Logo
Capital One

Cyber Risk and Analysis Lead

Capital One, Little Rock, Illinois, United States

Save Job

* Write comprehensive cybersecurity risk assessments identifying threats & vulnerabilities and recommend remediation.* Conduct formal, systematic threat modeling of IT systems using STRIDE methodology.* Apply deep knowledge of procedure-based controls of a cybersecurity program including qualitative risk analysis steps, vulnerability and patch management, threat modeling, Identity and Access Management (IAM), cybersecurity frameworks (NIST CSF, PCI-DSS and CIS).* Practice expert level assessment skills using technology-based controls of a cybersecurity program including cloud security, Artificial Intelligence / GenAI risks, penetration testing results, cryptography & network security fundamentals, malware defense, data loss prevention and endpoint security.* Compile professional security assessment reports, slides, and lead discussions to effectively communicate the risks and remediation options to partners.* Demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective.* Work independently to identify vulnerabilities in deployment of technologies, severity, and impact, and recommend risk-based options for remediation.* Actively collaborate with business partners, application architects and partner security teams to research and build security solutions aligned to business goals.* Learn advanced cybersecurity concepts including new and modern threat exploitation techniques of threat actors.* Achieve team commitments (and influence others to do the same) by using informal leadership & advanced communication skills.* Actively manage and escalate risk and customer-impacting issues within the day-to-day role to management.* Demonstrate excellent technical writing skills.* Mentor novices by providing learning tasks as well as work related tasks, direct the work of advanced beginners, and help them continue to grow.* Communicate effectively and promptly every day and lead cybersecurity discussions at Capital One. Provide oversight into security programs impacting decisions. Guide team to achieve key results for the assigned security assessment tasks.* High School Diploma, GED, or equivalent certification* At least 4 years of cybersecurity risk management experience* At least 4 years of experience troubleshooting end user issues* Bachelor's Degree* 6+ years in cybersecurity* 5+ years in 3rd party vendors risk assessment* 2+ years of experience with Zero Trust architecture* 2+ years of experience assessing security for cloud platforms such as SaaS, PaaS, and IaaS* 2+ years of experience in network, OS, and Database security administration* CISM Certification* CISSP CertificationCapital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. #J-18808-Ljbffr