Sr. Cyber Cloud Security Engineer

4 weeks ago


Richmond, United States Capital One Full time
Center 3 (19075), United States of America, McLean, Virginia

Sr. Cyber Cloud Security Engineer

Capital One is seeking a technical expert in Cloud Security to execute on cyber strategy, while playing a key role in assessing, challenging and advising on infrastructure, platform, and software services in the cloud.

The Ideal candidate will display a strong understanding of industry best practices in the Cloud including governance, engineering, architecture and networking. You will collaborate closely with associates in Cyber, Technology, the lines of Business, and risk management offices. You will evaluate and make recommendations to bolster and secure Capital One's cloud governance, engineering, architecture and on fun controls and practices. In addition, you will provide recommendations to teams regarding ways to safeguard Capital One's Information Assets by contributing to the identification, analysis, solutioning of new or emerging cyber-based threats impacting our cloud environments. You believe that a core component of security's role is to enable the business, not just to secure it, and the solutions you bring to life are aligned to the needs of our developer community and business partners. You thrive in working in a fast paced, technologically forward leaning environment and are not afraid to push the boundaries of security capabilities. You feel at home in the cloud and are an expert in delivering cloud-native security solutions.

In this role you will:
  • Design, architect, and help implement Cloud Security Architecture to modernize our cloud.
  • Assess cloud service offerings from AWS, Microsoft Azure, or Google Cloud Platform (Google Cloud Platform) to identify threats, risks, and controls to secure the service.
  • Encourage innovation, implementation of cutting-edge technologies, outside-of-the-box thinking, teamwork, and self-organization to find efficiencies in our cloud security assessment process.
  • Lead threat modeling of cloud services.
  • Participate in management of the overall Cloud Control Inventory, Procedure documents, Cloud Service Catalog and Service Adoption Framework (SAF) Reports.
  • Perform content and quality assurance reviews of Cloud Controls Exceptions and SAF assessments to provide risk-based recommendations.
  • Stay current on emerging Cloud computing vulnerabilities, threats, controls, and potential implications for Capital One.
  • Operate as a trusted advisor for cloud services helping junior team members and developers understand threats and risk mitigation options for cloud services.
  • Collaborate effectively with colleagues, stakeholders, lines of business and leaders across multiple organizations to achieve Capital One Cloud Security objectives.
  • Define cloud control intent through Policy-As-Code (PaC) using Rego Policy Language
  • Participate in the testing of control design and feasibility study (both manually and through automation) prior to the roll out of Cloud services for enterprise-wide consumption.

Basic Qualifications
  • High School Diploma, GED or Equivalent Certification
  • At least 4 years of experience in Cyber Security
  • At least 2 years of cloud experience with AWS, Microsoft Azure, or Google Cloud Platform

Preferred Qualifications:
  • Bachelor's Degree in Computer Science or Engineering
  • 5+ years of experience delivering cloud security solutions
  • 3+ years of experience in agile delivery
  • Solutions architect or developer certification from AWS, Google Cloud Platform or Azure
  • Industry recognized security certifications (CISSP, CSCP, or equivalent certifications)


At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaSr. Cyber Product OwnerCapital One is seeking a product owner to help deliver game-changing cybersecurity solutions based on threat, data, and design thinking. At Capital One, we believe in the values of Excellence and Doing the Right Thing. We are a technology-oriented company delivering financial...


  • Richmond, United States Unisys Full time

    Key Responsibilities• Responsible for the identification, tracking and management of enterprise risks. This includes performing risk assessments and measuring the success and effectiveness of mitigation efforts.• Identifies, evaluates, tests and implements appropriate security products, tools, and systems to establish and ensure a secure infrastructure....

  • Sr. Data Engineer

    1 week ago


    Richmond, United States Ampcus Full time

    Position: Sr. Data Engineer Location: Richmond/Mclean, VA. (Hybrid) Duration: 12 Months Contract Responsibilities: Be a part of team designing and building Enterprise Level scalable, low-latency, fault-tolerant data Pipelines that provides meaningful and timely insights Build the next generation Distributed Data Pipelines using programming languages like...

  • Sr Cloud Engineer

    1 week ago


    Richmond, United States Delphi-US Full time

    Title: Senior Cloud Engineer - (Contract) - Job#5101Location: Remote Job Description: Our client has an immediate requirement for a Sr Cloud Engineer to join their team on a long term contract. Candidates should have strong experience writing and deploying IAC code. Responsibilities Understand technology vision and strategic direction of business needs...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Security Operations Center (CSOC) Countermeasures AnalystCapital One is looking for talented Cyber Security Analysts with experience performing endpoint, network, and cloud security monitoring to join our Cyber Security Operations Center (CSOC). The Principal Associate...


  • Richmond, Virginia, United States Stefanini North America and APAC Full time

    Stefanini North America and APAC is seeking a talented professionalWe are currently in search of a Cloud Security Engineer for fully remote opportunities.For expedited application, please connect with our recruitment team.We welcome W2 candidates exclusively.We are looking for a proficient Security Assessment Specialist to become part of our dynamic team.The...


  • Richmond, United States Capital One Full time

    Center 2 (19050), United States of America, McLean, VirginiaSr. Director, Cyber Risk & Analysis | Retail BankSummary:Capital One, a Fortune 500 company and one of the nation's top 10 banks, offers a broad spectrum of financial products and services to consumers, small businesses and commercial clients. Our mission is to create one of the nation's great...


  • Richmond, Virginia, United States Capital One Full time

    About the RoleCapital One is seeking a highly skilled Cyber Security Analyst to join our Cyber Governance & Risk division. As a key member of our team, you will work closely with top talent to identify and mitigate cyber risks, ensuring the security and integrity of our systems and data.Key ResponsibilitiesDevelop and implement effective security controls...

  • Cyber Response Analyst

    2 months ago


    Richmond, United States Integration Innovation, Inc. Full time

    Overview: Come Join Our Team Fast-paced, dynamic, and rewarding environment supporting regional defense efforts. This project delivers defensive cyberspace operations (DCO) support to Cyber Security Service Provider Division (CSSP-D), US Army Regional Cyber Center-Korea. The CSSP-D environment includes any hardware, software, application, tool, system, or...

  • Cyber Product Owner

    4 weeks ago


    Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaCyber Product OwnerCapital One is seeking a product owner to help deliver game-changing cybersecurity solutions based on threat, data, and design thinking. At Capital One, we believe in the values of Excellence and Doing the Right Thing. We are a technology-oriented company delivering financial...


  • Richmond, United States Accord Technologies Inc. Full time

    Job DescriptionJob DescriptionSr. Infrastructure Engineer Richmond, VA (look for nearby candidates) Interview Type: In Person Only Work Arrangement: Hybrid (3 days onsite 2 days remote)Years of exp required: 6+ years of expmust have skills: Windows Server environments , exp with patching, backups, migrations, and implementing Active Directory and exp with...


  • Richmond, United States TECHEAD Full time

    TECHEAD is celebrating over thirty-five years of incredible heritage, talent, andaccomplishments! To learn more about TECHEAD, visit us at TECHEAD.com oron Glassdoor.Cyber Security SpecialistContract-to HireHybrid - 3 days a week including WednesdayGlen Allen, Virginia Monitor systems for security gaps, implement effective cyber security solutions, and...


  • Richmond, United States TECHEAD Full time

    TECHEAD is celebrating over thirty-five years of incredible heritage, talent, andaccomplishments! To learn more about TECHEAD, visit us at TECHEAD.com oron Glassdoor.Cyber Security SpecialistContract-to HireHybrid - 3 days a week including WednesdayGlen Allen, Virginia Monitor systems for security gaps, implement effective cyber security solutions, and...


  • Richmond, United States Capital One Full time

    Plano 1 (31061), United States of America, Plano, TexasPrincipal Associate, Cyber TechnicalWe are seeking a Principal Associate, Cyber Technical who enjoys solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment. At Capital One, you'll be part of a big group of builders, breakers, doers and disruptors,...


  • Richmond, United States Manage My Dream, LLC Full time

    Job DescriptionJob DescriptionSr. Infrastructure Engineer- Richmond, VA(Hybrid)**Local candidates preferredWe are seeking a highly skilled Senior Infrastructure Engineer with extensive experience managing Windows Server environments in both on-premises and cloud-based settings. The ideal candidate will have a proven track record in patching, backups,...


  • Richmond, Virginia, United States Capital One Full time

    About the RoleWe are seeking a highly skilled Cyber Security Analyst to join our team at Capital One. As a key member of our Cyber Governance & Risk division, you will play a critical role in helping us reduce cyber risk and drive business growth.Key ResponsibilitiesDevelop and implement effective information security standards and procedures to ensure...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Security Operations Center (CSOC) - (Fusion) AnalystThe Cyber Security Operation Center Fusion team synthesizes multi-source security alerting, intrusion investigations, cyber intelligence, and business information into actionable analysis. The Fusion team provides this...


  • Richmond, United States Nationmind Full time

    Job DescriptionJob DescriptionPosition: VDOT Sr. Infrastructure EngineerLocation: Richmond, VA, 23219Interview: In Person Only Years of Experience: 6Days on Site per week: 1-2 days a weekJob Description:We are seeking a highly skilled Senior Infrastructure Engineer with extensive experience managing Windows Server environments in both on-premises and...


  • Richmond, Virginia, United States Integrated Resources Full time

    Key Responsibilities: Enhance DevSecOps practices by creating and executing security testing within a CI/CD framework. Develop automation solutions to align with the NIST Risk Management Framework (SP800-37, SP800-53/53a). Formulate and monitor Plans of Action and Milestones (POA&Ms) to mitigate identified security risks and compliance deficiencies. Document...


  • Richmond, United States Integrated Resources Full time

    Key Responsibilities: • Support DevSecOps initiatives by developing and implementing test-driven security within a CI/CD pipeline • Create automation to support the NIST Risk Management Framework (SP800-37, SP800-53/53a). • Develop and track Plan of Action and Milestones (POA&Ms) to address identified security vulnerabilities and compliance gaps. •...