Principal Associate, Cyber Risk

3 weeks ago


McLean, United States Capital One Full time

Center 3 (19075), United States of America, McLean, Virginia

Principal Associate, Cyber Risk & Analysis

Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years, fully exiting our data centers. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk. Technology Risk Management (TRM) is a small organization that packs a big punch. The roughly ninety professionals in TRM are trusted expert advisers who shape decisions, challenge activities to ensure they meet our standards, and generally oversee technology and information security risk across the business and the central technology organization. TRM is a second line organization, which means it is independent and does not sit within the technology organization.

TRM plays a critical role in ensuring that the company’s risk-taking entities are aware of the risks inherent in their activities and decisions, the impact of their actions on the company at an enterprise level, and opportunities to reduce, mitigate or avoid the risks altogether. Associates within TRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, and risk management professionals who have a wealth of experience and a demonstrated ability to provide value added recommendations and deliver high-impact results in their areas of expertise.

Desired Outcomes:

- Identify, interpret and curate external data points to support and ground risk assessments
- Review various risk products and extract key findings and supporting risk intelligence and analyze its applicability to other assessments
- Respond to inquiries to provide grounding data points for specific assessments, research possible sources and their trustworthiness, distill into succinct data points.
- Understand compliance requirements, interpret their applicability and compare to existing mitigations. Identify potential gaps both scope of requirement applicability and whether the implementation meets intent.
- Create and distribute educational materials on cyber and tech industry trends, recent events and compliance requirements and answer questions from the team.

Basic Qualifications:

- Bachelor’s degree or military experience
- At least 2 years of experience managing, or consulting, or auditing in the fields of information security, or technology, or risk management
- At least 2 years of experience with cybersecurity or technology risk assessments or cybersecurity, technology or compliance controls assessments
- At least 1 professional security management certification (Open FAIR, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Informations Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC))

Preferred Qualifications:

- Critical analytical thinker, including the ability to express a point of view supported by data (with both technical and non-technical audiences). Experience in data analysis, metrics definition and/or metrics implementation is a plus.
- Raises concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization
- Passion and expertise in technology and cybersecurity domains, with an ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions
- Ability to collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to get consensus, socialize strategy, and achieve objectives
- Ability to manage multiple parallel initiatives while maintaining superior results
- Execution oriented and a self-motivator
- Personal resilience - the ability to to stay optimistic and keep people focused during crises or times of change
- Experience developing and implementing industry risk frameworks, quantitative analysis, tools, and methodologies: e.g. frameworks like COSO, quantitative analysis such as FAIR, tools such as a Process, Risk & Control (PRC) library, and assessment methodologies such as RCSA, scenario analysis, or new initiative risk assessments
- Experience developing and implementing industry controls frameworks (e.g. NIST 800-53, ISO 27001/27002), designing controls and/or testing controls design
- Knowledge of supervisory expectations expressed in the Federal Financial Institutions Examination Council (FFIEC) IT Handbook, Federal Reserve Supervisory Letters, Office of the Comptroller of the Currency Bulletins, and/or Federal Deposit Insurance Corporation Financial Institution Letters.
- Familiarity with compliance and legal requirements in the cyber and technology space, and



  • McLean, United States Capital One Full time

    Locations: VA - McLean, United States of America, McLean, Virginia Principal Associate, Governance, Risk Identification, and Testing - Technology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control, and...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, Cyber Product Owner Capital One is seeking a product owner to help deliver game-changing cybersecurity solutions based on threat, data, and design thinking. At Capital One, we believe in the values of Excellence and Doing the Right Thing. We are a technology-oriented company...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, Cyber Product Owner Capital One is seeking a product owner to help deliver game-changing cybersecurity solutions based on threat, data, and design thinking. At Capital One, we believe in the values of Excellence and Doing the Right Thing. We are a technology-oriented company...


  • McLean, United States Capital One Full time

    Center 1 (19052), United States of America, McLean, Virginia Principal Associate, Risk Management (Card) - (Hybrid) Principal Risk Associates at Capital One are highly motivated Risk Management professionals with excellent analytical, organizational, and communication skills. These skills allow the Principal Risk Associate to gain insights, and act as a...

  • Manager, Cyber Risk

    3 weeks ago


    McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Manager, Cyber Risk & Analysis Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One moved our...


  • McLean, United States Capital One Financial Corporation Full time

    Center 3 (19075), United States of America, McLean, Virginia. Principal Associate, CSOC Analyst. Capital One is looking for talented Cyber Security Analysts with traditional network security and cloud infrastructure monitoring experience to join our Associate, Analyst, Principal, Security Analyst, Operations, Network, Technology, Banking


  • McLean, United States Capital One Financial Corporation Full time

    Center 3 (19075), United States of America, McLean, Virginia. Principal Associate, CSOC Analyst. Capital One is looking for talented Cyber Security Analysts with traditional network security and cloud infrastructure monitoring experience to join our Associate, Analyst, Principal, Security Analyst, Operations, Network, Technology, Banking


  • McLean, United States Capital One Full time

    Center 1 (19052), United States of America, McLean, Virginia Principal Risk Specialist, IT Do you like working in the spotlight? Are you ready to work on the front line of a top 10 Bank? Can you build relationships as well as develop and implement innovative solutions? As a Principal Risk Specialist in Capital One’s Associate Experience Technology (AXT)...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, Cybersecurity Assessment Maturity Analyst **Responsibilities**: - Support the ongoing evaluation of cybersecurity capabilities to determine maturity score and effectiveness of capability implementation using the NIST Cybersecurity Framework (CSF) across the enterprise -...


  • McLean, United States Capital One Full time

    Center 1 (19052), United States of America, McLean, Virginia Principal Associate, Finance Risk Management (Hybrid) As a Risk Advisor within Finance Risk Management it is essential that you have strong problem solving, integrative thinking, judgment, and communication skills for success. Additionally, building partnerships with multiple business...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, CSOC Analyst It is your responsibility to find the threat actors attempting to attack the Capital One infrastructure, and identify and stop any malicious actors who make it past our defenses. In addition to the technical skills, you will need to be a leader, someone who...


  • McLean, United States Cyber Crime Full time

    USA, VA, McLean (8283 Greensboro Dr, Hamilton) Booz Allen Hamilton Using tomorrow’s technologies, Booz Allen advances the nation’s most critical civil, defense, and national security missions. View company page Key Role: Analyze a variety of information and intelligence relevant to the threats facing the systems, assets, and resources critical to the...

  • Manager, Cyber Risk

    3 weeks ago


    McLean, United States Capital One Full time

    West Creek 5 (12075), United States of America, Richmond, VirginiaManager, Cyber Risk & Analysis (Data Protection & Endpoint Security Service) As a Risk Manager in Capital One’s Cyber DPS Operations Team, you will be responsible for supporting the Data Protection governance and risk related activities for the service, including PLA, RCA, Audit, Regulatory,...

  • Manager, Cyber Risk

    2 weeks ago


    McLean, United States Capital One Full time

    West Creek 5 (12075), United States of America, Richmond, VirginiaManager, Cyber Risk & Analysis (Data Protection & Endpoint Security Service) As a Risk Manager in Capital One’s Cyber DPS Operations Team, you will be responsible for supporting the Data Protection governance and risk related activities for the service, including PLA, RCA, Audit, Regulatory,...


  • McLean, United States Capital One Financial Corp Full time

    Locations: VA - Richmond, United States of America, Richmond, Virginia Principal Risk Specialist As a Principal HR Risk Specialist in Capital One's Human Resource Business Risk Office you will be responsible for working with business partners to identify and consult on potential risks to Capital One, applying your risk/process management and analytical...


  • McLean, United States Capital One Full time

    Locations: VA - McLean, United States of America, McLean, Virginia Manager, Cyber Technical Technology Risk Management (TRM) is a growing second line of defense focused on providing technical and cyber expertise, effective challenge, and oversight activities. TRM Associates are highly-skilled cyber, technology, and risk management professionals who bring a...

  • Senior Consultant

    3 weeks ago


    McLean, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest – one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind...

  • Senior Consultant

    1 day ago


    McLean, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest - one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind our...


  • McLean, United States Exiger Full time

    The Cyber Risk and Compliance Manager will execute responsibilities within the Governance and Risk Management remit, including managing the ISO 27001, FedRAMP and SOC 2 Compliance programs, supporting the implementation of internal and external assessments, and managing the full lifecycle of compliance audits and third party risk reviews. **What You'll...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, Supplier Management At Capital One, we dare to dream, disrupt and deliver a better way. Our goal is simple — bring ingenuity, simplicity and humanity to an industry ripe for change. We are seeking a Principal Associate, Supplier Management to join our Enterprise Supplier...