Director, Policy and Risk Reporting

7 days ago


Richmond, United States Capital One Full time
Center 3 (19075), United States of America, McLean, Virginia

Director, Policy and Risk Reporting

Capital One is one of the fastest growing organizations, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk.

For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and their Technology Risk Management (TRM) organization oversee cybersecurity but also have broader responsibilities for reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.

Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.

Our business leaders must make technology decisions constantly. TRM makes sure they have the tech risk information they need to make good decisions. Associates within TRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.

As the Director, Policy & Risk Reporting, you will provide thought leadership and strategic guidance as we update and maintain our portfolio of policies, standards, and procedures, as well as establish policy-level requirements for the first line. You will drive improvements to our reporting processes and ensure that materials meet our high bar for clarity, consistency, and message. You will oversee the coordination and drafting of our quarterly memo to the Risk Committee of the Board of Directors, partnering closely with our peers in the second line and our counterparts in the first line. You will support the development of technology and cyber risk content for a committee composed of members of the Executive Committee. Lastly, you will oversee additional risk reporting, including the TRM Forum and monthly business reviews.

The successful candidate will:
  • Be a seasoned leader with strong influence, problem solving, and judgment skills
  • Strong technical writing skills as well as verbal and visual communication
  • Be a strategic and critical thinker who has the ability to express a point of view supported by data (with both technical and non-technical audiences)
  • Possess a high Emotional Intelligence
  • Be a self-starter that can work autonomously and take initiative
  • Have the ability to navigate "white space" or ambiguous situations
  • Collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to get consensus


Basic Qualifications:
  • Bachelor's degree or military experience
  • At least 5 years experience with policy development or risk reporting
  • At least 5 years experience in the financial services industry
  • At least 5 years experience in the technology, cybersecurity, or risk management
  • At least 2 years experience as a people leader


Preferred Qualifications:
  • Master's degree
  • Familiarity with industry frameworks such as NIST CSF, NIST 800-53, and/or COBIT
  • Knowledge of supervisory expectations
  • At least 2 years of experience working in an Agile environment
  • At least 3 years experience as a people leader
  • Professional security management certifications, such as a Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Controls (CRISC)


At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

  • Richmond, VA, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, Virginia Director, Policy and Risk Reporting Capital One is one of the fastest growing organizations, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we...


  • Richmond, California, United States Capital One Full time

    Capital One is one of the fastest-growing organizations in the industry, driven by our passion for customer satisfaction. We are serious about technology, we dream big, and we execute: Capital One successfully transitioned our entire enterprise to the public cloud over five years. Just as we prioritize driving innovation through technology, we equally...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaDirector, Risk Management (ES Risk)Risk Managers at Capital One are highly motivated risk and process management professionals with excellent analytical, organizational, risk management, project management, and communication skills. These skills allow us to gain insights, and act as a change agent...


  • Richmond, California, United States Capital One Full time

    About the RoleCapital One is seeking a seasoned leader to serve as the Director, Policy and Risk Reporting. This role is responsible for providing thought leadership and strategic guidance on updating and maintaining our portfolio of policies, standards, and procedures, as well as establishing policy-level requirements for the first line. The ideal candidate...


  • Richmond, Virginia, United States Diedre Moire Corp. Full time

    Company Overview:Diedre Moire Corporation is a leading provider of risk management solutions for mergers and acquisitions. With a strong presence in the industry, we offer a comprehensive range of services to help businesses navigate complex transactions.Our team of experts is dedicated to delivering exceptional results, and we are committed to providing our...


  • RICHMOND, United States Capital One Careers Full time

    Center 1 (19052), United States of America, McLean, VirginiaDirector, Enterprise Risk Management - Assessment AdvisoryDo you want to be part of an organization that’s dedicated to helping Capital One identify, manage and effectively mitigate risk – for our customers, our communities and our associates? As part of Enterprise Risk Management (ERM),...


  • Richmond, California, United States Diedre Moire Corp. Full time

    About UsDiedre Moire Corporation is a leading industry player, highly regarded by employees and customers alike. We offer a career-oriented work environment and strive to provide our team members with opportunities for growth and development.Job OverviewWe are seeking an experienced Corporate Risk Management Underwriter to join our team in Richmond, VA. This...


  • richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • Richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 200 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • Richmond, United States Fulfillment Family Services,LLC Full time

    Benefits: Opportunity for advancement Experience and Qualifications: This position requires a high school diploma and a minimum of one (5) year experience in Human Services, related service, or any equivalent combination of experience and training which provides the required knowledge, skills, and abilities to serve those with dual diagnosis and...


  • Richmond, United States Capital One Full time

    Locations: NY - New York, United States of America, New York, New YorkDirector, Resiliency Advisory & Oversight, Technology Risk ManagementTechnology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control,...

  • Compliance Analyst

    4 weeks ago


    Richmond, California, United States Goodwill of Central and Coastal Virginia Full time

    Job SummaryWe are seeking a highly skilled Compliance Analyst to join our team at Goodwill of Central and Coastal Virginia. This role will assist in all aspects of our quality assurance, compliance, and enterprise risk management programs.Key ResponsibilitiesConduct reviews and audits to ensure compliance with policies, procedures, and quality audit...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Risk Associate, Data Management - Enterprise Services RiskAs a Principal Associate on Capital One's Enterprise Services Divisional Data Risk Officer (ES DDRO) - Data Management team, you will apply your project management, risk management, data management, and analytical skills to ensure...

  • Director of Quality

    2 weeks ago


    Richmond, United States FAREVA Full time

    Director of Quality Fareva is a third-party manufacturing company and one of the world’s leading subcontractors in the Industrial, Household, Cosmetics and Pharmaceuticals field. We are currently seeking an experienced Director of Quality, to join their team in Richmond, VA. Job Summary: Reporting to the site General Manager, the Director of Quality...


  • Richmond, California, United States Capital One Full time

    About the RoleThis is a senior-level position that requires hands-on cybersecurity technical and operational experience to leverage and enhance expertise in risk management.The Senior Risk Manager, Data Protection will play a key role in reviewing, identifying, assessing, reporting, and effectively challenging cybersecurity controls, operational...


  • Richmond, California, United States Capital One Full time

    Capital One, a leading financial institution, is seeking an experienced Risk Management Specialist Leader to join its Enterprise Risk Management team. This role is based in the United States of America and offers a comprehensive compensation package, estimated at around $120,000 per annum, depending on experience.About UsWe are a diverse and inclusive...

  • GCO Risk Advisor I

    6 months ago


    Richmond, United States Truist Full time

    The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status. ...

  • Research Associate

    4 days ago


    Richmond, California, United States Virginia Commonwealth University Full time

    Job SummaryThe Research Institute on Social Equity (RISE) at the Center for Public Policy (CPP) in the L. Douglas Wilder School of Government and Public Affairs is seeking a highly qualified Research Associate to work closely with the Director, Senior Research Associates, research team, and clients. The successful candidate will have a strong background and...


  • Richmond, VA, United States Capital One Full time

    Center 1 (19052), United States of America, McLean, Virginia Director - Enterprise Risk Management, Change Governance Do you want to be part of an organization that's dedicated to helping Capital One identify, manage and effectively mitigate risk - for our customers, our communities and our associates? As part of Enterprise Risk Management (ERM), you'll work...