Sr. Manager, Technology Risk
Company: Capital One
Location: New Haven
Posted on: May 17, 2023
Job Description:
Center 2 (19050), United States of America, McLean, VirginiaSr.
Manager, Technology RiskAs a Technology Risk Sr. Manager in Capital
One's Enterprise Services (ES) Risk Office (ES Risk), you will
apply your risk management and cyber expertise to the company's
Technology organization. You will partner across Enterprise
Services, Divisional CIOs, and Information Security teams to
develop and support best-in-class industry risk solutions in a
manner that supports innovation and protects our customers,
shareholders and associates. You will collaborate with second lines
of defense to lead and implement risk and control tools,
techniques, and frameworks for the Technology organization, as well
as provide direct tech risk advisory services into our first line
Divisional CIO teams. Your contributions will drive organizational
change through risk identification, measurement, analysis and
reporting in order to better manage the company's risk in an open
and collaborative environment.Technology Risk Sr. Managers are
experienced and progressive individuals that operate within a
highly collaborative team environment to deliver value-added risk
management services to our Technology savvy business partners. You
will have a high level of exposure across lines of business and
have the opportunity to work with senior Cyber and Tech Executives
to create and implement innovative solutions to identify and
mitigate potential risks to the Company. Proficiency in risk
management program (ideally Technology risk-driven program)
development and management are key to success in this role. The
successful candidate will be an experienced risk management
professional who understands cyber technology functions and
organizations, with strong risk management, analytical, planning,
strategic thinking, organizational and communication
skills.Responsibilities:
- Assist the ES Risk leadership in delivering against their
strategy and service model
- Serve as interdepartmental advisor, interfacing with
technology, cyber, lines of business and other areas such as second
line technology risk management and Compliance; collaborate
effectively across multiple organizations to achieve
objectives.
- Identify and implement continual program enhancements based on
industry standards and best practices related to risk management
(especially technology risk) and aligned with Capital One's
strategic risk direction
- Gather risk and control data and reporting; perform initial
analysis or potentially evaluate data provided by team
analysts
- Design and implement internal risk and control governance
processes
- Build successful relationships with line of business risk
offices and team members to understand impact of technology risk on
critical business processes
- Manage, implement and deliver on a subset of the program
deliverables
- Facilitate and provide first line oversight and challenge of
various risk assessments
- Understand, document and analyze current state capabilities
regarding one or more risk methods. Leverage industry benchmarking
to determine best practices and lessons learned regarding
components of the risk framework.
- Write and revise documents such as policies, standards,
procedures, and guidelines. Develop and enhance processes, tools,
templates, and job aides. Draft, contribute to, edit, and deliver
presentations that aid in the design, development, refinement, and
usage of risk methods.Basic Qualifications:
- At least 7 years experience in Technology or Operational Risk,
IT Internal or External Audit, or a combination
- At least 7 years of experience in data management and
performing data analysis in support of internal risk assessments
and control reviews
- At least 7 years of experience planning and leading IT audits
or risk assessments
- At least 5 year of experience performing controls testing over
cloud-based infrastructure (AWS) Preferred Qualifications:
- Professional certification such as Certified Information
Systems Auditor (CISA), Certified in Risk and Information Systems
Control (CRISC), Certified Information Systems Security
Professional (CISSP), Certified Information Security Manager (CISM)
or related certifications
- 9+ years experience in information systems auditing,
information systems risk management, or a combination
- 9+ years of experience in performing Control Self Assessments
(CSAs), or completing assessments against established industry risk
frameworks, including: the NIST Cybersecurity Framework, COBIT v5,
or COSO
- 6+ years risk assessing cloud services and cloud architecture
(AWS specific).
- 9+ years experience performing data analysis in support of
internal risk assessments and control reviews
- AWS certification (e.g., Practitioner, Solutions Architect,
Security)
- Excellent verbal presentation and written communication skills
to confidently interact with application teams and enterprise
stakeholders
- Excellent problem-solving, analytical and critical thinking
skills to effectively respond to shifting priorities, demands and
timelines
- Consulting experience with Big 4 or other consulting firms is a
plus
- Proficient with G Suite / Google Workspace for reports,
analysis, and presentations is a plusAt this time, Capital One will
not sponsor a new applicant for employment authorization for this
position.The minimum and maximum full-time annual salaries for this
role are listed below, by location. Please note that this salary
information is solely for candidates hired to perform work within
one of these locations, and refers to the amount Capital One is
willing to pay at the time of this posting. Salaries for part-time
roles will be prorated based upon the agreed upon number of hours
to be regularly worked.Location is New York City: $195,200 -
$222,800 for Sr. Manager, Cyber Risk & AnalysisCandidates hired to
work in other locations will be subject to the pay range associated
with that location, and the actual annualized salary amount offered
to any candidate at the time of hire will be reflected solely in
the candidate's offer letter.This role is also eligible to earn
performance based incentive compensation, which may include cash
bonus(es) and/or long term incentives (LTI). Incentives could be
discretionary or non discretionary depending on the plan.Capital
One offers a comprehensive, competitive, and inclusive set of
health, financial and other benefits that support your total
well-being. Learn more at theCapital One Careers website.
Eligibility varies based on full or part-time status, exempt or
non-exempt status, and management level.No agencies please. Capital
One is an Equal Opportunity Employer committed to diversity and
inclusion in the workplace. All qualified applicants will receive
consideration for employment without regard to sex, race, color,
age, national origin, religion, physical and mental disability,
genetic information, marital status, sexual orientation, gender
identity/assignment, citizenship, pregnancy or maternity, protected
veteran status, or any other status prohibited by applicable
national, federal, state or local law. Capital One promotes a
drug-free workplace. Capital One will consider for employment
qualified applicants with a criminal history in a manner consistent
with the requirements of applicable laws regarding criminal
background inquiries, including, to the extent applicable, Article
23-A of the New York Correction Law; San Francisco, California
Police Code Article 49, Sections 4901-4920; New York City's Fair
Chance Act; Philadelphia's Fair Criminal Records Screening Act; and
other applicable federal, state, and local laws and regulations
regarding criminal background inquiries.If you have visited our
website in search of information on employment opportunities or to
apply for a position, and you require an accommodation, please
contact Capital One Recruiting at 1-800-304-9102 or via email at
RecruitingAccommodation@capitalone.com. All information you provide
will be kept confidential and will be used only to the extent
required to provide needed reasonable accommodations.For technical
support or questions about Capital One's recruiting process, please
send an email to Careers@capitalone.comCapital One does not
provide, endorse nor guarantee and is not liable for third-party
products, services, educational tools or other information
available through this site.Capital One Financial is made up of
several different entities. Please note that any position posted in
Canada is for Capital One Canada, any position posted in the United
Kingdom is for Capital One Europe and any position posted in the
Philippines is for Capital One Philippines Service Corp.
(COPSSC).
Keywords: Capital One, New Haven , Sr. Manager, Technology Risk, IT / Software / Systems , New Haven, Connecticut
Didn't find what you're looking for? Search again!
Loading more jobs...