As a Principal Analyst, Cyber Risk & Analysis in Technology Risk Management – you will play a key role in shaping second line’s independent point of view on cybersecurity, reliability, and tech risk, and analyzing the outcomes of first line’s analysis to enable robust challenge across assessments.
This includes researching industry and internal trends to scope scenarios for analysis and systematically analyzing, aggregating and comparing outputs of different scenarios.
Desired Outcomes:
Identify, interpret, and curate external data points to support and ground risk assessments
Review various risk products and supporting risk intelligence to extract key findings and analyze their applicability to other assessments
Respond to inquiries to provide grounding data points for specific assessments, research possible sources and their trustworthiness, and distill findings into succinct data points.
Understand risk metrics and interpret their relevance in the context of risk, and understand and communicate the risk implications of specific trends in those risk metrics
Create and distribute educational materials on cyber and tech industry trends and recent events and answer questions from the team
The ideal candidate:
Is a critical and analytical thinker, and has the ability to express a point of view supported by data (with both technical and non-technical audiences)
Raises concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization
Has a passion and expertise in technology and cybersecurity domains, and can be confident, respectful, and articulate when registering dissenting or unpopular opinions
Is able to collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to get consensus, socialize strategy, and achieve objectives
Can manage multiple parallel initiatives while maintaining superior results
Is execution oriented and a self-motivator
Displays personal resilience - the ability to to stay optimistic and keep people focused during crises or times of change
Basic Qualifications:
Bachelor’s degree or military experience
At least 2 years of experience managing, or consulting, or auditing in the fields of information security, or technology, or risk management
At least 2 years of experience with cybersecurity or technology metrics design and reporting
At least 2 years of experience with SQL, programming languages (Python, R), data visualization tools or statistical analysis concepts.
At least 1 professional security management certification (Open FAIR, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC))
Preferred Qualifications:
At least 1+ year experience with cybersecurity or technology risk assessments or cybersecurity, technology or compliance controls assessments
At least 1+ year experience developing and implementing industry controls frameworks (e.g. NIST 800-53, ISO 27001/27002), designing controls and/or testing controls design.
. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
משרות נוספות שיכולות לעניין אותך