At a Glance
- Tasks: Lead third-party cybersecurity assessments and evaluate supplier security postures.
- Company: Join a leading firm in cybersecurity and technology controls.
- Benefits: Competitive salary, professional development, and opportunities for career advancement.
- Other info: Dynamic role with a focus on innovation and strategic risk management.
- Why this job: Make a significant impact on cybersecurity by ensuring supplier safety and resilience.
- Qualifications: 10+ years in cybersecurity with expertise in cloud security and control frameworks.
The predicted salary is between 80000 - 100000 € per year.
As an Executive Director within the Cybersecurity and Technology Controls (CTC) Assessments & Exercises function, you will serve as the senior technical authority for third-party cybersecurity assurance. You will bring deep, hands‑on expertise in cybersecurity architecture, cloud security, and enterprise control frameworks to critically evaluate the control maturity of the firm's most complex and strategically significant suppliers. Reporting to the Global Third-Party Assurance Lead, you help to elevate the technical rigor, depth, and credibility of third‑party assurance outcomes. You will translate complex technical findings into clear, business‑relevant risk insights for senior stakeholders across Cybersecurity, Technology, Risk, and the Business, and will act as a trusted escalation point for the most technically challenging assessments.
Job Responsibilities
- Provide authoritative technical leadership across third-party cybersecurity assessments, bringing deep expertise in cybersecurity architecture, cloud‑native and hybrid environments, application security, and enterprise control domains.
- Lead and personally conduct in-depth technical evaluations of supplier cybersecurity posture, control maturity, and architectural resilience, particularly for the firm's most critical and complex third‑party relationships.
- Perform threat modeling against supplier environments to identify potential security risks and develop mitigation strategies tailored to the firm's risk appetite.
- Evaluate supplier security architectures across public cloud providers (AWS, Azure, Google Cloud), assessing the design and effectiveness of controls in cloud‑native, hybrid, and on‑premises environments.
- Act as the senior technical escalation point for complex supplier risks, control gaps, and remediation strategies, providing credible challenge and expert advisory input.
- Drive the evolution of the third‑party assurance methodology by embedding deeper technical assessment capabilities, including architecture reviews, threat modeling, and cloud security posture evaluation.
- Translate complex technical cybersecurity risks and supplier control deficiencies into clear, actionable, business‑relevant insights for senior leadership and non-technical audiences through detailed reports, presentations, and other appropriate methods.
- Partner with Product Security, Cybersecurity Architecture, Technology Risk & Controls, and Cybersecurity pillar leads to ensure alignment in control intent, solution design, and third‑party risk remediation.
- Lead thematic analysis to identify systemic technical weaknesses, emerging risks, and trends across the supplier landscape, and recommend strategic remediation approaches.
Required Qualifications, Capabilities, and Skills
- 10+ years of professional experience in cybersecurity, with significant depth in senior technical and/or architecture‑focused positions.
- Proven ability to assess and articulate the cybersecurity control maturity of complex technology environments, including enterprise, cloud‑native, and hybrid architectures.
- Deep, hands‑on expertise in cybersecurity architecture, threat modeling, and designing or evaluating secure controls for enterprise‑level solutions.
- Strong understanding of industry cybersecurity frameworks and key control domains (e.g., NIST CSF, ISO 27001, FFIEC, SOC 2, GDPR).
- Thorough design and operational experience across one or more major public cloud providers (AWS, Azure, Google Cloud), with relevant certifications advantageous.
- Proficiency with Cloud Security Posture Management (CSPM) tools and cloud security assessment methodologies.
Assessments & Exercises Director - Third Party Assurance in Bournemouth employer: JP Morgan
As a leading employer in the cybersecurity sector, we offer a dynamic work environment that fosters innovation and collaboration. Our commitment to employee growth is evident through continuous learning opportunities and a culture that values technical expertise and leadership. Located in a vibrant area, we provide competitive benefits and a supportive atmosphere where your contributions directly impact our mission of enhancing third-party cybersecurity assurance.
StudySmarter Expert Advice🤫
We think this is how you could land Assessments & Exercises Director - Third Party Assurance in Bournemouth
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the hunt for opportunities. Attend industry events or webinars to meet potential employers and showcase your expertise.
✨Tip Number 2
Prepare for interviews by brushing up on your technical knowledge and real-world applications. Be ready to discuss your experience with cloud security and third-party assessments, as these will be key topics for the role.
✨Tip Number 3
Don’t just wait for job postings! Proactively reach out to companies you admire, even if they’re not advertising openings. A well-crafted message expressing your interest can open doors we didn’t even know existed.
✨Tip Number 4
Apply through our website for the best chance at landing that dream job! We love seeing candidates who take the initiative to engage directly with us, so make sure to highlight your unique skills and experiences.
We think you need these skills to ace Assessments & Exercises Director - Third Party Assurance in Bournemouth
Some tips for your application 🫡
Show Off Your Expertise:When you're writing your application, make sure to highlight your deep expertise in cybersecurity architecture and cloud security. We want to see how your hands-on experience aligns with the role, so don’t hold back on showcasing your skills!
Be Clear and Concise:Remember, we’re looking for someone who can translate complex technical findings into clear insights. Use straightforward language in your application to demonstrate your ability to communicate effectively with both technical and non-technical audiences.
Tailor Your Application:Make sure to tailor your application to the specific requirements of the Assessments & Exercises Director role. Highlight relevant experiences that showcase your ability to evaluate supplier cybersecurity postures and control maturity.
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!
How to prepare for a job interview at JP Morgan
✨Know Your Cybersecurity Stuff
Make sure you brush up on your knowledge of cybersecurity architecture, cloud security, and enterprise control frameworks. Be ready to discuss specific examples from your past experience that demonstrate your expertise in these areas, especially when it comes to evaluating third-party suppliers.
✨Prepare for Technical Questions
Expect to face some tough technical questions during the interview. Review threat modelling techniques and be prepared to explain how you would assess a supplier's cybersecurity posture. Practising with mock interviews can help you articulate your thought process clearly.
✨Translate Tech Speak into Business Language
Since you'll need to communicate complex technical findings to non-technical stakeholders, practice translating your technical insights into business-relevant language. Think about how you can present risks and recommendations in a way that resonates with senior leadership.
✨Showcase Your Leadership Skills
As an Executive Director, you'll be expected to lead and influence others. Prepare examples that highlight your leadership experience, particularly in driving technical assessments and collaborating with cross-functional teams. Demonstrating your ability to guide others will set you apart.