Jobs and Careers
CA

Sr. Manager, Cyber Risk & Analysis

Capital One
United Statesfull_timeVerifiedPosted 19 Dec 2024
💰 $227,200/yr($199,100/yr$227,200/yr)

About the role

Center 3 (19075), United States of America, McLean, Virginia

Sr. Manager, Cyber Risk & Analysis

Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, and managing technology risk. 

For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.

Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.

Our business leaders must make technology decisions constantly. TRM makes sure they have the tech risk information they need to make good decisions. Associates within TRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.

This position, Sr. Manager, Technology & Cyber Risk Advisor, will play a key role in the organization’s second line of defense risk identification program by independently overseeing the organization’s cybersecurity and technology risk taking and providing expertise and challenge during ongoing assessments. 

As part of the second line of defense, you will collaborate closely with partners in cybersecurity, technology, the lines of business, and other risk management offices across the various lines of business, to perform and support evaluations of the firm’s risk posture and offer independent advice and value-add recommendations regarding ways to reduce cybersecurity and technology risks. Having the ability to understand and translate data-driven analysis, business drivers, initiatives, and priorities, and translate them into meaningful risk analysis is critical to being a trusted advisor to our business stakeholders and partners. 

Desired Outcomes:

  • Be a trusted advisor and subject matter expert in your assigned Lines of Business 

  • Guide/drive effective and relevant risk conversations with Line of Business leadership and their teams to enable meaningful insights into key technology and cybersecurity risks (e.g., aligning to or providing insights in support of strategic priorities or objectives for the business, increasing risk accountability and visibility) 

  • Perform the review and effective challenge of technology and cybersecurity risks through business-driven assessment activities (e.g., risk and control self assessment (RCSA) activities,  scenario analysis, new products and services, etc.), to include providing expertise and advice on risk themes and mitigation strategies 

  • Monitor, report, and escalate metric performance, identify changes or trends in the risk profile, and brief senior management

  • Collaborate effectively and build trusted relationships with colleagues, stakeholders, and leaders across multiple organizations to achieve objectives.  

  • Communicate in a compelling manner, with a strong point of view, to any audience, including internal and external stakeholders 

  • Leverage business and tech/cyber domain expertise to raise the level of challenge activities to a strategic focus 

  • Constructively debate issues and connect the dots across various assessments (examples include assessments of new initiatives, scenario analysis, challenge of proposed mitigation plans and risk acceptances, etc.) 

  • Partner with first and second line peers to succinctly frame and report on technology and cybersecurity risks relative to risk appetite

  • Identify o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Capital One

View company profile →