Logo
Capital One

Cyber Risk and Analysis Lead

Capital One, Richmond, Virginia, United States, 23214

Save Job

Cyber Risk and Analysis Lead Capital One is seeking an energetic, self-motivated Risk and Analysis Manager with experience evaluating and analyzing technology and cybersecurity risks interested in becoming part of our Cyber team.

Responsibilities

Write comprehensive cybersecurity risk assessments identifying threats & vulnerabilities and recommend remediation.

Conduct formal, systematic threat modeling of IT systems using STRIDE methodology.

Apply deep knowledge of procedure-based controls of a cybersecurity program including qualitative risk analysis steps, vulnerability and patch management, threat modeling, Identity and Access Management (IAM), cybersecurity frameworks (NIST CSF, PCI-DSS and CIS).

Practice expert level assessment skills using technology-based controls of a cybersecurity program including cloud security, Artificial Intelligence / GenAI risks, penetration testing results, cryptography & network security fundamentals, malware defense, data loss prevention and endpoint security.

Compile professional security assessment reports, slides, and lead discussions to effectively communicate the risks and remediation options to partners.

Demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective.

Work independently to identify vulnerabilities in deployment of technologies, severity, and impact, and recommend risk-based options for remediation.

Actively collaborate with business partners, application architects and partner security teams to research and build security solutions aligned to business goals.

Learn advanced cybersecurity concepts including new and modern threat exploitation techniques of threat actors.

Achieve team commitments (and influence others to do the same) by using informal leadership & advanced communication skills.

Actively manage and elevate risk and customer-impacting issues within the day-to-day role to management.

Demonstrate excellent technical writing skills.

Mentor novices by providing learning tasks as well as work related tasks, direct the work of advanced beginners, and help them continue to grow.

Communicate effectively and promptly every day and lead cybersecurity discussions at Capital One. Provide oversight into security programs impacting decisions. Guide team to achieve key results for the assigned security assessment tasks.

Qualifications

High School Diploma, GED, or equivalent certification

At least 4 years of cybersecurity risk management experience

At least 4 years of experience troubleshooting end user issues

Preferred Qualifications

Bachelor's Degree

6+ years in cybersecurity

5+ years in 3rd party vendors risk assessment

2+ years of experience with Zero Trust architecture

2+ years of experience assessing security for cloud platforms such as SaaS, PaaS, and IaaS

2+ years of experience in network, OS, and Database security administration

CISM Certification

CISSP Certification

Chicago, IL: $144,000 - $164,400 McLean, VA: $158,400 - $180,800 Plano, TX: $144,000 - $164,400 Richmond, VA: $144,000 - $164,400

Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug‑free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries.

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position.

#J-18808-Ljbffr