Senior Manager, Cyber Risk and Analysis, Technology Risk Management
Company: Capital One
Location: Lewisville
Posted on: January 20, 2023
Job Description:
Center 1 (19052), United States of America, McLean,
VirginiaSenior Manager, Cyber Risk and Analysis, Technology Risk
Management Technology Risk Management (TRM) is a growing
organization focused on providing expert advice, credible
challenge, and effective oversight of information security and
technology risk activities. The Associates that make up the TRM
team are highly-skilled information security, cyber, technology,
and risk management professionals who bring a wealth of experience
to deliver high-impact analysis and recommendations that are rooted
in direct knowledge of security and technology. Senior Manager,
Cyber Risk and Analysis, Technology Risk Management - will play a
key role in the execution of technical testing to support
technology risk identification, risk assessment, reporting, and
effective challenge of processes, controls, and capabilities,
including but not limited to material and high risk technology
changes. This individual will contribute to and act as leader
within a team of highly skilled resources to design and execute
Outcome Based Testing. As part of the second line of defense, this
position will also interact regularly with first line Cyber,
Technology, the Lines of Business, as well as other second line of
defense risk management offices to perform and support targeted
technical reviews of the effectiveness of the firm's controls
infrastructure and offer independent advice and recommendations
regarding ways to further mature the firm's cyber risk management
capabilities. Essential Functions (Responsibilities):
- Conduct analysis of artifacts from risk management platforms,
cyber operations, application security, and cloud infrastructure to
develop use cases for outcome based testing
- Design and execute outcome based testing to assess various risk
hypotheses
- Publish technical reports and presentations for risk owners,
senior management, and other stakeholders regarding risks
associated with new or emerging technologies
- Facilitate prioritization and timing of outcome based testing
using Agile methodology
- Collaborate effectively with colleagues, stakeholders, and
leaders across multiple organizations to achieve objectives
- Support process maturity within outcome based testing through
continual improvement of documentation, processes, and frameworks
Basic Qualifications:
- Bachelor's degree
- At least 6 years experience in cyber security
- At least 3 years experience operating in a cloud computing
environment (AWS, Microsoft Azure, or Google Cloud)
- At least 3 years experience with security frameworks (NIST CSF,
ISO, CIS, or COBIT)
- At least 2 years experience performing testing to identify
enterprise, network, system, endpoint, and application-level
security issues and risks
- At least one of the following professional security
certifications: ISC2 Certified Information Systems Security
Professional CISSP , Offensive Security Certified Professional OSCP
, GIAC Security Leadership GSLC , ISACA Certified Information
Security Manager CISM , or ISACA Certified Information Systems
Auditor CISA , or ISACA Certified in Risk and Information Systems
Control CRISC Preferred Qualifications:
- Master's degree
- Experience conducting penetration testing, red teaming, purple
teaming, or cloud security testing
- Experience working in financial services or other
highly-regulated sectors
- Experience supporting delivery of products using Agile
methodology
- One or more of the following cloud certifications: AWS
Solutions Architect - Associate, AWS Solutions Architect -
Professional, AWS Certified Security Specialty, AWS Developer -
Associate, or AWS Devops Engineer Professional, ISC2 Certified
Cloud Security Professional CCSP, or CSA Certificate of Cloud
Security Knowledge CCSK At this time, Capital One will not sponsor
a new applicant for employment authorization for this position. The
minimum and maximum full-time annual salaries for this role are
listed below, by location. Please note that this salary information
is solely for candidates hired to perform work within one of these
locations, and refers to the amount Capital One is willing to pay
at the time of this posting. Salaries for part-time roles will be
prorated based upon the agreed upon number of hours to be regularly
worked. Location is New York City- $188,814 and $222,758 for Sr.
Manager, Cyber Risk & Analysis Candidates hired to work in other
locations will be subject to the pay range associated with that
location, and the actual annualized salary amount offered to any
candidate at the time of hire will be reflected solely in the
candidate's offer letter. No agencies please. Capital One is an
Equal Opportunity Employer committed to diversity and inclusion in
the workplace. All qualified applicants will receive consideration
for employment without regard to sex, race, color, age, national
origin, religion, physical and mental disability, genetic
information, marital status, sexual orientation, gender
identity/assignment, citizenship, pregnancy or maternity, protected
veteran status, or any other status prohibited by applicable
national, federal, state or local law. Capital One promotes a
drug-free workplace. Capital One will consider for employment
qualified applicants with a criminal history in a manner consistent
with the requirements of applicable laws regarding criminal
background inquiries, including, to the extent applicable, Article
23-A of the New York Correction Law; San Francisco, California
Police Code Article 49, Sections ; New York City's Fair Chance Act;
Philadelphia's Fair Criminal Records Screening Act; and other
applicable federal, state, and local laws and regulations regarding
criminal background inquiries.If you have visited our website in
search of information on employment opportunities or to apply for a
position, and you require an accommodation, please contact Capital
One Recruiting at 1- or via email at . All information you provide
will be kept confidential and will be used only to the extent
required to provide needed reasonable accommodations.For technical
support or questions about Capital One's recruiting process, please
send an email to Capital One does not provide, endorse nor
guarantee and is not liable for third-party products, services,
educational tools or other information available through this
site.Capital One Financial is made up of several different
entities. Please note that any position posted in Canada is for
Capital One Canada, any position posted in the United Kingdom is
for Capital One Europe and any position posted in the Philippines
is for Capital One Philippines Service Corp. (COPSSC).
Keywords: Capital One, Lewisville , Senior Manager, Cyber Risk and Analysis, Technology Risk Management, Executive , Lewisville, Texas
Didn't find what you're looking for? Search again!
Loading more jobs...