Expoint – all jobs in one place
The point where experts and best companies meet

Information Officer jobs in United States, Virginia, Arlington

Unlock your potential in the high tech industry with Expoint. Search for job opportunities as a Information Officer in United States, Virginia, Arlington and join the network of leading companies. Start your journey today and find your dream job as a Information Officer with Expoint.
Company
Job type
Job categories
Job title (1)
United States
Virginia
Arlington
23 jobs found
09.12.2025
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
18.11.2025
EY

EY GPS - Assistant Facility Security Officer Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance. Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies,...
Description:

As Assistant Facility Security Officer (AFSO) you will be responsible for ensuring the protection of National Security Information in accordance with the National Industrial Security Program Operating Manual (NISPOM)/32 CFR Part 117. Responsibilities include program oversight, evaluations, and educating cleared employees on promulgated government and company initiatives, policies and procedures. The candidate will serve as the primary security liaison with government agencies, sponsor representatives and integrate security solutions across business portfolios.

Your key responsibilities

  • Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance.
  • Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies, and established regulations.
  • Enforce procedures for accounting, controlling, transmitting, safeguarding, and destroying classified information.
  • Support a security education, training, and awareness program.
  • Support the FSO with preparing reports and presentations for all levels of Management.
  • Maintains data compliance in DISS, NISS, NBIS, SWFT and other system of records.
  • Maintain and update Standard Practices and Procedures (SPP) documentation.
  • Support and mature the NISP annual security self-inspection, coordinating with internal stakeholders and DCSA representatives.
  • Provide support for classified meetings, including coordination and visitor management (e.g., processing Visitor Approval Requests (VARs)).
  • Lead security incident investigations in accordance with EY policy, NISPOM/32 CFR Part 117, and DCSA guidelines, collaborating with internal and external stakeholders.
  • Analyze and validate security processes, procedures, and standards to ensure compliance, identify trends and root-causes and facilitate multi-disciplinary teams to address gaps.
  • Prepare, track, and maintain Prime and Subcontractor DD-254s forms to ensure accuracy of security requirements. Coordinate with applicable stakeholders to facilitate actions necessary to execute and update such documentation.
  • Demonstrate professionalism, independent engagement, and collaboration with peers and external personnel to ensure adherence to regulations and guidelines.
  • Exhibit strong decision-making, individual initiative, organizational skills, and the ability to function with minimal supervision.

Skills and attributes for success

  • The AFSO must be a strategic thinker who can exercise independent judgment and knowledge to manage risks, deliver Industrial security support and align security solutions with business needs.
  • Candidate will collaborate with Senior security staff, employees and government clients to meet objectives while ensuring EY security program remains effective, compliant with Defense Counterintelligence and Security Agency (DCSA) standards, and aligned with corporate security requirements
  • In addition to technical expertise and independent initiative, the ideal AFSO will demonstrate a collaborative spirit and the ability to work seamlessly within multidisciplinary teams. Strong interpersonal skills are essential, enabling the candidate to foster open communication, support colleagues in joint problem solving, and cultivate an environment of mutual respect and shared accountability. A commitment to partnership—both within the security staff and across business units—ensures robust information exchange, effective coordination, and unified progress toward security and organizational objectives.

To qualify for the role you must have

  • Bachelor’s degree (Criminal Justice preferred) or equivalent experience
  • Strong organizational and communications skills, and the ability to effectively interact with staff and customers at all levels.
  • Proficiency in Microsoft Office products is required, with particular emphasis on Microsoft Access for database management and Microsoft Copilot for workflow optimization and automation.
  • DCSA Center for Development of Security Excellence (CDSE) FSO Program Management for Possessing Facilities courses.
  • Ability to obtain and maintain a TS/SCI Fullscope polygraph clearance
  • This position has an on-site requirement of 5 days a week on-site in the Tysons, VA and Arlington, VA office locations

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $57,400 to $104,100. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $68,800 to $118,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

15.09.2025
WF

Wells Fargo Senior Lead Financial Crimes Officer - CIB Advisory United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Perform Independent Risk Management (IRM) oversight, advisory, and credible challenge of CIB financial crimes-related issues, controls and initiatives, ensuring compliance with Bank Secrecy Act (BSA), Anti-Money Laundering (AML), Sanctions regulatory...
Description:


In this role, you will:

  • Perform Independent Risk Management (IRM) oversight, advisory, and credible challenge of CIB financial crimes-related issues, controls and initiatives, ensuring compliance with Bank Secrecy Act (BSA), Anti-Money Laundering (AML), Sanctions regulatory and policy requirements.

  • Evaluate long-term implications and consequences of strategic business decisions and recommend appropriate alternatives for risk management.

  • Deliver solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical thinking, and coordination of highly complex issue-related activities and guidance to key stakeholders and other members of CIB Financial Crimes Advisory.

  • Advise CIB functional leaders on customer and product risk, and ensure alignment with Wells Fargo's policies and business line objectives.

  • Identify potential risks when implementing change along with developing mitigation strategies and plans.

  • Act as an escalation point for complex customer and product issues between 1st and 2nd LOB, issue management and initiatives.

  • Determine appropriate strategies and actions of multiple business groups to meet moderate to high complex deliverables in managing financial crimes risk.

  • Interpret procedures and processes, and provide leadership to strategize and execute a variety of financial crime programs, services, and initiatives that are significant in scope, complexity, and risk.

  • Collaborate with and influence functional business partners, leaders, and executive management to provide support and drive strategic initiatives for the business.


Required Qualifications:

  • 7+ years of Financial Crimes, Operational Risk, Fraud, Sanctions, Anti-Bribery, Corruption experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.


Desired Qualifications:

  • 7+ years of experience within global financial institutions, regulatory, law enforcement or intelligence community working on international financial crime and emerging risk programs.

  • Strong understanding of Anti-Money Laundering regulatory principles covering correspondent banking, wholesale banking, markets, and MSB/Payment portfolios and federal and state money transmitter requirements covering MSBs and Payment Intermediariespreferred.

  • Develop strategic and tactical financial crimes risk assessments using data and analytics to inform senior business and financial crime leadership of emerging risk within the CIB platform.

  • Collect intelligence from multiple sources (open source, professional networks, etc.) and provide actionable recommendations to senior management.

  • Knowledge of United States and International AML and Sanction Regulations as well as emerging financial crimes risk associated with cybercrime andcryptocurrencies.

  • Ability to work with multiple teams and stakeholders to deliver on company objectives.

  • Experienced communicator at all levels within an organization from senior executives to junior staff.

  • Strong written communication who is able to provide guidance and supportive feedback to business and operational teams on company policies and procedures.

  • Bilingual speaking, reading, and writing proficiency in: Spanish, Arabic, or Mandarin.


Job Expectations:

  • Willingness to work on-site at stated location on the job opening.

  • This position offers a hybrid work schedule.

  • This position is not eligible for Visa sponsorship.

  • This position is subject to FINRA Background Screening Requirements, including successful completion and clearing of a background check. Internal transfers are subject to compliance with 17 CFR 240.17f-2 of the Securities Exchange Act of 1934 and FINRA Bylaws, Article III, Section 3, which states that Associated Persons should not be subject to statutory disqualification. Successful candidates must also meet ongoing regulatory requirements including additional screening and are required to report certain incidents.

401 S Tryon Street, Charlotte, NC

1753 Pinnacle Dr, Mclean, VA

401 Las Colinas Blvd W, Bldg B, Irving, TX

Texas – Irving Pay Range: $159,000.00 - 254,000.00 USD Annually

North CarolinaCharlotte Pay Range:$159,000.00 - 254,000.00 USD Annually

VirginiaMcLean Pay Range: $191,000.00 - 305,000.00 USDAnnually

18 Sep 2025


Wells Fargo Recruitment and Hiring Requirements:

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

Show more

These jobs might be a good fit

22.08.2025
CO

Capital One Senior Director Information Security Officer United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Be a leader at a premiere technology and financial services company. Lead a team of Product Security advisory professionals, responsible for Divisional cyber strategy integration and execution, identification and management...
Description:

Responsibilities:

  • Be a leader at a premiere technology and financial services company

  • Lead a team of Product Security advisory professionals, responsible for Divisional cyber strategy integration and execution, identification and management of risk for top business initiatives and technology platforms, threat and vulnerability management, incident management, supply chain cyber risk management, cyber risk oversight and reporting.

  • Deliver Cyber agenda and integration of Information Security within business objectives for line of business area

  • Serve as the central point of contact for your line of business technology executives into Capital One’s Cyber risk management priorities

  • Educate and influence executive leadership and associates to effectively leverage security capabilities and solutions to mitigate risks and emerging threats

  • Provide security expertise on prioritizing and managing information security risks and initiatives

  • Escalate and manage cyber security risk

  • Provide regular updates to executive leadership with your line of business on the overall information security health and risk environment

  • Work with business leadership to anticipate their objectives and needs to better serve them

  • Be an advocate for security and an advocate for the business and digital innovation. Instills a culture that works toward the highest standards in cyber (safeguard the business) while ensuring that business requirements are understood and adhered to (enabling the business).

  • Plays a key leadership role within Cyber’s community of leaders, drives innovation activity as an outcome; partner extensively with other Cyber and Technology organizations to derive solutions enabling industry leading products

  • Build relationships and influence with risk management functions across lines of defense

  • Become knowledgeable and advise on Capital One’s Cyber’s services, policies, procedures and standards

  • Staying current on the changing regulatory environment and understanding the impacts to the organization

  • Recruits, develops, and retains top talent, and uses excellent people leadership skills.

  • Build your team to provide top-notch information security and risk management expertise and guidance

About You:

  • You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including business executives, technology leaders, and enterprise suppliers

  • You are a focused individual who thrives in a fast-paced, dynamic, and collaborative team environment.

  • You have a deep passion for securing forward leaning, modern computing platforms

  • You have intuitive knowledge and experience with Offensive and Defensive Security techniques

  • You are comfortable with technologies and innovation including, Generative AI, Data Lakes, Cloud Services, Containers, Microservices, Serverless, APIs, DevOps, Encryption and Zero Trust

  • You have a strong desire to continually learn about new technologies

  • You enjoy leveraging your engineering experience to problem solve and continually learn new technology concepts to solve issues.

  • You display strong judgment, data/risk based decisioning, leadership, integrity, and communication skills.

  • You are able to tailor communications and analysis to the intended audience.

  • You have a passion and expertise in cybersecurity, with an ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions.

  • You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality

  • You are able to work well under minimal supervision

  • You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives

  • You have the ability to describe the risks of a security exposure or vulnerability in business-impact terms

Basic Qualifications:

  • Bachelor's degree

  • At least 9 years of experience in Information Security

  • At least 7 years of experience in people management

  • At least 5 years of experience with cyber policies, standards, and procedures

  • At least 5 years of experience in securing public cloud environments and services (AWS, GCP, Azure)

Preferred Qualifications:

  • Masters degree or PhD in Computer Science, Information Systems, or Engineering

  • 10+ years experience in technology and cybersecurity risk

  • 8+ years experience in leading applications security, vulnerability management and incident response

  • 8+ years experience performing security risk assessments

  • 5+ years experience in security automation and integrating security into software development pipelines

  • 5+ years experience working with industry frameworks and compliance requirements (NIST CSF, FFIEC CAT, CIS RAM, FAIR, PCI DSS)

  • 3+ years experience with information technology audit or compliance management

  • 2+ years in payment security including securing digital payments and payment cryptography

  • 2+ years experience utilizing agile methodologies within DevOps environments

  • Industry-recognized professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Solutions Architect, Certified Information Security Manager (CISM)

  • 4+ years experience in a regulated environment

  • 2+ years experience in financial services industry

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer anyimmigrationrelated support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that requireimmigrationsupport from an employer).

McLean, VA: $308,700 - $352,300 for Sr. Dir, Cyber Technical Plano, TX: $280,600 - $320,200 for Sr. Dir, Cyber Technical Richmond, VA: $280,600 - $320,200 for Sr. Dir, Cyber TechnicalThis role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

Show more

These jobs might be a good fit

22.08.2025
CO

Capital One Dir Information Security Officer United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Be a leader at a premiere technology and financial services company. Build cybersecurity strategy tailored for the line of business, partnering closely with business leaders, the Divisional CIO, and cybersecurity...
Description:
Dir, Information Security Officer

Director, Information Security Officer, you will lead security for one of our key lines of business. You will work with business and technology partners to achieve goals and objectives in a secure manner with a heavy forward lean on modern software and technology architectures. At Capital One, you will help advise on strategic initiatives, programs, and projects to create business value in a risk-based and agile manner. You will build and lead a team of talented and experienced Information Security professionals delivering product security advisory services to a line of business portfolio. You are pragmatic and practical in your understanding of security and associated risks, but also willing to know when to collaborate with experts and escalate as required. You believe in making the secure way easy and see yourself as an advocate in the value of data driven business decisions and products. You are comfortable with modern software, big data ecosystems, and cloud based technologies as well as associated protective methods.

Responsibilities:

  • Be a leader at a premiere technology and financial services company

  • Build cybersecurity strategy tailored for the line of business, partnering closely with business leaders, the Divisional CIO, and cybersecurity leaders across the company.

  • Lead a team of Product Security advisory professionals, responsible for Divisional cyber strategy integration and execution, identification and management of risk for top business initiatives and technology platforms, threat and vulnerability management, incident management, supply chain cyber risk management, cyber risk oversight and reporting.

  • Deliver Cyber agenda and integration of Information Security within business objectives for line of business area

  • Serve as the central point of contact for your line of business technology executives into Capital One’s Cyber risk management priorities

  • Educate and influence executive leadership and associates to effectively leverage security capabilities and solutions to mitigate risks and emerging threats

  • Provide security expertise on prioritizing and managing information security risks and initiatives

  • Escalate and manage cyber security risk

  • Provide regular updates to executive leadership with your line of business on the overall information security health and risk environment

  • Work with business leadership to anticipate their objectives and needs to better serve them

  • Plays a key leadership role within Cyber’s community of leaders, drives innovation activity as an outcome; partner extensively with other Cyber and Technology organizations to derive solutions enabling industry leading products

  • Build relationships and influence with risk management functions across lines of defense

  • Become knowledgeable and advise on Capital One’s Cyber’s services, policies, procedures and standards

  • Staying current on the changing regulatory environment and understanding the impacts to the organization

  • Recruits, develops, and retains top talent, and uses excellent people leadership skills.

  • Build your team to provide top-notch information security and risk management expertise and guidance

About You:

  • You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including business executives, technology leaders, and enterprise suppliers

  • You are a focused individual who thrives in a fast-paced, dynamic, and collaborative team environment.

  • You have a deep passion for securing forward leaning, modern computing platforms

  • You are comfortable with technologies and innovation including Generative AI, Data Lakes, Cloud Services, Containers, Microservices, Serverless, APIs, DevOps, Encryption and Zero Trust

  • You have a strong desire to continually learn about new technologies

  • You enjoy leveraging your engineering experience to problem solve and continually learn new technology concepts to solve issues.

  • You display strong judgment, data/risk based decisioning, leadership, integrity, and communication skills.

  • You are able to tailor communications and analysis to the intended audience.

  • You have a passion and expertise in cybersecurity, with an ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions.

  • You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality

  • You are able to work well under minimal supervision

  • You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives

  • You have the ability to describe the risks of a security exposure or vulnerability in business-impact terms

Basic Qualifications:

  • Bachelor's degree

  • At least 7 years of experience in Information Security

  • At least 5 years of experience in people management

  • At least 5 years of experience with cyber policies, standards, and procedures

  • At least 5 years of experience in securing public cloud environments and services (AWS, GCP, Azure)

Preferred Qualifications:

  • Masters degree or PhD in Computer Science, Information Systems, or Engineering

  • 10+ years experience in information technology and cybersecurity

  • 7+ years experience in leading applications security, vulnerability management and incident response

  • 7+ years experience performing security risk assessments

  • 5+ years experience working with industry frameworks and compliance requirements (NIST CSF, FFIEC CAT, CIS RAM, FAIR, PCI DSS)

  • 2+ years experience utilizing agile methodologies within DevOps environments

  • Industry-recognized professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Solutions Architect, Certified Information Security Manager (CISM)

  • 4+ years experience in a regulated environment

  • 2+ years experience in financial services industry

  • 2+ years of experience with modern Payment network security technologies

  • 2+ years of experience in security integration for Mergers and Acquisitions

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Chicago, IL: $239,900 - $273,800 for Director, Cyber Technical McLean, VA: $263,900 - $301,200 for Director, Cyber Technical New York, NY: $287,800 - $328,500 for Director, Cyber TechnicalThis role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

Show more

These jobs might be a good fit

21.08.2025
CO

Capital One Manager Information Security Office Consultant United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Act as a central point of contact for your line of business to the rest of Capital One’s Information Security and Risk Management. Coordinate and execute proactive Information Security consulting...
Description:
Manager, Information Security Office Consultant


Responsibilities:

  • Act as a central point of contact for your line of business to the rest of Capital One’s Information Security and Risk Management

  • Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management

  • Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards

  • Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes

  • Escalate and manage cyber security risk

  • Provide ad hoc support on special Information Security hot topics for the business

  • Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment

  • Work with line of business leadership to anticipate their objectives and needs to better serve the line of business

About You:

  • You have a desire to work in a very fast moving, forward leaning, and modern computing environment

  • You have a deep passion for Securing modern computing platforms

  • You have a strong desire to continually learn about new technologies

  • You possess strong conceptual thinking and communication skills

  • You are able to work well under minimal supervision

  • You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors

  • You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality

  • You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives

Basic Qualifications:

  • High School Diploma, GED, or equivalent certification

  • At least 4 years of experience providing guidance and oversight of Security concepts

  • At least 3 years of experience performing security risk assessments and security architecture reviews

  • At least 3 years of experience with Architecture design, software design, networking or Cloud infrastructure

Preferred Qualifications:

  • Bachelor’s Degree

  • 6+ years of experience with Architecture design, software design, networking or Cloud infrastructure

  • 4+ years of experience in securing a public cloud environment (AWS, GCP, or Azure)

  • 2+ years of experience utilizing Agile methodologies

  • 2+ years of experience in Enterprise Monitoring

  • 2+ years of experience with technologies supporting finance, fintech, banking, payment cards, or a related domain

  • 2+ years of experience with web and mobile application security, and solid understanding of the OWASP Top Ten

  • 2+ years of experience with security testing, such as penetration testing, red teaming, vulnerability scanning, SAST and DAST

  • 2+ years of scripting or programming experience (Python, SQL, PHP, PowerShell)

  • Professional certifications such as AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP)

McLean, VA: $193,400 - $220,700 for Manager, Cyber Technical New York, NY: $211,000 - $240,800 for Manager, Cyber Technical Richmond, VA: $175,800 - $200,700 for Manager, Cyber TechnicalThis role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

Show more

These jobs might be a good fit

20.08.2025
CO

Capital One Senior Manager - Global Payment Network Information United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Act as a central Information Security point of contact for the Global Payment Networks line of business. Coordinate and execute proactive Information Security consulting to the business and technology teams...
Description:
Senior Manager - Global Payment Network Information Security Office (ISO) Consultant


Responsibilities:

The Senior Lead ISO Consultant will provide cyber security architecture advisory support needed to build the Technology & Business capabilities on a novel Modern platform, that will enable customer set-up, use, and management of a Capital One Credit Card, including Data Product. In this role, the responsibilities will include:

  • Act as a central Information Security point of contact for the Global Payment Networks line of business

  • Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management

  • Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards

  • Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.

  • Support security architecture and implementation needs for technology modernization efforts

  • Overseeing all cyber related dependencies across the multiple components being built for the modernization effort.

  • Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes

  • Escalate and manage cyber security risk

  • Provide ad-hoc support on special Information Security hot topics for the business

  • Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment

  • Work with line of business leadership to anticipate their objectives and needs to better serve the line of business

  • Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms.

  • Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations.

  • Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures.

About You:

  • You have a desire to work in a very fast moving, forward leaning, and modern computing environment

  • You have a deep passion for Securing modern computing platforms

  • You have a strong desire to continually learn about new technologies

  • You possess strong conceptual thinking and communication skills

  • You are able to work well under minimal supervision

  • You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors

  • You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality

  • You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives

Basic Qualifications:

  • High School Diploma, GED or equivalent certification

  • At least 6 years of experience working in cybersecurity or information technology

  • At least 5 years of experience providing guidance and oversight of cyber security concepts

  • At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews

  • At least 4 years of experience with cloud security

Preferred Qualifications:

  • Bachelor’s Degree

  • 7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)

  • 6+ years of cyber security advisory and technology consulting experience

  • 6+ years of experience in Cyber Risk Management

  • 3+ years of experience on cryptography, HSMs and similar systems

  • Knowledge of HPNS, ATM, Mainframe technologies and other payment networks infrastructure technologies

  • Experience in security integration for Mergers and Acquisitions

  • Experience with PCI and Payment Network Compliance.

  • Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Chicago, IL: $204,900 - $233,800 for Sr Manager, Cyber Technical McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber TechnicalThis role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

Show more

These jobs might be a good fit

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Find your next career move in the high tech industry with Expoint. Our platform offers a wide range of Information Officer job opportunities in the United States, Virginia, Arlington area, giving you access to the best companies in the field. Whether you're looking for a new challenge or a change of scenery, Expoint makes it easy to find your perfect job match. With our easy-to-use search engine, you can quickly find job opportunities in your desired location and connect with top companies. Sign up today and take the next step in your high tech career with Expoint.