersecurity and technology functions they perform within systems or 2) information they receive regarding sensitive cybersecurity or technology matters. Users in these roles are subject to enhanced pre‑hire screening which includes both criminal and credit background checks (as allowed by law). The enhanced screening will need to be successfully completed prior to commencing employment or assignment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assessments & Exercises Director - Third Party Assurance
Assessments & Exercises Director - Third Party Assurance

Next Frontier Capital • Greater London

On-site
GBP 150,000 - 210,000
Cyber Intelligence Director
Cyber Intelligence Director

Fairygodboss • Greater London

On-site
GBP 150,000 - 190,000
Senior Director – Third-Party Cybersecurity & Cloud Controls
Senior Director – Third-Party Cybersecurity & Cloud Controls

Next Frontier Capital • Greater London

On-site
GBP 150,000 - 210,000
Tech Risk Assurance Lead
Tech Risk Assurance Lead

JPMorganChase • Bournemouth

On-site
GBP 90,000 - 120,000
Senior Director, Third-Party Security Assessments
Senior Director, Third-Party Security Assessments

JPMorgan Chase & Co. • Bournemouth

On-site
GBP 120,000 - 190,000
Cyber Intelligence Director
Cyber Intelligence Director

Cyber UK • Greater London

On-site
GBP 80,000 - 110,000
Cyber Intelligence Director
Cyber Intelligence Director

JPMorganChase • Greater London

On-site
GBP 120,000 - 180,000
Assessments & Exercises Director - Third Party Assurance
Assessments & Exercises Director - Third Party Assurance

JPMorgan Chase & Co. • Bournemouth

On-site
GBP 120,000 - 190,000
Tech Risk Assurance Lead
Tech Risk Assurance Lead

JPMorgan Chase & Co. • Christchurch

On-site
GBP 90,000 - 130,000
Tech Risk and Controls Senior Associate
Tech Risk and Controls Senior Associate

JPMorganChase • Greater London

Hybrid
GBP 60,000 - 90,000