Principal Risk Specialist - Data, Analytics and Testing
Capital OneAbout the role
Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, software quality, and data management.
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 professionals in TDRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk, and data management risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.
For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Tech & Data Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and the risk of failing to manage our data. The CTRO is independent and oversees the work of the CISO, the CIO/CTO, and the Chief Data Officer. The CTRO reports to the Chief Risk Officer, who reports directly to the CEO.
Our business leaders must make technology decisions constantly. TDRM makes sure they have the tech and data risk information they need to make good decisions. Associates within TDRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.
As a Principal Risk Specialist on TDRM’s Data, Analytics and Testing team, you will own the metric governance process through the risk lens, work with your leaders to identify and implement program enhancements, and provide thought leadership to junior members of the team.
Desired Outcomes:
Drive desired outcomes through metrics and data with deep understanding of not only the risks but also human elements
Build relationships, collaborate, and communicate directly with TDRM internal stakeholders and 1LOD to manage metric governance process; lead the maturity of the metric governance process
Work with leaders to continue maturing the team’s capabilities that align with TDRM’s strategic objectives
A successful candidate will have:
Deep focus on execution, follow-through, accountability and results; ability to make progress even when in ambiguous situations
Strong communication to stakeholders at all levels across both 1LOD and 2LOD organizations to enable transparency and timely information sharing
Proven critical thinking skills, including the ability to express a point of view supported by data and evidence
Willingness to learn and intense intellectual curiosity to better understand technology and cyber risks and how metrics, analytics and testing fit in to enhance 2LOD effective challenge and oversight activities
Adept at providing structure and organization for stakeholders in different job families, expertise and scope of work
Basic Qualifications:
A Bachelor’s degree or military experience
At least 3 years of experience working in risk management
At least 2 years of experience manipulating and analyzing data sets
At least 2 years of program management experience
Preferred Qualifications:
3+ years of experience in tech or cyber
2+ years of experience working with at least one scripting language such as Python or SQL
Strong knowledge of various risk management frameworks and tools such as controls, reporting and escalation
Certified Information Security Manager (CISM) or Certified Information Systems Auditor (CISA)
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s