Logo
Capital One

Director, Technology Risk- Enterprise Services Risk

Capital One, Mc Lean, Virginia, us, 22107

Save Job

Overview

Director, Technology Risk - Enterprise Services Risk at Capital One. The Enterprise Services Risk organization focuses on attracting innovative, collaborative, and highly skilled professionals to lead risk management for novel and developing technologies and critical business strategies. We value diverse perspectives and experiences as we redefine the financial sector. In this role, you will apply risk management, cyber, and technical expertise to Capital One’s Technology organization. You will partner across Enterprise Services, Divisional CIOs, and Information Security teams to develop and support risk solutions that enable innovation while protecting customers, shareholders, and associates. You will collaborate with second lines of defense to lead and implement risk and control tools, techniques, and frameworks for the Technology organization, driving organizational and strategic change through risk identification, measurement, analysis, and reporting. Responsibilities

Serve as the Technology Risk Guide leader for the Enterprise Platforms Technology and Product Leadership Team and respective software engineering teams to propel technology risk agenda and help them make informed risk-based decisions. Assist Tech and Product Risk leadership in delivering against their strategy and services. Provide oversight and guidance on key strategic Technology initiatives. Serve as interdepartmental advisor, interfacing with technology lines of business and other areas such as second line Technology and Cyber organizations and Compliance; collaborate effectively across multiple organizations to achieve objectives. Identify and implement continual program enhancements based on industry standards and best practices related to risk management (especially technology risk) aligned with Capital One’s strategic risk direction. Gather risk and control data and reporting; perform initial analysis or evaluate data provided by team analysts. Design and implement internal risk and control governance processes. Influence leaders within Tech, Cyber, Product, second line risk organizations, the developer community, and Internal Audit on key technology risks and actions needed. Develop and monitor risk analysis, perform deep dive investigations, and drive specific risk initiatives to minimize risk posture and strengthen overall control suite effectiveness. Support Risk Control and Self Assessments (RCSAs). Understand, document, and analyze current state capabilities leveraging risk methods; leverage industry benchmarking to determine best practices and lessons learned regarding components of the risk framework. Demonstrate advanced knowledge of cloud computing and third-party collaboration platforms (e.g., Google apps, Zoom, Slack, Confluence). Familiarity with Generative AI technologies, including safeguards and associated risk management activities. Write and revise documents such as policies, standards, procedures, and guidelines; develop and enhance processes, tools, templates, and job aids; draft, contribute to, edit, and deliver presentations for risk methods. Basic Qualifications

High School Diploma, GED or Equivalent Certification At least 7 years of experience in Cybersecurity, Technology, Risk Management, or External Audit, or a combination At least 7 years of experience in project, process, or program management At least 7 years of experience planning and leading IT audits or risk assessments At least 7 years of People Management experience Preferred Qualifications

Bachelors Degree or Military Experience At least 10 years of experience in Cybersecurity, Technology, Risk Management or External Audit, or a combination At least 10 years of experience in project, process, or program management Cyber and Risk Certifications (CRISC, CISM, CRCM, CAMS, CIPP, ABA Risk Management Certification) Excellent verbal presentation and written communication skills to confidently interact with the cyber organization and enterprise stakeholders Excellent problem-solving, analytical, and critical thinking skills Consulting experience with a Big 4 firm is a plus At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The minimum and maximum full-time annual salaries for this role are listed below, by location. This information is solely for candidates hired to work within these locations and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based on hours worked. Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis Candidates hired to work in other locations will be subject to the pay range associated with that location; the actual salary offered will be reflected in the offer letter. This role is eligible for performance-based incentive compensation, which may include cash bonuses and/or long-term incentives. Capital One offers a comprehensive set of benefits that support overall well-being. This role is expected to accept applications for a minimum of 5 business days. No agencies, please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in accordance with applicable laws. Capital One promotes a drug-free workplace and may consider qualified applicants with criminal histories as allowed by law. If you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or RecruitingAccommodation@capitalone.com. For technical support or questions about Capital One's recruiting process, email Careers@capitalone.com. Capital One does not endorse or guarantee third-party products or services available through this site. Some positions posted may be for Capital One Canada, Capital One Europe, or Capital One Philippines Service Corp. Seniority level

Director Employment type

Full-time Job function

Information Technology

#J-18808-Ljbffr