Sr. Manager, Technology & Cyber Risk
Company: Capital One
Location: Chicago
Posted on: April 15, 2025
Job Description:
Sr. Manager, Technology & Cyber RiskTech Risk Guides (TRG) at
Capital One are highly motivated tech and cyber risk management
professionals with strong analytical, organizational, planning,
strategic thinking, and communication skills. These skills allow us
to gain insights, and act as a change agent to influence our tech
and business partners. A successful candidate will be able to apply
their Tech and Cyber risk management skills to inform and provide
sound tech and cyber risk decisions. They are forward thinking,
quick to adapt, and have a high degree of ownership in supporting
their line of business.As a TRG within the ES Business Risk team,
covering various lines of business, we are the first line of
defense to ensure these lines of business are well-managed and
avoid unnecessary risk. In this position, you will play a key role
in ensuring the identification and management of our tech risk
profile across the lines of business we support.What you'll do:
- Serve as a Tech Risk Guide within the Business Risk team
covering various lines of business (e.g.; Global Workspace Service,
Enterprise Supplier Management, Brand, etc.)
- Build successful relationships within their line of business,
business risk offices, and team members to understand the impact of
technology risk on critical business processes
- Perform risk reviews during various processes such as Risk
Control and Self Assessments (RCSAs), Process Level Assessments
(PLA), Exceptions, Issues and Events, LAUNCH Assessments, Targeted
Risk Assessments and recommend on risk mitigation activities.
- Influence leaders within the lines of business, Business Risk
Offices, Compliance, Cyber Security, second line risk
organizations, and Internal Audit on key technology risks and
actions needed
- Conduct periodic risk reviews with the executives and support
reporting for technology risk metrics
- Develop risk analysis, perform deep dive investigations, and
drive specific risk initiatives to minimize risk posture and
strengthen overall control suite effectiveness
- Partner with tech leaders to ensure technical KRI/KPI's are
managed appropriately
- Design and support internal risk and control governance
processes
- Identify and implement continual tech risk program enhancements
based on industry standards and best practices in alignment with
Capital One's strategic risk direction
- Support the Enterprise Services Risk (ESR), Business Risk
organization by implementing new and innovative ideasBasic
Qualifications:
- At least 5 years of experience developing risks, associated
controls, issues and/or mitigation plans or performing controls
testing over cloud-based infrastructure
- At least 5 or more years of experience in Banking or Financial
Services
- At least 5 years experience in Technology Risk, IT Internal or
External Audit, or a combination, gained within a financial
institution or professional services firm
- At least 5 years of experience planning, analyzing and leading
Risk assessments, and/or performing detailed reviews of control
assessments; including National Institute of Standard & Technology
(NIST), PCI DSS, SOC 2 and SaaS offerings for both B2B and B2C
markets
- At least 5 years of Project Management experience (or
equivalent)
- At least 5 years of experience supporting internal/external
business clients with a deep understanding of Technology risk in
the areas of security considerations, sustainability, business
resilience and data restrictions
- Exposure to Cloud Risk Management
- Knowledge of the UK and US regulatory landscapes is a
plusPreferred Qualifications:
- 7+ years of Project Management experience leading cross
functional projects in Risk simultaneously
- Professional certification such as Certified Information
Systems Auditor (CISA), Certified in Risk and Information Systems
Control (CRISC), Certified Information Systems Security
Professional (CISSP), Certified Information Security Manager (CISM)
or other Industry related certifications
- 7+ years experience in information systems risk management, in
information systems auditing, or a combination
- At least 7 years of experience planning, analyzing and leading
Control Self Assessments (CSAs), or completing assessments against
established industry risk frameworks; including, National Institute
of Standard & Technology (NIST), PCI-DSS, SOC 2 and SaaS offerings
for both B2B and B2C markets
- Experience with Amazon Web Service (AWS) with multi-cloud
(Azure and GCP)
- Big 4 firm consulting experience a plus
- Cloud Risk Management experience a plus
- Proficient with G Suite / Google Workspace
- Excellent verbal presentation and written communication skills
to confidently interact with and lead meetings at all levels,
including executives
- Excellent problem-solving, analytical and critical thinking
skills to effectively respond to shifting priorities, demands and
timelines
#J-18808-Ljbffr
Keywords: Capital One, Crystal Lake , Sr. Manager, Technology & Cyber Risk, Executive , Chicago, Illinois
Didn't find what you're looking for? Search again!
Loading more jobs...