×
Register Here to Apply for Jobs or Post Jobs. X

Commercial and Investment Bank, Controls - Third Party and Resiliency Risk & Control Manager - Executive Director

Job in City of Rochester, Rochester, Monroe County, New York, 14602, USA
Listing for: JPMorgan Chase & Co.
Full Time position
Listed on 2026-09-13
Job specializations:
  • IT/Tech
  • Finance & Banking
Salary/Wage Range or Industry Benchmark: 180000 - 280000 USD Yearly USD 180000.00 280000.00 YEAR
Job Description & How to Apply Below

Help shape how we make confident, well-governed decisions about third-party risk across a large, complex vendor ecosystem. You’ll turn technical assessment outputs into clear, executive-ready insights that protect clients, data, and operations. In this role, you will influence how we identify emerging risk patterns, prioritize remediation, and set consistent control expectations. You’ll partner across risk, technology, legal, procurement, and compliance in a highly visible role with meaningful impact.

As an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank
, you will synthesize, challenge, and communicate key risks and control considerations across the third-party lifecycle (onboarding, change, ongoing monitoring, and exit). You will ensure risk conclusions and decision artifacts are consistent, defensible, and aligned to agreed standards, thresholds, and risk appetite. You will translate vendor security evidence into clear risk narratives, business impact, and actionable recommendations. You will help leaders make informed decisions on risk acceptance, remediation prioritization, and safe vendor adoption.

Job

responsibilities
  • Aggregate and analyze third-party risk signals with a focus on data protection, cybersecurity, and operational resilience, translating findings into business process impacts and operational risk outcomes.
  • Set and govern standards for risk statements, residual risk framing, materiality thresholds, issue taxonomy, and escalation expectations across the third-party lifecycle.
  • Own quality assurance and constructive challenge of third-party assessment and monitoring outputs to ensure completeness, consistency, and defensibility of conclusions and remediation expectations.
  • Identify and elevate themes across the third-party portfolio (recurring control gaps, common failure modes, concentration hot spots) through appropriate governance forums.
  • Produce decision-grade materials that clearly articulate residual risk, recommended mitigations, and defined decision points tailored to business criticality.
  • Review and advise on business cases for new or expanded third-party engagements, including opportunities to reuse existing vendors and standardize controls or contractual levers.
  • Interpret vendor security evidence (for example, SOC 2 reports, ISO 27001 certification, and industry questionnaires such as Standardized Information Gathering (SIG) and the Consensus Assessments Initiative Questionnaire (CAIQ)) and convert it into clear risk narratives and control gap assessments.
  • Evaluate cloud and software-as-a-service architectures to identify material risks (identity and access management, encryption/key management, logging/monitoring, segmentation, data residency, dependency chains, and concentration risk).
  • Define and maintain a risk insights framework, including risk taxonomy mapping, key risk/key performance indicators, thresholds, trends, and executive-ready reporting.
  • Drive consistency in issue management by setting expectations for classification, documentation quality, evidence standards for closure, and transparent reporting of overdue actions and residual risk.
  • Partner and influence across control management, technology, procurement, legal, compliance, and operational risk to maintain a single, consistent narrative and improve decision usefulness.
Required qualifications, capabilities and skills
  • 8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a similarly regulated industry.
  • Demonstrated experience across the third-party lifecycle (onboarding, assessment, monitoring, issue management, and exit).
  • Proven ability to synthesize…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary