Jobs and Careers
CA

Principal Associate, Authentication and Access Assurance (AAA)

Capital One
United Statesfull_timeVerifiedPosted 26 Feb 2025
💰 $145,500/yr($115,900/yr$145,500/yr)

About the role

Principal Associate, Authentication and Access Assurance (AAA)

The Authentication and Access Assurance (AAA) team is responsible for conducting cybersecurity risk assessments that evaluate authentication and access management practices across the organization. Our team ensures compliance with the FFIEC Authentication & Access Guidance and identifies key risks that impact the security and resilience of financial services.

As a Principal Associate, Cyber Risk Assessor, you will play a critical role in assessing authentication risks, identifying control gaps, and providing actionable recommendations. You will engage with stakeholders across cybersecurity, IT, and business functions to drive risk-based decision-making and improve authentication and access security.

This is an opportunity to work in a highly adaptable and evolving team, directly contributing to the organization’s cybersecurity posture. We seek an individual who is technically proficient, business-savvy, and an effective communicator, with a passion for authentication and identity security.

Roles and Responsibilities:

Cyber Risk Assessment & Advisory

  • Conduct cybersecurity risk assessments focused on authentication and access management practices, ensuring alignment with the FFIEC Authentication & Access Guidance and cybersecurity best practices.

  • Identify and assess authentication-related risks and IAM (Identity & Access Management) control gaps, providing well-supported risk ratings and recommendations.

  • Work with cybersecurity and business teams to understand the impact of authentication risks on the organization and provide business-relevant risk insights.

  • Maintain an up-to-date understanding of emerging authentication threats, IAM security practices, and regulatory expectations to continuously enhance assessment methodologies.

Risk Communication & Stakeholder Engagement

  • Translate technical findings into clear, actionable insights tailored for business and technology leaders.

  • Influence risk decisions by effectively articulating the significance of authentication risks and advocating for necessary security improvements.

  • Engage with stakeholders to challenge assumptions, push back when appropriate, and ensure risk assessments maintain independence and objectivity.

  • Strengthen team credibility by ensuring assessment reports and presentations are clear, concise, and aligned with customer needs.

Process and Team Development

  • Improve the consistency, efficiency, and strategic impact of risk assessments by refining assessment frameworks, templates, and methodologies.

  • Ensure assessments adhere to defined schedules and deadlines, proactively escalating issues when needed.

  • Serve as a knowledge resource for authentication and IAM risks, mentoring junior assessors and contributing to team training initiatives.

  • Support efforts to expand the team's capabilities in end-to-end IAM risk assessments, helping evolve the program's strategic focus over time.

Experience:

  • Experience in cybersecurity risk assessment, cybersecurity audit, or IAM security, with a focus on authentication risks and access management.

  • Familiarity with the FFIEC Authentication & Access Guidance and experience assessing compliance against it.

  • Strong understanding of authentication technologies, including multi-factor authentication (MFA), passwordless authentication, biometric authentication, and risk-based authentication.

  • Working knowledge of IAM security principles, such as identity governance, privileged access management (PAM), role-based access control (RBAC), and just-in-time access.

  • Experience working with stakeholders across business, IT, and security teams, with an ability to effectively communicate and influence security decisions.

  • Ability to manage multiple assessments simultaneously, maintain adherence to deadlines, and escalate issues when needed.

  • Strong critical thinking and analytical skills, with the ability to assess control effectiveness and make well-reasoned risk judgments.

  • Excellent written and verbal communication skills, including the ability to translate technical risk assessments into business-relevant insights.

<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Capital One

View company profile →