JPMorgan Chase needs to keep the firm's supply chain strong and resilient by anticipating and addressing new and emerging risks in third party software, cloud environments, and AI systems.
Requirements
Experience: 2+ years in application security, third party risk management, or cloud security within a financial services or technology environment.
Proficiency in Microsoft Office (especially Excel), and familiarity with security assessment tools, SBOM/AI BOM standards, and cloud security platforms (e.g., AWS, Azure, GCP).
Software Bill of Materials (SBOM) and Artificial Intelligence Bill of Materials (AIBOM)
Certification in Public Cloud Technology (e.g., AWS, Azure, GCP)
Responsibilities
Assess, verify, and develop processes to gather and analyze third party application security data, including Software Bill of Materials (SBOMs), AI Bill of Materials (AI BOMs), and cloud security controls.
Continuously monitor controls to ensure supply chain security.
Drive continuous improvement by identifying and implementing opportunities to processes, tools, and overall program.
Lead efforts to monitor and strengthen third party applications by assessing Software Bill of Materials (SBOMs), Artificial Intelligence Bill of Materials (AI BOMs), and cloud security controls.
Analyze risk data, and track remediation efforts.
Streamline security assessments and validate controls.
Other
Analytical Mindset: Ability to understand security requirements, regulatory drivers, and a curiosity that looks for the story behind the data.
Control Focused: Detail-oriented approach to verifying the accuracy of security assessments and underlying data, especially in large and complex environments.
Team Player: Excellent interpersonal skills to work seamlessly within a team and communicate across various departments, both written and verbal.
Multitasker: Ability to juggle multiple priorities and meet tight deadlines with exceptional organizational skills.
Innovator: Capable of delivering continuous improvements to all stages of the third party application security process