Posted in

Sr. Manager – Cyber Risk & Analysis – Retail Bank Tech – Cyber – Data and Resiliency

Sr. Manager – Cyber Risk & Analysis – Retail Bank Tech – Cyber – Data and Resiliency

CompanyCapital One
LocationMcLean, VA, USA, Richmond, VA, USA
Salary$175500 – $220300
TypeFull-Time
Degrees
Experience LevelSenior

Requirements

  • At least 5 years of risk management experience
  • At least 5 years experience in Cybersecurity, Technology Risk, or Audit
  • At least 3 years of People Management experience

Responsibilities

  • Partner with Premium Products and Experiences (PPX) (a part of Retail Bank) Tech and Business teams to assess their compliance with the divisional and enterprise level cybersecurity controls.
  • Lead identification, assessment, monitoring, and reporting on technology and cyber risks inherent to business and technology concepts.
  • Lead tech and cybersecurity risk assessments of large scale technology change initiatives to ensure all of the risks and potential areas of non compliance are identified, documented, and planned for appropriate remediation
  • Apply understanding of cybersecurity controls to proactively mitigate risks to the business.
  • Influence control owners and other stakeholders to build consensus on risk mitigation and remediation strategies.
  • Provide oversight and guidance on key strategic cybersecurity initiatives and assess impact of these initiatives on the PPX control environment
  • Identify and implement continual program enhancements based on industry standards and best practices related to cloud technology and cyber risk management for eCommerce and financial services industries
  • Design and implement information based internal risk and control governance
  • Build successful relationships with line of business risk offices and team members to understand impact of technology risk on critical business processes
  • Support Risk Control and Self Assessments (RCSAs) and audits
  • Provide leadership, coaching, and mentorship to more junior team members and assign tasks, as needed.
  • Assist the TCDR team in delivering against their strategy and service model.

Preferred Qualifications

  • Cybersecurity and technology risk certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or related certifications
  • Experience in performing Control Self Assessments (CSAs), or completing assessments against established industry risk frameworks, including: the NIST Cybersecurity Framework.
  • Experience performing data analysis in support of internal risk assessments and control reviews
  • Consulting experience with a Big 4 firm is a plus