Skip to content
CISO Spotlights

Career profile

Patrick Opet

Global Chief Information Security Officer, JPMorganChase

Status
Current role, per sources checked 26 April 2025
Appointed
Not stated in the sources
Published

Compiled 27 September 2026 from public records. Each statement below is drawn from the sources listed at the end.

Patrick Opet is chief information security officer of JPMorganChase, a title he signs beneath a company blog post that reads as a public warning to the firm's software suppliers.

RSA Conference's expert page gives the fuller title: Global CISO and Head of Cybersecurity & Technology Controls, a member of the firm's Global Technology Leadership Team leading several thousand cybersecurity and technology-controls professionals across every line of business and geography where JPMorganChase operates.

Career path

The public record reviewed for this profile does not trace Opet's roles before JPMorganChase; what it does show is his current work, including a seat as Vice Chair of the Analysis & Resilience Center for Systemic Risk, and an academic background of an M.S. from the University of Maryland in Computer Systems Management and Information Assurance and a B.S. from George Washington University in Computer Engineering.

A public letter on supply-chain security

In April 2025, Opet published an open letter to JPMorganChase's third-party software suppliers, arguing that the software-as-a-service delivery model concentrates risk among a small number of providers and that a breach at one can now ripple through all of its customers.

He wrote that over the prior three years, JPMorganChase's third-party providers had experienced a number of incidents within their own environments, requiring the firm to isolate certain compromised providers and dedicate substantial resources to threat mitigation.

His central request to suppliers was direct: "Providers must urgently reprioritize security, placing it equal to or above launching new products."

The letter also pointed to solutions Opet said were already available, including confidential computing, customer self-hosting and bring-your-own-cloud arrangements, as ways for organizations to keep stronger control of their data while still using SaaS platforms.

Sources

  1. 1.
    JPMorganChasejpmorganchase.com · published 26 April 2025 · checked 27 September 2026 · tier A
  2. 2.
    RSA Conferencersaconference.com · undated page · checked 27 September 2026 · tier A

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.