Manager, Cyber Risk

3 weeks ago


McLean, United States Capital One Full time

Center 3 (19075), United States of America, McLean, Virginia

Manager, Cyber Risk & Analysis

Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years, fully exiting our data centers. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk. Technology Risk Management (TRM) is a small organization that packs a big punch. The roughly ninety professionals in TRM are trusted expert advisers who shape decisions, challenge activities to ensure they meet our standards, and generally oversee technology and information security risk across the business and the central technology organization. TRM is a second line organization, which means it is independent and reports up through the Chief Risk Officer.

TRM plays a critical role in ensuring that the company’s risk-taking entities are aware of the risks inherent in their activities and decisions, the impact of their actions on the company at an enterprise level, and opportunities to reduce, mitigate or avoid the risks altogether. Associates within TRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, and risk management professionals who have a wealth of experience and a demonstrated ability to provide value added recommendations and deliver high-impact results in their areas of expertise.

Desired Outcomes:

- Challenge and reinvent the methodology that the 1st and 2nd Lines of Defense will use to measure cybersecurity and technology risk within the existing ERM framework, including control efficacy
- Research and develop data-driven assessment practices that will facilitate deeper risk conversations and surface insights in support of strategic decision-making
- Evaluate and standardize various risk scoring methods for tech/cyber domains across the enterprise
- Standardize the approach for TRM to prioritize the assessment scope to best focus our team on the areas of the greatest impact
- Evolve the existing risk, process, control taxonomies to succinctly frame emerging threats and risks
- Distill complex risk, process, and control relationships into simple designs and solutions
- Introduce forward-looking risk measures
- Demonstrate tech/cyber risk measurement advocacy and thought leadership, and train and mentor peers and executives across the enterprise to enable adoption of more modern analysis and assessment techniques
- Constructively debate trade-offs between different assessment approaches with other 2nd Line and 1st Line partners
- Enhance the business’ understanding of regulatory/compliance requirements and the implications to the firm
- Mentor peers to meet their professional development goals

Basic Qualifications:

- A bachelor’s degree or military experience
- At least 4 years of experience managing, consulting, or auditing in the fields of information security, technology, or risk management
- At least 3 years of experience developing and implementing industry risk frameworks, quantitative analysis, tools, and methodologies (COSO, quantitative analysis, Factor Analysis Information Risk (FAIR), Process, Risk & Control (PRC) library), and assessment methodologies (RCSA, scenario analysis, or new initiative risk assessments))
- At least 1 professional security management certification (Open FAIR, Certified Information Systems Security Professional (CISSP), Certified Informations Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC))

Preferred Qualifications:

- A master’s degree
- Critical analytical thinker, including the ability to express a point of view supported by data (with both technical and non-technical audiences)
- Excellent communication and teaching skills. Strong influencing and persuasion skills
- Raises concerns early and knows when to escalate, including the ability to raise issues and facilitate constructive problem-solving at all levels of the organization
- Passion and expertise in technology and cybersecurity domains, with an ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions
- Experience implementing risk quantification frameworks
- Ability to collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to get consensus, socialize strategy, and achieve objectives
- Ability to manage multiple parallel initiatives while maintaining superior results
- Execution oriented and a self-motivator
- Personal resilience - the ability to stay optimistic and keep people focused during crises or times of change
- Experience in a second-line or oversight role at a financial institution or regulatory agency
- Knowledge of supervisory expectat



  • McLean, United States Exiger Full time

    The Cyber Risk and Compliance Manager will execute responsibilities within the Governance and Risk Management remit, including managing the ISO 27001, FedRAMP and SOC 2 Compliance programs, supporting the implementation of internal and external assessments, and managing the full lifecycle of compliance audits and third party risk reviews. **What You'll...

  • Manager, Cyber Risk

    3 weeks ago


    McLean, United States Capital One Full time

    West Creek 5 (12075), United States of America, Richmond, VirginiaManager, Cyber Risk & Analysis (Data Protection & Endpoint Security Service) As a Risk Manager in Capital One’s Cyber DPS Operations Team, you will be responsible for supporting the Data Protection governance and risk related activities for the service, including PLA, RCA, Audit, Regulatory,...

  • Manager, Cyber Risk

    2 weeks ago


    McLean, United States Capital One Full time

    West Creek 5 (12075), United States of America, Richmond, VirginiaManager, Cyber Risk & Analysis (Data Protection & Endpoint Security Service) As a Risk Manager in Capital One’s Cyber DPS Operations Team, you will be responsible for supporting the Data Protection governance and risk related activities for the service, including PLA, RCA, Audit, Regulatory,...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Principal Associate, Cyber Risk & Analysis Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One...


  • McLean, United States Capital One Full time

    Locations: VA - McLean, United States of America, McLean, Virginia Manager, Cyber Technical Technology Risk Management (TRM) is a growing second line of defense focused on providing technical and cyber expertise, effective challenge, and oversight activities. TRM Associates are highly-skilled cyber, technology, and risk management professionals who bring a...


  • McLean, United States Cyber Crime Full time

    USA, VA, McLean (8283 Greensboro Dr, Hamilton) Booz Allen Hamilton Using tomorrow’s technologies, Booz Allen advances the nation’s most critical civil, defense, and national security missions. View company page Key Role: Analyze a variety of information and intelligence relevant to the threats facing the systems, assets, and resources critical to the...

  • Manager, Cyber Risk

    2 weeks ago


    McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Manager, Cyber Risk & Analysis (Machine Learning) The Enterprise Services Business Risk Office provides risk management support to several lines of business including: Tech, Digital, Brand, Enterprise Supplier Management, Capital One Ventures, External Affairs, Capital One Software (COS) and...

  • Senior Consultant

    3 weeks ago


    McLean, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest – one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind...

  • Senior Consultant

    1 day ago


    McLean, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest - one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind our...


  • McLean, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Manager, Cyber Product Owner (SaaS Security) Capital One is seeking a product owner to help deliver game-changing cybersecurity solutions based on threat, data, and design thinking. At Capital One, we believe in the values of Excellence and Doing the Right Thing. We are a technology-oriented...


  • McLean, United States Guidehouse Full time

    Job Family:Cyber ConsultingTravel Required:Up to 10%Clearance Required:Ability to Obtain Public TrustWhat You Will Do: Assess, Implement and Enhance the cybersecurity solutions for a state and local agency. Our team is helping our client increase their overall cybersecurity maturity through the use of a gap analysis and cybersecurity roadmap to help them...


  • McLean, United States Capital One Full time

    Locations: VA - McLean, United States of America, McLean, Virginia Principal Associate, Governance, Risk Identification, and Testing - Technology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control, and...


  • McLean, United States Deloitte Full time

    Position Summary Are you looking to elevate your cyber career? Your technical skills? Your opportunity for growth? Deloitte’s Government and Public Services Cyber Practice (GPS Cyber Practice) is the place for you! Our GPS Cyber Practice helps organizations create a cyber minded culture and become stronger, faster, and more innovative. You will...

  • Cyber Operations Sme

    4 weeks ago


    McLean, United States Peraton Full time

    **About Peraton** **Responsibilities** Peraton is seeking an experienced **Cyber Operations****: - Subject Matter Expert (SME) **to join our talented team of technical and business experts providing key operational and mission support to a SI/SETA mission for a customer in Virginia. Our unique team of technical and business disciplines provide operational...


  • McLean, United States US Office of the Director of National Intelligence Full time

    **Duties**: Lead the NIM-Cyber team's efforts for all steps of the Intelligence Planning, Programming, Budget, and Evaluation cycle including the Intelligence Planning Guidance, Consolidated Intelligence Guidance, and all other tasks pertaining to IC resource prioritization and engagement to raise the capabilities of the Cyber Intelligence...


  • McLean, United States The MITRE Corporation Full time

    Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work...


  • McLean, United States Capital One Full time

    West Creek 2 (12072), United States of America, Richmond, VirginiaSr. Associate, Risk Management (Card) Do you want to be part of an organization that’s dedicated to helping Capital One identify, manage and effectively mitigate risk – for our customers, our communities and our associates? Working with talented associates, you’ll provide oversight and...


  • Mclean, United States Apexon Full time

    Role: Cyber Defense Incident Responder Key Skills: Hands on experience in UEBA or Splunk Enterprise SecurityStrong experience in Cyber Security domainExperience in Splunk content development and Splunk Search Processing Language (SPL).Knowledge of Machine Learning (ML) and how it applies to Insider Risk programs.


  • McLean, United States Eliassen Group Full time

    Job DescriptionJob Description**Hybrid in Washington, DC.** Our government client is looking for a Cyber Task Order Manager to join their team.Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with the ability to obtain a Public Trust Clearance. We offer a great benefits package that includes...


  • McLean, United States Eliassen Group Full time

    Job DescriptionJob Description**Hybrid in Washington, DC.** Our government client is looking for a Cyber Task Order Manager to join their team.Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with the ability to obtain a Public Trust Clearance. We offer a great benefits package that includes...