Penetration Testing Program Governance & Vendor Strategy Manager

Company: JP Morgan Chase
Apply for the Penetration Testing Program Governance & Vendor Strategy Manager
Location: London
Job Description:

Overview

In this role, you will act as the primary coordinator for Penetration Testing governance, vendor management, and delivery excellence across the program. You will bridge Penetration Testing with wider strategic functions to ensure alignment with the testing strategy while overseeing performance, quality, and evidence standards. This is a service-delivery and governance position with a strong technical and strategy focus, not a hands-on testing role. You’ll shape delivery and QA approaches, drive improvements across vendors, and support executive-level reporting and decision-making.

Responsibilities

  • Own vendor management for penetration testing delivery, including performance management, issue resolution, and continuous improvement
  • Establish and maintain program-wide delivery standards (testing approach, reporting, evidence quality, reproducibility, retest criteria) and ensure vendor adherence
  • Run vendor governance cadences with KPI-driven reporting, action tracking, and escalation management
  • Oversee Penetration Testing strategy execution, maintain delivery roadmaps and milestones, and produce disciplined status reporting
  • Serve as the primary link between Penetration Testing and wider strategic functions and governance forums to align priorities and reporting
  • Coordinate with product/engineering, procurement, and finance to support governance and program execution
  • Lead a small team by setting direction, allocating work, removing blockers, and coaching for capability growth

Key requirements

  • Proven experience in vendor management and program oversight in a large, matrixed organization
  • Demonstrable program management capability (roadmap planning, milestone tracking, dependency management, RAID-style risk/issue tracking) with executive-ready status reporting
  • Strong understanding of penetration testing delivery models and the offensive security space (ability to challenge, translate, and steer)
  • Strong stakeholder management and conflict-resolution skills across technical and non-technical audiences
  • Experience running governance forums with KPI reporting and action follow-through
  • Strong organizational skills with attention to detail and ability to manage multiple priorities
  • Strong written and verbal communication, including executive-ready updates for senior stakeholders
  • Experience in people management, including leading a small team
  • stakeholder management
  • effective communication with senior audiences
  • problem-solving and strategic thinking
  • understanding of offensive security and penetration testing delivery models
  • ability to identify gaps in methodology, severity, and evidence articulation
  • ability to challenge and translate technical concepts for governance contexts

Posted: September 14th, 2026