Principal Risk Specialist, Tech & Cyber Risk | Retail Bank

Capital One

McLean (VA)

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Capital One is looking for a Principal Risk Specialist in McLean, Virginia to enable and drive end-to-end risk management in Tech & Cyber Risk. As part of the Business Risk Office, you will partner with various stakeholders to identify and mitigate risks associated with technology and cyber domains.

The ideal candidate will have over 5 years of experience in technology risk management, strong analytical skills, and a proven track record in project management.

Qualifications

  • 5+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, or Technology Consulting.
  • Experience leveraging data analysis and visualization tools to derive risk insights.
  • Demonstrated success managing complex, cross-functional projects utilizing agile or waterfall methodologies.

Responsibilities

  • Drive technology and cyber risk assessments, managing from implementation to remediation.
  • Utilize project management skills to prioritize risk initiatives.
  • Monitor and analyze key risk metrics and dashboards in compliance reports.

Skills

Technology Risk Management
Cybersecurity
Project Management
Data Analysis
Stakeholder Engagement

Education

5+ years of experience in related field

Tools

SQL
Tableau
Power BI

Job description

Principal Risk Specialist, Tech & Cyber Risk | Retail Bank

As a Principal Associate of Tech & Cyber Risk within Capital One’s Business Risk Office, you will enable and drive end-to-end risk management of the portfolio by partnering directly with risk partners, technology stakeholders, operations and engineering teams to identify, assess, and mitigate technology and cyber risks.

Key Responsibilities
  • End-to-End Risk Management & Execution
  • Drive end-to-end technology and cyber risk assessments, managing the lifecycle from tactical implementation and ongoing evaluation through to remediation tracking and successful risk finding closure.
  • Support the responsible implementation of AI applications and large‑scale architecture transformations by conducting timely risk assessments and ensuring project teams align with well‑managed best practices and enterprise risk frameworks.
  • Project Management & Stakeholder Engagement
  • Utilize strong project management skills to effectively prioritize risk initiatives, ensuring clear project scope and the timely delivery of impactful results.
  • Exhibit outstanding communication skills to build and manage strong stakeholder relationships across engineering, operations, cyber, risk functions, keeping all levels and lines of defense informed and influencing outcomes to drive project success.
  • Display strong advisory skills to guide risk and engineering partners through complex risk landscapes, adapting with agility to changing business demands and evolving technology environments.
  • Process Improvement & Program Execution
  • Drive continuous improvement within the Tech & Cyber Risk Office by identifying, designing, and implementing enhancements to streamline risk identification, assessment, and mitigation workflows.
  • Metrics, Reporting & Compliance
  • Monitor and analyze key risk metrics and dashboards, partnering closely with stakeholders to oversee remediation efforts and drive metrics toward target compliance levels.
  • Assist in preparing accurate compliance documentation and data for audit engagements, ensuring the overall tech risk posture is transparent and well‑documented.
  • Lead and facilitate recurring risk forums (e.g., metrics reviews) to ensure progress visibility and stakeholder alignment.
  • Proactively own and drive RCSA workflow, acting as a lead or delegate to improve operational efficiency and risk coverage.
  • Develop and manage comprehensive risk measurement frameworks (KRI/metrics), ensuring actionable data‑driven insights are communicated to senior leadership.
Role Expectations & Desired Behaviors
  • Autonomy & Strategic Execution: Proactively identify, own, and resolve risks with limited supervision; exhibit structured problem‑solving to lead sub‑tasks and strategy.
  • Customer Focus & Reliability: Own the end‑to‑end customer process by facilitating project forums and anticipating partner needs to reduce portfolio risk.
  • Communication & Influence: Tailor messaging for diverse audiences (from peers to senior leadership); lead meeting agendas to drive consensus, influence outcomes, and ensure timely action.
  • Fungibility & SME Development: Actively develop deep domain expertise to rotate across core and adjacent risk roles, sharing knowledge to strengthen team capabilities and flexibility.
Basic Qualifications
  • 5+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, or Technology Consulting.
Preferred Qualifications
  • Experience leveraging data analysis and visualization tools (e.g., Sheets, Pivot Tables, SQL, Tableau, Power BI) to derive risk insights and manage metrics.
  • Project management experience, including planning, execution, and delivery of strategic initiatives. Demonstrated success managing complex, cross‑functional risk or technology projects utilizing agile or waterfall methodologies.
  • Awareness of RCSA (Risk and Control Self‑Assessment) risk frameworks and methodologies.
  • Certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP).
  • Familiarity with AI risk management frameworks, or possession of/interest in obtaining certifications such as the Certified AI Governance Professional (AIGP).
  • Experience working within a large financial services institution, highly regulated environment, or technology consulting organization.

No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non‑discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug‑free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23‑A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Risk Specialist, Tech & Cyber Risk | Retail Bank
Principal Risk Specialist, Tech & Cyber Risk | Retail Bank

Capital One National Association • McLean (VA)

On-site
USD 131,000 - 150,000
Manager - Cyber Risk & Analysis
Manager - Cyber Risk & Analysis

Jobtailor • Richmond (VA)

On-site
USD 149,800 - 171,000
Performance-based incentives
Comprehensive health benefits
Financial benefits
Manager, Cyber Risk & Analysis| Retail Bank
Manager, Cyber Risk & Analysis| Retail Bank

Capital One National Association • McLean (VA)

On-site
USD 150,000 - 188,000
Performance-based incentives
Senior Associate, Cyber Risk & Analysis| Retail Bank
Senior Associate, Cyber Risk & Analysis| Retail Bank

Capital One • Richmond (VA)

On-site
USD 101,000 - 127,000
Sr. Director- Data, Models, and AI Risk Management | Retail Bank
Sr. Director- Data, Models, and AI Risk Management | Retail Bank

Capital One • Richmond (VA)

On-site
USD 245,000 - 280,000
Senior Manager, Cyber Risk & Analysis - Enterprise Services Risk
Senior Manager, Cyber Risk & Analysis - Enterprise Services Risk

Capital One • Richmond (VA)

On-site
USD 175,000 - 201,000
Performance-based incentives
Comprehensive health benefits
Manager, Tech and Product Risk Guide - Enterprise Services Risk
Manager, Tech and Product Risk Guide - Enterprise Services Risk

Capital One • McLean (VA)

On-site
USD 164,000 - 189,000
Performance-based incentive compensation
Comprehensive health and financial benefits
Principal Risk Specialist
Principal Risk Specialist

Capital One • Richmond (VA)

Hybrid
USD 110,000 - 125,000
Director, Cyber Risk & Analysis | Retail Bank
Director, Cyber Risk & Analysis | Retail Bank

Capital One National Association • McLean (VA)

On-site
USD 230,400 - 263,000
Principal Risk Specialist
Principal Risk Specialist

Capital One • McLean (VA)

On-site
USD 121,000 - 138,000
Health benefits
Incentives & bonuses