Sr Associate - Technology Risk Management Governance
Capital OneAbout the role
Technology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control, and manage cyber and technology risk throughout the company. This organization plays a critical role in helping to ensure that the company’s risk-taking entities are aware of the risks inherent in their activities and decisions, the impact of their actions on the company at an enterprise level, and opportunities to reduce, mitigate, or avoid risks altogether. Associates within the Technology Risk Management organization are highly-skilled information security, cyber, technology, or risk management professionals who have a wealth of experience and a demonstrated ability to provide value-added recommendations and deliver high-impact results in their areas of expertise.
The Role, Sr Associate - TRM Governance
We are currently seeking a motivated, self driven Sr associate with experience in engaging with business and technology leaders to structure sound technology and cyber risk governance processes. This individual will partner with business divisions and risk management organizations to support development and implementation of robust risk governance processes supporting numerous technology risk management practices within Capital One.
The ideal candidate for this role will have a good understanding of technology and cyber security risk processes and industry-level governance practices, both from a technical and risk management perspective. The associate in this role will support programs to develop relationships and influence strong risk management across the organization, providing oversight and effective challenge.
Responsibilities:
Develop and support production of risk governance oversight routines covering technology and cyber control programs, as well as technical assessments of the effectiveness and design of technology and cybersecurity controls
Play a supporting role in identifying areas of cyber risk to provide oversight, analysis, effective challenge, and risk-informed recommendations
Support drafting of risk governance proposals for senior management and other stakeholders, to potentially include regulatory agencies and the Board of Directors, as needed
Team member of technology risk professionals
Stay current on emerging enterprise-level risk management approaches
Collaborate effectively with stakeholders and leaders across multiple organizations to achieve objectives
This role requires the ability to articulate complex technical concepts in clear, concise, actionable manner through both written products and verbal communications
Basic Qualifications:
Bachelor’s degree or military experience
At least 2 years of governance experience within technology or cybersecurity
At least 1 year of experience working in the fields of information security, audit, or risk management
Preferred Qualifications:
Experience with public cloud infrastructure, security, and controls principles
Experience working in an Agile environment
Experience performing risk governance, assessments, detection and response operations
Familiarity with financial sector regulatory practices and second line of defense effective challenge
Familiarity with NIST Cybersecurity Framework controls, COSO Risk Framework, NIST 800-53, ISO 27000-1
CRISC, CISSP, CISA
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigrationApply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s