Logo
Capital One

Cyber Risk and Analysis Lead

Capital One, Mc Lean, Virginia, us, 22107

Save Job

Join to apply for the

Cyber Risk and Analysis Lead

role at

Capital One

Overview Capital One is seeking an energetic, self-motivated Risk and Analysis Manager with experience evaluating and analyzing technology and cybersecurity risks interested in becoming part of our Cyber team.

Role Responsibilities

Write comprehensive cybersecurity risk assessments identifying threats & vulnerabilities and recommend remediation.

Conduct formal, systematic threat modeling of IT systems using STRIDE methodology.

Apply deep knowledge of procedure-based controls of a cybersecurity program including qualitative risk analysis steps, vulnerability and patch management, threat modeling, IAM, and cybersecurity frameworks (NIST CSF, PCI‑DSS, CIS).

Practice expert level assessment skills using technology-based controls of a cybersecurity program including cloud security, AI/GenAI risks, penetration testing results, cryptography & network security fundamentals, malware defense, data loss prevention and endpoint security.

Compile professional security assessment reports, slides, and lead discussions to effectively communicate the risks and remediation options to partners.

Demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective.

Work independently to identify vulnerabilities in deployment of technologies, severity, and impact, and recommend risk‑based options for remediation.

Actively collaborate with business partners, application architects and partner security teams to research and build security solutions aligned to business goals.

Learn advanced cybersecurity concepts including new and modern threat exploitation techniques of threat actors.

Achieve team commitments (and influence others to do the same) by using informal leadership & advanced communication skills.

Actively manage and elevate risk and customer‑impacting issues within the day‑to‑day role to management.

Demonstrate excellent technical writing skills.

Mentor novices by providing learning tasks as well as work related tasks, direct the work of advanced beginners, and help them continue to grow.

Communicate effectively and promptly every day and lead cybersecurity discussions at Capital One. Provide oversight into security programs impacting decisions. Guide team to achieve key results for the assigned security assessment tasks.

Basic Qualifications

High School Diploma, GED, or equivalent certification

At least 4 years of cybersecurity risk management experience

At least 4 years of experience troubleshooting end user issues

Preferred Qualifications

Bachelor's Degree

6+ years in cybersecurity

5+ years in 3rd party vendors risk assessment

2+ years of experience with Zero Trust architecture

2+ years of experience assessing security for cloud platforms such as SaaS, PaaS, and IaaS

2+ years of experience in network, OS, and Database security administration

CISM Certification

CISSP Certification

Salary Chicago, IL: $144,000 - $164,400 McLean, VA: $158,400 - $180,800 Plano, TX: $144,000 - $164,400 Richmond, VA: $144,000 - $164,400

Benefits Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well‑being.

EEO Statement Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non‑discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug‑free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries.

Metadata

Seniority level: Mid‑Senior level

Employment type: Full‑time

Job function: Research, Analyst, and Information Technology

Immigration At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position.

#J-18808-Ljbffr