Logo
Capital One

Director strategy

Capital One, Hartford, Connecticut, us, 06112


West Creek 3 (12073), United States of America, Richmond, VirginiaDirector, Metrics Strategy

Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk.For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and their Technology Risk Management (TRM) organization oversee cybersecurity but also have broader responsibilities for reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.As the Director, Metrics Strategy, you will create a strategy for how to use metrics to drive change; help us update our suite of metrics for cybersecurity, technology risk, and developer quality; and drive the implementation of those metrics to effect systemic change. You will be an independent contributor who will partner with subject matter experts in TRM and across all three lines of defense.The successful candidate will be a seasoned leader with strong knowledge of quantitative methods applied to technology/cyber risk, who can think strategically, who is intellectually curious, and who thrives in a data-driven environment.Responsibilities

Understand our current approach and develop a strategy to better use metrics, dashboards, and governance fora to drive change. The intended audience starts at the program manager level and progresses up through the Board of Directors and formal risk appetite metrics.Develop suites of metrics across the technology, technology risk, and cybersecurity domains, aligned to industry frameworks.Engage stakeholders across the first, second, and third lines of defense to align on the metrics and thresholds.Dive deeply into different domains to understand the shortcomings and limitations of metrics and ensure they are appropriately documented and communicated.Monitor metrics, investigate anomalies, and escalate necessary response actions.Basic Qualifications

Bachelor’s degree or military experienceAt least 10 years of experience in cybersecurity or technology riskAt least 2 years of experience in cybersecurity or technology risk metricsAt least 2 years of experience with governance foraPreferred Qualifications

Bachelor’s degree in computer science, mathematics, or engineering.Master’s degree in computer science, mathematics, or engineering.At least 10 years of experience in cybersecurity or technology risks related to resilience, reliability, or code quality (e.g., the DORA work).At least 2 years of experience in cloud computing.An understanding of more than one of the following domains: cybersecurity, site reliability engineering, dev/ops, and developer excellence.Experience revamping an organizational metrics program.Experience with governance fora in which senior leaders use metrics to manage their organizations.Execution oriented and a self-motivator.Ability to collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to get consensus, socialize strategy, and achieve objectives.Passion and expertise in technology risk and cybersecurity domains, with an ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions.Critical analytical thinker, including the ability to express a point of view supported by data (with both technical and non-technical audiences).At this time, Capital One will not sponsor a new applicant for employment authorization for this position.This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace.

#J-18808-Ljbffr