Jobs and Careers
CA

Sr Associate - Technology Risk Management Governance

Capital One
United Statesfull_timeVerifiedPosted 4 Dec 2023

About the role

Center 1 (19052), United States of America, McLean, Virginia

Sr Associate - Technology Risk Management Governance

Technology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control, and manage cyber and technology risk throughout the company. This organization plays a critical role in helping to ensure that the company’s risk-taking entities are aware of the risks inherent in their activities and decisions, the impact of their actions on the company at an enterprise level, and opportunities to reduce, mitigate, or avoid risks altogether. Associates within the Technology Risk Management organization are highly-skilled information security, cyber, technology, or risk management professionals who have a wealth of experience and a demonstrated ability to provide value-added recommendations and deliver high-impact results in their areas of expertise.

The Role, Sr Associate - TRM Governance

We are currently seeking a motivated, self driven Sr associate with experience in engaging with business and technology leaders to structure sound technology and cyber risk governance processes. This individual will partner with business divisions and risk management organizations to support development and implementation of robust risk governance processes supporting numerous technology risk management practices within Capital One.  

The ideal candidate for this role will have a good understanding of technology and cyber security risk processes and industry-level governance practices, both from a technical and risk management perspective. The associate in this role will support programs to develop relationships and influence strong risk management across the organization, providing oversight and effective challenge.

Responsibilities:

  • Develop and support production of risk governance oversight routines covering technology and cyber control programs, as well as technical assessments of the effectiveness and design of technology and cybersecurity controls

  • Play a supporting role in identifying areas of cyber risk to provide oversight, analysis, effective challenge, and risk-informed recommendations

  • Support drafting of risk governance proposals for senior management and other stakeholders, to potentially include regulatory agencies and the Board of Directors, as needed

  • Team member of technology risk professionals

  • Stay current on emerging enterprise-level risk management approaches

  • Collaborate effectively with stakeholders and leaders across multiple organizations to achieve objectives

  • This role requires the ability to articulate complex technical concepts in clear, concise, actionable manner through both written products and verbal communications

Basic Qualifications:

  • Bachelor’s degree or military experience

  • At least 2 years of governance experience within technology or cybersecurity 

  • At least 1 year of experience working in the fields of information security, audit, or risk management

Preferred Qualifications:

  • Experience with public cloud infrastructure, security, and controls principles

  • Experience working in an Agile environment

  • Experience performing risk governance, assessments, detection and response operations

  • Familiarity with financial sector regulatory practices and second line of defense effective challenge

  • Familiarity with NIST Cybersecurity Framework controls, COSO Risk Framework, NIST 800-53, ISO 27000-1

  • CRISC, CISSP, CISA 

At this time, Capital One will not sponsor a new applicant for employment authorization for this position. 

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Capital One

View company profile →