Capital One - Petersburg, VA

posted 5 days ago

Full-time - Senior
Petersburg, VA
51-100 employees
Credit Intermediation and Related Activities

About the position

The Senior Manager, Technology Change Risk Oversight at Capital One plays a crucial role in overseeing technology processes, controls, and capabilities, particularly focusing on high-risk technology changes. This position requires collaboration with various stakeholders to ensure effective risk management and compliance with cybersecurity standards. The role demands a strong technical background, particularly in cloud services and technology risk management, to provide independent assessments and recommendations for improving the firm's cyber risk management capabilities.

Responsibilities

  • Provide technical leadership in assessing the practices of designing, developing, testing and implementing cloud native solutions.
  • Evaluate proposed and approved cloud technical solutions for automation, resiliency, performance, scalability, and security.
  • Evaluate complex technological and business environment migrations to the cloud and integrated end-to-end solution options.
  • Build and maintain relationships with technical leaders, business owners, engineers and other stakeholders to understand and evaluate implementation plans.
  • Keep up-to-date on cutting edge technology, standards, protocols and tools relevant to cloud native architecture and emerging AWS services.
  • Demonstrate strong analytical, problem-solving, and decision-making skills.
  • Communicate and drive complex technology solutions to broad audiences including executives and product managers.
  • Define, structure and plan work independently.
  • Perform independent risk assessment of the cloud environment focusing on architecture, engineering, networking, governance.
  • Provide expertise and advice regarding the effectiveness of device configurations and IT architecture.
  • Consult with risk owners on the design and implementation of mitigating controls associated with emerging technologies.
  • Draft and publish independent reports for risk owners and senior management regarding risks associated with new technologies.

Requirements

  • Bachelor's Degree or military experience
  • At least 5 years of experience managing, consulting, auditing, or working in information security or information technology
  • At least 3 years experience with Public Cloud implementations

Nice-to-haves

  • Master's Degree in Computer Science or Engineering
  • Professional certification (AWS Certified Solutions Architect, AWS Certified Security Specialty, AWS SysOps Administrator, or CISSP)
  • Experience with Information Security at the policy, architecture or implementation level
  • Ability to communicate clearly and interact effectively at all levels of the organization
  • Experience with identifying and communicating key risks related to cloud native implementations
  • Experience drafting reports or analytic assessments for senior management
  • Experience with analysis of emerging threats
  • Passion and expertise in cybersecurity and technology risk
  • Experience with threat modeling frameworks (STRIDE, OWASP Top 10, MITRE ATT&CK)
  • Familiarity with controls and control frameworks (NIST Cybersecurity Framework, NIST 800-53, CIS Top 20, ISO, COBIT)
  • Prior experience working in financial services or other highly-regulated sectors

Benefits

  • Comprehensive health benefits
  • Financial benefits including performance-based incentives
  • Inclusive workplace policies
  • Support for total well-being
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service