Logo
Capital One

Sr. Director, Cyber Risk & Analysis | Retail Bank

Capital One, Richmond, Virginia, United States, 23214


Sr. Director, Cyber Risk & Analysis | Retail Bank

Summary:Capital One, a Fortune 500 company and one of the nation's top 10 banks, offers a broad spectrum of financial products and services to consumers, small businesses, and commercial clients. Our mission is to create one of the nation's great banks, and we have the necessary ingredients: a strong balance sheet, resilient businesses, a massive customer franchise, strong analytical capabilities, and great people. We nurture a work environment where people with a variety of thoughts, ideas, and backgrounds, guided by our shared Values, come together to make Capital One a great company - and a great place to work.As a Senior Director, Cyber Risk and Analysis, you will apply expertise on cyber best practices to assess the current state, identify gaps, and assess cyber risk, threats, and business impact. Defines mitigation strategies, prioritizes, and escalates recommendations. Participates in the design and implementation of cyber control programs. Cybersecurity area-specific SME (knowledge of risk frameworks, information security risk assessments, information risk controls, regulatory and internal governance), data analysis (metrics and reporting), & customer engagement.Responsibilities:Possesses an understanding of technology systems at an aggregate level, including networks, applications, cloud computing, and data.Maintains a broad understanding of relevant operating systems and their respective vulnerabilities to quickly identify the severity of potential issues.Demonstrates a broad understanding of major categories of cyber threats, how those threats can occur in our environment, and the measures required to safeguard the enterprise.Leverages reporting & tools to perform analysis on different types of projects, efforts, or datasets & uses data to inform policies and drive change. Understands associated reporting metrics and is able to inform on cyber risk.May use code to perform and/or automate analysis and repeatable tasks, but not a baseline requirement for the role. Leverages tools (e.g. Excel/Gsheets) to analyze data and create charts to support cyber risk management efforts.Quickly and accurately analyzes data, assesses risk, & prioritizes published vulnerabilities and potential risks to differentiate critical, high-risk, and low-risk issues, and escalate as appropriate.Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting cybersecurity policies or programs; recommends sound, practical solutions to complex issues.Makes recommendations regarding changes to policy, procedures, and control programs to mitigate evolving risks.Effectively self-challenges cyber control programs as part of first-line duties and escalates risks where appropriate.Demonstrates sound lifecycle program management to include documenting and communicating action plans, impediments and risks, and stakeholder engagement.Reports on vulnerability assessment to ensure proper functionality and alignment with Information Security Standards.Advises Accountable Executives of cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management.Keeps pace with the evolving cyber threat landscape to ensure ongoing relevance of cyber risk mitigation and has knowledge of leading Technology and Cybersecurity frameworks.Basic Qualifications:Bachelor's Degree or military experienceAt least 7 years of experience with Technology or Cyber Security Risk ManagementAt least 7 years of experience in People ManagementPreferred Qualifications:Master's DegreeProcess or Project Management certification (i.e. Lean, Six Sigma, PMP), Business Management certification10+ years of experience with Technology or Cyber Security Risk Management9+ years of experience in People Management

#J-18808-Ljbffr