Information Security Office

2 days ago


McLean VA United States Capital One Full time

Center 3 (19075), United States of America, McLean, Virginia

Information Security Office (ISO) Product Security Risk Manager

Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years, fully exiting our data centers. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk.

Cybersecurity Risk professionals at Capital One are trusted expert advisers who shape decisions, challenge activities to ensure they meet our standards, and generally oversee technology, cybersecurity, and information security risk across the business and the central technology organization.

As an associate in Capital One's Cyber Information Security Office, you will work with top talent in an entrepreneurial environment to solve problems and drive solutions to help the company reduce cyber risk. You will be challenged to excel alongside the brightest talent in the industry and be rewarded for your achievements. The demands and high-visibility nature of this position require an expert with a proven ability to work independently in a fast-paced environment and who can begin contributing immediately.

Job Responsibilities:
  1. Analyze and interpret industry standards, regulations, and best practices to develop risk management tooling to identify cyber risk trends, gap analysis, or maturity opportunities.
  2. Normalize and translate cyber risks at the organizational level to support a fully integrated, prioritized, enterprise-wide view of organizational risks to drive strategic and business decisions.
  3. Incorporate cybersecurity risk information into the organization's enterprise risk management program to provide a fully integrated, prioritized, enterprise-wide view of organizational risks.
  4. Help to enhance cyber risk management processes across Capital One by providing thought leadership, oversight, and coordination with other risk management activities across the company.
  5. Aggregate and evaluate risks, develop and maintain a risk register, perform risk analysis and quantification to enumerate top risks and provide risk reporting.
  6. Perform operational cyber risk assessments, identifying inherent risks, determining control suite effectiveness, and residual risk.
  7. Analyze information to proactively identify risks, trends, and process improvements; supporting reporting on risk topics to management.
  8. Assist and drive project and program delivery, including project and process management, reporting, and engagement in senior leadership meetings.
  9. Build successful relationships with Tech, Cyber, and Enterprise Risk to understand the impact of cyber risk on business processes.
  10. Participate in risk and other management forums and contribute to continuous improvement of risk and project or program management practices.
Candidates for this role will have:
  1. Deep understanding of risk management principles, expertise in assessing cybersecurity controls, and a strong technical background.
  2. Experience in risk evaluation or assessment methodologies, risk analysis, and risk reporting.
  3. Self-prioritize and effectively plan your own work activities managing multiple priorities and tasks across the team to deliver quality results.
  4. Establish and maintain good working relationships during engagement. Effectively communicate information and project process to team and other stakeholders involved.
  5. Advanced skill in presenting findings, conclusions, alternatives, and information clearly and concisely.
Basic Qualifications:
  1. High School Diploma, GED, or equivalent certification.
  2. At least 4 years of experience in project management leading cross-functional projects in Risk.
  3. At least 4 years of experience with Risk Management Frameworks (RMF).
  4. At least 4 years of experience in cybersecurity, risk, or technology industry standards (ISO 27001, NIST CSF and 800 series, MITRE ATTACK, MITRE DEFEND, FFIEC, COBIT, PCI-DSS, or FAIR).
  5. At least 4 years of experience developing, evaluating, or implementing cybersecurity, information technology, or risk assessment activities.
Preferred Qualifications:
  1. Bachelor's Degree.
  2. 2+ years of experience with cloud risk, governance, control, and security.
  3. CISA, CISM, CRISC, or CISSP Certification.

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration-related support for this position.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being.

This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace.

#J-18808-Ljbffr

  • Suitland, MD, United States Information Systems Solutions, Inc. Full time

    Information Systems Solutions (ISS) is currently looking to hire multiple Information System Security Officers (ISSOs) on a full time, permanent basis to support the Office of Naval Intelligence. These opportunities must be performed onsite in Washington D.C. and require an active Top Secret w/ SCI eligibility security clearance (minimum). Active TS/SCI...


  • McLean, VA, United States McIntire Solutions, LLC Full time

    Title: Information Systems Security Officer Location: McLean, VA McIntire Solutions is seeking an ISSO to support our McLean Customer. Responsibilities include, but are not limited to: Provide support to senior ISSOs for implementing, and enforcing information systems security policies, standards, and methodologies Assist...


  • McLean, United States Logistics Management Institute Full time

    Overview LMI is a consultancy dedicated to powering a future-ready, high-performing government, drawing from expertise in digital and analytic solutions, logistics, and management advisory services. We deliver integrated capabilities that incorporate emerging technologies and are tailored to customers’ unique mission needs, backed by objective research and...


  • McLean, United States Booz Allen Hamilton Full time

    Job Number: R0210238Information Systems Security OfficerKey Role:Join a team of communications and systems engineers supporting engineering, sustainment, and management of communications systems. Perform ongoing system analyst activities for programs. Perform risk assessments of systems and equipment, assist engineers with identifying solutions for...


  • Springfield, VA, United States Parsons Corporation Full time

    What Required Skills You'll Bring:Active TS/SCI.Ability to obtain and maintain a CI POLY.Bachelor's degree or equivalent experience in a related field.7 - 10 years of relevant work experience.What You'll Be Doing:Prepare security documentation for seven systems to include test plan, security plans, hardware list, software list data flow diagrams, standard...


  • McLean, United States Harmonia Holdings Group, LLC Full time

    Harmonia Holdings Group, LLC, an award-winning federal government contractor, has an exciting opportunity for a Information Security Specialist to join our team. Essential Job Functions:Responsibilities include analysis, design, development, testing, data staging, and implementation activities.Responsible for delivering a high-quality application with a...


  • McLean, United States Capital One Financial Corporation Full time

    Act as a central Information Security point of contact for the Commercial line of business. Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Secur Security, Information, Associate, Office, Consultant, Principal, Banking


  • McLean, United States Top Notch Security Inc. Full time $21

    Top Notch Security Inc., is looking for dynamic individuals who are honest, dependable, career-minded, and looking to meet the challenges as a contract security officer at a federal location in McLean, VA.  Objective: Provide professional security services by protecting individuals and properties within established company guidelines and in accordance with...

  • Security Officer

    4 weeks ago


    Sidney, OH, United States Merchants Security Full time

    Merchants Security Service is a local company that offers a caring personal feel that the mega companies cannot. We have been serving in and around Dayton since 1901. Merchants Security Service provides uniformed security officers to the Dayton and surrounding community. While we primarily observe and report, customer service and a smile are a must. Our team...


  • McLean, VA, United States Convergenz Full time

    Responsibilities:Lead the initiative to improve the current Data Loss Prevention (DLP) exclusions/exceptions process for the Cyber DLP team. This enhancement will encompass both process improvements and technological updates.Gain a deep understanding of the existing DLP architecture, processes, and procedures, and identify opportunities for improvement....


  • Alexandria, VA, United States Tyto Athene, LLC Full time

    Tyto Athene is searching for an Information System Security Officer to support a law enforcement customer in Alexandria, VA. This role is responsible for researching, generating, and validating security controls that support the customers’ Risk Management Framework (RMF) and ICD 503 Security Accreditation. Responsibilities include defining, creating, and...


  • Buena Park, CA, United States Royal Business Bank Full time

    JOB SUMMARYInformation Security Officer is responsible for the planning and development of the Bank’s information security program which includes establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. Addresses ongoing threats associated with cybercrime and online...


  • McLean, United States NTT DATA, Inc. Full time

    NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking an Information Security Manager to join our team in McLean, Virginia (US-VA), United States (US).NTT DATA is seeking a highly skilled and...

  • Security Officer

    3 weeks ago


    McLean, United States Admiral Security Services Full time

    Admiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United States.Now is your opportunity to join our...

  • Security Officer

    3 weeks ago


    McLean, United States Admiral Security Services Full time

    Admiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United States.Now is your opportunity to join our...


  • McLean, VA, United States McIntire Solutions, LLC Full time

    Title: Information System Security Manager (ISSM) Location : McLean, VAClearance : TS/SCI with CI Poly (REQUIRED) McIntire Solutions is seeking an Information System Security Manager (ISSM) to support our McLean Customer. Responsibilities include, but are not limited to: Support customer RMF workflow and processes by proposing, coordinating, implementing...


  • Chantilly, VA, United States Parsons Corporation Full time

    Parsons is looking for a talented ISSO to join our growing team!In this role you will develops, maintain, and implement information security standards, procedures, and guidelines for applications and databases. In addition, you will ensure that systems and organizational databases are protected from unauthorized access and use, and monitor systems, identify...


  • Alexandria, VA, United States Tyto Athene, LLC Full time

    Tyto Athene is searching for a Senior Information System Security Officer to support a law enforcement customer in Washington, DC. This role is responsible for researching, generating, and validating security controls that support the customers’ Risk Management Framework (RMF) and ICD 503 Security Accreditation. Responsibilities include defining, creating,...


  • Greensboro, NC, United States Insight Global Full time

    Must Haves: Bachelor’s Degree or higher with a major in computer science, information technology, business or public administration, or related disciplines; OR equivalent combination of education and/or experienceDeep expertise and technical knowledge in the information security and risk management domains10+ years of experience managing an information...


  • Washington, DC, United States Iron Bow Technologies Full time

    Iron Bow Technologies is for people who believe trust is paramount , transformation is embraced , and the future is here , because "What we do matters !" We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on our passionate people , long standing...