Finding the best job has never been easier
Share
For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.
As a Director, Cyber Risk and Analysis, you will apply expertise on risk frameworks and best practices to assess current state, identify methodology gaps, and evaluate threats and/or business impact to enable advisory partnerships and effective oversight of tech and cyber risk across Capital One. You will lead risk aggregation initiatives, define mitigation strategies, prioritize and escalate recommendations to senior leadership. You will also participate in the design, socialization and implementation of risk management products and programs through your deep knowledge of risk assessments, information risk controls, regulatory and internal governance standards, data analysis, metrics / reporting, and customer engagement.
Responsibilities:
Maintains a broad, expert understanding of technology risk frameworks, has innate ability to leverage these frameworks in risk identification processes.
Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting risk management policies or programs; recommends sound, practical solutions to complex issues.
Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise.
Advises Accountable Executives of tech and cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management.
Exhibits strong critical thinking and communication skills,with proven ability to navigate the unknown to devise and socialize innovative risk management solutions.
Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change. Understands associated reporting metrics and is able to inform on tech and cyber risks.
Quickly and accurately analyzes data, assesses risk, & prioritizes potential risks to differentiate critical, high-risk, and low-risk issues, and remediate and escalate as appropriate.
Makes recommendations regarding changes to first line policy, procedures, and control programs to mitigate evolving risks.
Effectively self-challenges tech and cyber control and risk management programs as part of first line duties and escalates risks where appropriate.
Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement.
Basic Qualifications:
Bachelor's Degree or military experience
At least 5 years of experience with Technology Risk Management or Cyber Security Risk Management
At least 5 years of experience building risk control environments or risk frameworks
At least 5 years of experience in People Management
Preferred Qualifications:
Master’s Degree
Process or Project Management certification (i.e. Lean, Six Sigma, PMP), Business Management certification
10+ years of experience with Technology or Cyber Security Risk Management
9+ years of experience in People Management
. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
These jobs might be a good fit