Executive Director - Third-Party Risk & Controls Insights

JPMorganChase

New York (NY)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

JPMorganChase is seeking an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank. You will synthesize risks across the vendor lifecycle and translate security evidence into clear narratives for senior leadership.

The role demands strong risk judgment, collaboration with risk, technology, legal, procurement, and compliance, and the ability to drive remediation prioritization and decision-ready materials.

Qualifications

  • 8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a similarly regulated industry.
  • Experience across the third-party lifecycle (onboarding, assessment, monitoring, issue management, exit).
  • Ability to synthesize assessment outputs into executive-ready insights, including themes, emerging risks, residual risk framing, and clear recommendations.
  • Strong cybersecurity and technology risk fluency, including the ability to challenge vendor security posture using evidence such as SOC 2 and ISO 27001.
  • Working knowledge of cloud and software-as-a-service control domains (identity and access management, encryption, logging/monitoring, vulnerability management, incident response, and secure development controls).
  • Ability to translate technical risk into business decisions, including trade-offs, materiality, and practical mitigation actions.
  • Experience defining and using KPIs, thresholds, and trend interpretation to drive risk visibility and prioritization.
  • Strong stakeholder management skills, with the ability to influence cross-functional partners and challenge constructively when outputs are not decision-useful.
  • Excellent written and verbal communication skills, including producing concise governance materials for senior stakeholders.

Responsibilities

  • Aggregate and analyze third-party risk signals with a focus on data protection, cybersecurity, and operational resilience, translating findings into business process impacts and operational risk outcomes.
  • Set and govern standards for risk statements, residual risk framing, materiality thresholds, issue taxonomy, and escalation expectations across the third-party lifecycle.
  • Own quality assurance and constructive challenge of third-party assessment and monitoring outputs to ensure completeness, consistency, and defensibility of conclusions and remediation expectations.
  • Identify and elevate themes across the third-party portfolio (recurring control gaps, common failure modes, concentration hot spots) through appropriate governance forums.
  • Produce decision-grade materials that clearly articulate residual risk, recommended mitigations, and defined decision points tailored to business criticality.
  • Review and advise on business cases for new or expanded third-party engagements, including opportunities to reuse existing vendors and standardize controls or contractual levers.
  • Interpret vendor security evidence (for example, SOC 2 reports, ISO 27001 certification, and industry questionnaires such as SIG and CAIQ) and convert it into clear risk narratives and control gap assessments.
  • Evaluate cloud and software-as-a-service architectures to identify material risks (identity and access management, encryption/key management, logging/monitoring, segmentation, data residency, dependency chains, and concentration risk).
  • Define and maintain a risk insights framework, including risk taxonomy mapping, key risk/KPIs, thresholds, trends, and executive-ready reporting.
  • Drive consistency in issue management by setting expectations for classification, documentation quality, evidence standards for closure, and transparent reporting of overdue actions and residual risk.
  • Partner and influence across control management, technology, procurement, legal, compliance, and operational risk to maintain a single, consistent narrative and improve decision usefulness.

Skills

Executive leadership
Stakeholder management
Risk synthesis & storytelling
Cybersecurity risk fluency
Third-party risk management
Vendor security posture evaluation
Communication

Job description

JPMorganChase is seeking an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank. You will synthesize risks across the vendor lifecycle and translate security evidence into clear narratives for senior leadership.

The role demands strong risk judgment, collaboration with risk, technology, legal, procurement, and compliance, and the ability to drive remediation prioritization and decision-ready materials.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Executive Director - Third-Party Risk & Controls Insights
Executive Director - Third-Party Risk & Controls Insights

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 240,000
Executive Director, Third-Party Risk & Controls Insights
Executive Director, Third-Party Risk & Controls Insights

JPMorgan Chase & Co. • City of Rochester (NY)

On-site
USD 180,000 - 240,000
Executive Director, Third-Party Risk & Controls Insights
Executive Director, Third-Party Risk & Controls Insights

J.P. Morgan • New York (NY)

On-site
USD 180,000 - 280,000
VP, Third-Party Risk Insights & Controls
VP, Third-Party Risk Insights & Controls

JPMorgan Chase & Co. • Chicago (IL)

On-site
USD 180,000 - 240,000
VP, Third-Party Risk & Controls Insights
VP, Third-Party Risk & Controls Insights

Next Frontier Capital • Chicago (IL)

On-site
USD 160,000 - 240,000
Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director
Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director

J.P. Morgan • New York (NY)

On-site
USD 180,000 - 280,000
Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director
Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director

JPMorganChase • New York (NY)

On-site
USD 180,000 - 240,000
Vice President, Third-Party Governance & Insights
Vice President, Third-Party Governance & Insights

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 150,000 - 210,000
Third Party Risk Control Manager - Vice President
Third Party Risk Control Manager - Vice President

Next Frontier Capital • Chicago (IL)

On-site
USD 160,000 - 240,000
Third Party Risk Control Manager - Vice President
Third Party Risk Control Manager - Vice President

JPMorgan Chase & Co. • Chicago (IL)

On-site
USD 180,000 - 240,000