Senior Manager, Cyber Risk and Analysis, Technology Risk Management
Company: Capital One
Location: Syosset
Posted on: January 24, 2023
Job Description:
Center 1 (19052), United States of America, McLean,
VirginiaSenior Manager, Cyber Risk and Analysis, Technology Risk
Management Technology Risk Management (TRM) is a growing
organization focused on providing expert advice, credible
challenge, and effective oversight of information security and
technology risk activities. The Associates that make up the TRM
team are highly-skilled information security, cyber, technology,
and risk management professionals who bring a wealth of experience
to deliver high-impact analysis and recommendations that are rooted
in direct knowledge of security and technology. Senior Manager,
Cyber Risk and Analysis, Technology Risk Management - will play a
key role in the execution of technical testing to support
technology risk identification, risk assessment, reporting, and
effective challenge of processes, controls, and capabilities,
including but not limited to material and high risk technology
changes. This individual will contribute to and act as leader
within a team of highly skilled resources to design and execute
Outcome Based Testing. As part of the second line of defense, this
position will also interact regularly with first line Cyber,
Technology, the Lines of Business, as well as other second line of
defense risk management offices to perform and support targeted
technical reviews of the effectiveness of the firm's controls
infrastructure and offer independent advice and recommendations
regarding ways to further mature the firm's cyber risk management
capabilities. Essential Functions (Responsibilities):
- Conduct analysis of artifacts from risk management platforms,
cyber operations, application security, and cloud infrastructure to
develop use cases for outcome based testing
- Design and execute outcome based testing to assess various risk
hypotheses
- Publish technical reports and presentations for risk owners,
senior management, and other stakeholders regarding risks
associated with new or emerging technologies
- Facilitate prioritization and timing of outcome based testing
using Agile methodology
- Collaborate effectively with colleagues, stakeholders, and
leaders across multiple organizations to achieve objectives
- Support process maturity within outcome based testing through
continual improvement of documentation, processes, and frameworks
Basic Qualifications:
- Bachelor's degree
- At least 6 years experience in cyber security
- At least 3 years experience operating in a cloud computing
environment (AWS, Microsoft Azure, or Google Cloud)
- At least 3 years experience with security frameworks (NIST CSF,
ISO, CIS, or COBIT)
- At least 2 years experience performing testing to identify
enterprise, network, system, endpoint, and application-level
security issues and risks
- At least one of the following professional security
certifications: ISC2 Certified Information Systems Security
Professional CISSP , Offensive Security Certified Professional OSCP
, GIAC Security Leadership GSLC , ISACA Certified Information
Security Manager CISM , or ISACA Certified Information Systems
Auditor CISA , or ISACA Certified in Risk and Information Systems
Control CRISC Preferred Qualifications:
- Master's degree
- Experience conducting penetration testing, red teaming, purple
teaming, or cloud security testing
- Experience working in financial services or other
highly-regulated sectors
- Experience supporting delivery of products using Agile
methodology
- One or more of the following cloud certifications: AWS
Solutions Architect - Associate, AWS Solutions Architect -
Professional, AWS Certified Security Specialty, AWS Developer -
Associate, or AWS Devops Engineer Professional, ISC2 Certified
Cloud Security Professional CCSP, or CSA Certificate of Cloud
Security Knowledge CCSK At this time, Capital One will not sponsor
a new applicant for employment authorization for this position. The
minimum and maximum full-time annual salaries for this role are
listed below, by location. Please note that this salary information
is solely for candidates hired to perform work within one of these
locations, and refers to the amount Capital One is willing to pay
at the time of this posting. Salaries for part-time roles will be
prorated based upon the agreed upon number of hours to be regularly
worked. Location is New York City: $188,814 - $222,758 for Sr.
Manager, Cyber Risk & Analysis Candidates hired to work in other
locations will be subject to the pay range associated with that
location, and the actual annualized salary amount offered to any
candidate at the time of hire will be reflected solely in the
candidate's offer letter. This role is also eligible to earn
performance based incentive compensation, which may include cash
bonus(es) and/or long term incentives (LTI). Incentives could be
discretionary or non discretionary depending on the plan. Capital
One offers a comprehensive, competitive, and inclusive set of
health, financial and other benefits that support your total
well-being. Learn more at the Capital One Careers website .
Eligibility varies based on full or part-time status, exempt or
non-exempt status, and management level. No agencies please.
Capital One is an Equal Opportunity Employer committed to diversity
and inclusion in the workplace. All qualified applicants will
receive consideration for employment without regard to sex, race,
color, age, national origin, religion, physical and mental
disability, genetic information, marital status, sexual
orientation, gender identity/assignment, citizenship, pregnancy or
maternity, protected veteran status, or any other status prohibited
by applicable national, federal, state or local law. Capital One
promotes a drug-free workplace. Capital One will consider for
employment qualified applicants with a criminal history in a manner
consistent with the requirements of applicable laws regarding
criminal background inquiries, including, to the extent applicable,
Article 23-A of the New York Correction Law; San Francisco,
California Police Code Article 49, Sections ; New York City's Fair
Chance Act; Philadelphia's Fair Criminal Records Screening Act; and
other applicable federal, state, and local laws and regulations
regarding criminal background inquiries.If you have visited our
website in search of information on employment opportunities or to
apply for a position, and you require an accommodation, please
contact Capital One Recruiting at 1- or via email at . All
information you provide will be kept confidential and will be used
only to the extent required to provide needed reasonable
accommodations.For technical support or questions about Capital
One's recruiting process, please send an email to Capital One does
not provide, endorse nor guarantee and is not liable for
third-party products, services, educational tools or other
information available through this site.Capital One Financial is
made up of several different entities. Please note that any
position posted in Canada is for Capital One Canada, any position
posted in the United Kingdom is for Capital One Europe and any
position posted in the Philippines is for Capital One Philippines
Service Corp. (COPSSC).
Keywords: Capital One, New Rochelle , Senior Manager, Cyber Risk and Analysis, Technology Risk Management, Executive , Syosset, New York
Didn't find what you're looking for? Search again!
Loading more jobs...