Director, Cyber Risk and Analysis

Capital One National Association

New York (NY)

On-site

USD 246,500 - 281,300

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Financial benefits
Performance-based incentives
Inclusive workplace environment

Job summary

An established industry player is seeking a Director of Cyber Risk and Analysis to enhance their cybersecurity framework. This pivotal role involves applying expertise in risk management to assess threats and business impacts, ensuring robust oversight of technology and cyber risks. You will lead initiatives to aggregate risk data, develop mitigation strategies, and engage with senior leadership to drive informed decision-making. Join a dynamic team committed to innovation and excellence in cybersecurity, where your contributions will significantly impact the organization’s risk posture and resilience in a rapidly evolving digital landscape.

Qualifications

  • 5+ years in Technology or Cyber Security Risk Management.
  • Strong understanding of risk frameworks and control environments.

Responsibilities

  • Lead risk aggregation initiatives and define mitigation strategies.
  • Advise executives on tech and cyber-related risks consistently.

Skills

Technology Risk Management
Cyber Security Risk Management
Risk Control Environments
People Management
Data Analysis
Critical Thinking
Communication Skills

Education

Bachelor's Degree or military experience
Master’s Degree

Tools

Risk Management Products
Reporting Tools

Job description

Director, Cyber Risk and Analysis

Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, and managing technology risk.

For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO.

Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.

As a Director, Cyber Risk and Analysis, you will apply expertise on risk frameworks and best practices to assess current state, identify methodology gaps, and evaluate threats and/or business impact to enable advisory partnerships and effective oversight of tech and cyber risk across Capital One. You will lead risk aggregation initiatives, define mitigation strategies, prioritize and escalate recommendations to senior leadership. You will also participate in the design, socialization and implementation of risk management products and programs through your deep knowledge of risk assessments, information risk controls, regulatory and internal governance standards, data analysis, metrics / reporting, and customer engagement.

Responsibilities:
  • Maintains a broad, expert understanding of technology risk frameworks, has innate ability to leverage these frameworks in risk identification processes.
  • Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting risk management policies or programs; recommends sound, practical solutions to complex issues.
  • Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise.
  • Advises Accountable Executives of tech and cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management.
  • Exhibits strong critical thinking and communication skills, with proven ability to navigate the unknown to devise and socialize innovative risk management solutions.
  • Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change. Understands associated reporting metrics and is able to inform on tech and cyber risks.
  • Quickly and accurately analyzes data, assesses risk, & prioritizes potential risks to differentiate critical, high-risk, and low-risk issues, and remediates and escalates as appropriate.
  • Makes recommendations regarding changes to first line policy, procedures, and control programs to mitigate evolving risks.
  • Effectively self-challenges tech and cyber control and risk management programs as part of first line duties and escalates risks where appropriate.
  • Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement.
Basic Qualifications:
  • Bachelor's Degree or military experience
  • At least 5 years of experience with Technology Risk Management or Cyber Security Risk Management
  • At least 5 years of experience building risk control environments or risk frameworks
  • At least 5 years of experience in People Management
Preferred Qualifications:
  • Master’s Degree
  • Process or Project Management certification (i.e. Lean, Six Sigma, PMP), Business Management certification
  • 10+ years of experience with Technology or Cyber Security Risk Management
  • 9+ years of experience in People Management

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis
New York, NY: $246,500 - $281,300 for Director, Cyber Risk & Analysis
Plano, TX: $205,400 - $234,400 for Director, Cyber Risk & Analysis
Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis

Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Risk & Analysis | Retail Bank
Director, Cyber Risk & Analysis | Retail Bank

Capital One • McLean (VA)

On-site
USD 230,400 - 263,000
Director, Cyber Risk & Analysis | Retail Bank
Director, Cyber Risk & Analysis | Retail Bank

Capital One National Association • McLean (VA)

On-site
USD 230,400 - 263,000
Manager, Cyber Risk & Analysis (International and Regulatory Risk)
Manager, Cyber Risk & Analysis (International and Regulatory Risk)

Socket.dev • McLean (VA)

On-site
USD 165,000 - 188,000
Manager, Cyber Risk & Analysis (International and Regulatory Risk)
Manager, Cyber Risk & Analysis (International and Regulatory Risk)

Capital One • Richmond (VA)

On-site
USD 150,000 - 171,000
Manager, Cyber Risk & Analysis (International and Regulatory Risk)
Manager, Cyber Risk & Analysis (International and Regulatory Risk)

Capital One • New York (NY)

On-site
USD 180,000 - 205,000
Manager, Cyber Risk & Analysis
Manager, Cyber Risk & Analysis

Capital One • McLean (VA)

On-site
USD 165,000 - 188,000
Manager, Cyber Risk & Analysis
Manager, Cyber Risk & Analysis

Capital One National Association • McLean (VA), Northern (KY)

On-site
USD 165,000 - 188,000
Director, IAM Cyber Product
Director, IAM Cyber Product

Relha LLC • McLean (VA)

Hybrid
USD 269,000 - 307,000
Senior Manager, Cyber Risk & Analysis - Enterprise Services Risk
Senior Manager, Cyber Risk & Analysis - Enterprise Services Risk

Capital One • Richmond (VA)

On-site
USD 175,000 - 201,000
Performance-based incentives
Comprehensive health benefits
Manager - Cyber Risk & Analysis
Manager - Cyber Risk & Analysis

Capital One • Richmond (VA)

On-site
USD 149,800 - 171,000
Performance-based incentives
Comprehensive health benefits
Financial benefits