Director, Cyber Risk and Analysis
Capital OneAbout the role
Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, and managing technology risk.
For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.
Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.
Our business leaders must make technology decisions constantly. TRM makes sure they have the tech risk information they need to make good decisions. Associates within TRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.
As a Director, Cyber Risk and Analysis, you will apply expertise on risk frameworks and best practices to assess current state, identify methodology gaps, and evaluate threats and/or business impact to enable advisory partnerships and effective oversight of tech and cyber risk across Capital One. You will lead risk aggregation initiatives, define mitigation strategies, prioritize and escalate recommendations to senior leadership. You will also participate in the design, socialization and implementation of risk management products and programs through your deep knowledge of risk assessments, information risk controls, regulatory and internal governance standards, data analysis, metrics / reporting, and customer engagement.
Responsibilities:
Maintains a broad, expert understanding of technology risk frameworks, has innate ability to leverage these frameworks in risk identification processes.
Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting risk management policies or programs; recommends sound, practical solutions to complex issues.
Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise.
Advises Accountable Executives of tech and cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management.
Exhibits strong critical thinking and communication skills,with proven ability to navigate the unknown to devise and socialize innovative risk management solutions.
Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change. Understands associated reporting metrics and is able to inform on tech and cyber risks.
Quickly and accurately analyzes data, assesses risk, & prioritizes potential risks to differentiate critical, high-risk, and low-risk issues, and remediate and escalate as appropriate.
Makes recommendations regarding changes to first line policy, procedures, and control programs to mitigate evolving risks.
Effectively self-challenges tech and cyber control and risk management programs as part of first line duties and escalates risks where appropriate.
Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement.
Basic Qualifications:
Bachelor's Degree or military experience
At least 5 years of experience with Technology Risk Management or Cyber Secur
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s