Capital One
Director, Technology Risk - Enterprise Services Risk
Capital One, Richmond, Virginia, United States, 23214
Overview
Director, Technology Risk - Enterprise Services Risk. The Enterprise Services Risk organization focuses on attracting innovative, pioneering, collaborative, and highly skilled professionals. We operate at the forefront of risk management, supporting novel and developing technologies as well as critical business strategies. As a Technology Risk Director in Capital One’s Tech and Product Risk Office, you will apply risk management, cyber, and technical expertise to the company’s Technology organization. You will partner across Enterprise Services, Divisional CIOs, and Information Security teams to develop and support risk solutions that enable innovation while protecting customers, shareholders, and associates. You will collaborate with second lines of defense to implement risk and control tools, techniques, and frameworks for the Technology organization, driving organizational and strategic change through risk identification, measurement, analysis, and reporting. Responsibilities
Serve as the Technology Risk Guide leader for the Enterprise Platforms Technology and Product Leadership Team and respective software engineering teams to propel technology risk agenda and help informed risk-based decisions. Assist Tech and Product Risk leadership in delivering against their strategy and services. Provide oversight and guidance on key strategic Technology initiatives. Serve as interdepartmental advisor interfacing with technology lines of business, second line Technology and Cyber organizations, and Compliance; collaborate across multiple organizations to achieve objectives. Identify and implement continual program enhancements based on industry standards and best practices related to risk management (especially technology risk) aligned with Capital One’s strategic risk direction. Gather risk and control data and reporting; perform initial analysis or evaluate data provided by team analysts. Design and implement internal risk and control governance processes. Influence leaders within Tech, Cyber, Product, second line risk organizations, the developer community, and Internal Audit on key technology risks and actions needed. Develop and monitor risk analysis, perform deep dive investigations, and drive risk initiatives to minimize risk posture and strengthen control effectiveness. Support Risk Control and Self Assessments (RCSAs). Understand, document, and analyze current state capabilities using risk methods; leverage benchmarking to determine best practices. Write and revise documents such as policies, standards, procedures, and guidelines; develop processes, tools, templates, and job aids; draft and deliver presentations to enable risk method usage. Basic Qualifications
High School Diploma, GED or Equivalent Certification At least 7 years of experience in Cybersecurity, Technology, Risk Management, or External Audit, or a combination At least 7 years of experience in project, process, or program management At least 7 years of experience planning and leading IT audits or risk assessments At least 7 years of People Management experience Preferred Qualifications
Bachelor's Degree or Military Experience At least 10 years of experience in Cybersecurity, Technology, Risk Management or External Audit, or a combination At least 10 years of experience in project, process, or program management Cyber and Risk Certifications (CRISC, CISM, CRCM, CAMS, CIPP, ABA Risk Management Certification) Excellent verbal presentation and written communication skills Excellent problem-solving, analytical, and critical thinking skills Consulting experience with a Big 4 firm is a plus Note:
At this time, Capital One will not sponsor a new applicant for employment authorization for this position. Compensation and Benefits
The minimum and maximum full-time annual salaries are listed below by location. Salaries for part-time roles will be prorated. This information is intended for candidates hired to work within the listed locations and refers to the amount Capital One is willing to pay at the time of posting. McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis Candidates hired to work in other locations will be subject to the pay range associated with that location. The actual salary offered will be in the offer letter. This role may be eligible for performance-based incentive compensation, which may include cash bonuses and/or long-term incentives (LTI). Capital One offers comprehensive health, financial, and other benefits. Eligibility varies by status. See the Capital One Careers site for details. This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with laws. Capital One promotes a drug-free workplace and will consider qualified applicants with criminal histories in accordance with applicable laws. Additional Information
Capital One does not provide, endorse, or guarantee third-party products, services, or information available through this site. Capital One Financial is made up of several entities; postings may reflect the correct entity based on location.
#J-18808-Ljbffr
Director, Technology Risk - Enterprise Services Risk. The Enterprise Services Risk organization focuses on attracting innovative, pioneering, collaborative, and highly skilled professionals. We operate at the forefront of risk management, supporting novel and developing technologies as well as critical business strategies. As a Technology Risk Director in Capital One’s Tech and Product Risk Office, you will apply risk management, cyber, and technical expertise to the company’s Technology organization. You will partner across Enterprise Services, Divisional CIOs, and Information Security teams to develop and support risk solutions that enable innovation while protecting customers, shareholders, and associates. You will collaborate with second lines of defense to implement risk and control tools, techniques, and frameworks for the Technology organization, driving organizational and strategic change through risk identification, measurement, analysis, and reporting. Responsibilities
Serve as the Technology Risk Guide leader for the Enterprise Platforms Technology and Product Leadership Team and respective software engineering teams to propel technology risk agenda and help informed risk-based decisions. Assist Tech and Product Risk leadership in delivering against their strategy and services. Provide oversight and guidance on key strategic Technology initiatives. Serve as interdepartmental advisor interfacing with technology lines of business, second line Technology and Cyber organizations, and Compliance; collaborate across multiple organizations to achieve objectives. Identify and implement continual program enhancements based on industry standards and best practices related to risk management (especially technology risk) aligned with Capital One’s strategic risk direction. Gather risk and control data and reporting; perform initial analysis or evaluate data provided by team analysts. Design and implement internal risk and control governance processes. Influence leaders within Tech, Cyber, Product, second line risk organizations, the developer community, and Internal Audit on key technology risks and actions needed. Develop and monitor risk analysis, perform deep dive investigations, and drive risk initiatives to minimize risk posture and strengthen control effectiveness. Support Risk Control and Self Assessments (RCSAs). Understand, document, and analyze current state capabilities using risk methods; leverage benchmarking to determine best practices. Write and revise documents such as policies, standards, procedures, and guidelines; develop processes, tools, templates, and job aids; draft and deliver presentations to enable risk method usage. Basic Qualifications
High School Diploma, GED or Equivalent Certification At least 7 years of experience in Cybersecurity, Technology, Risk Management, or External Audit, or a combination At least 7 years of experience in project, process, or program management At least 7 years of experience planning and leading IT audits or risk assessments At least 7 years of People Management experience Preferred Qualifications
Bachelor's Degree or Military Experience At least 10 years of experience in Cybersecurity, Technology, Risk Management or External Audit, or a combination At least 10 years of experience in project, process, or program management Cyber and Risk Certifications (CRISC, CISM, CRCM, CAMS, CIPP, ABA Risk Management Certification) Excellent verbal presentation and written communication skills Excellent problem-solving, analytical, and critical thinking skills Consulting experience with a Big 4 firm is a plus Note:
At this time, Capital One will not sponsor a new applicant for employment authorization for this position. Compensation and Benefits
The minimum and maximum full-time annual salaries are listed below by location. Salaries for part-time roles will be prorated. This information is intended for candidates hired to work within the listed locations and refers to the amount Capital One is willing to pay at the time of posting. McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis Candidates hired to work in other locations will be subject to the pay range associated with that location. The actual salary offered will be in the offer letter. This role may be eligible for performance-based incentive compensation, which may include cash bonuses and/or long-term incentives (LTI). Capital One offers comprehensive health, financial, and other benefits. Eligibility varies by status. See the Capital One Careers site for details. This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with laws. Capital One promotes a drug-free workplace and will consider qualified applicants with criminal histories in accordance with applicable laws. Additional Information
Capital One does not provide, endorse, or guarantee third-party products, services, or information available through this site. Capital One Financial is made up of several entities; postings may reflect the correct entity based on location.
#J-18808-Ljbffr