Director, Technology & Cyber Risk Officer
Company: Capital One
Location: Harrisonburg
Posted on: August 5, 2022
Job Description:
Center 2 (19050), United States of America, McLean,
VirginiaDirector, Technology & Cyber Risk Officer -Director,
Technology & Cyber Risk Officer -Capital One is one of the fastest
growing organizations in the world today. The growth of the
business is being accelerated by leveraging innovative and emerging
technologies. We are serious about technology, we dream big, and we
execute: Capital One moved our entire enterprise to the public
cloud over the course of five years, fully exiting our data
centers. Just as we prioritize driving innovation through
technology, we equally prioritize cybersecurity and managing
technology risk. Technology Risk Management (TRM) is a small
organization that packs a big punch. The roughly seventy
professionals in TRM are trusted expert advisers who shape
decisions, challenge activities to ensure they meet our standards,
and generally oversee technology and information security risk
across the business and the central technology organization. TRM is
a second line organization, which means it is independent and
reports up through the Chief Risk Officer.Since its founding,
Capital One has invested in developing cutting-edge digital and
analytics capabilities in order to continually drive innovation.
The Commercialization initiatives are now at the heart of these
efforts. Our teams of product builders, designers, and
technologists are building the next generation of
software-as-a-service (SaaS) -- leveraging both Capital One's
leading platform and technological capabilities, as well as
building entirely new business-to-business-to-consumer (B2B2C)
constructs across the FinTech ecosystem.This new position -
Director, Technology & Cyber Risk Officer - will play a high impact
role in assessing and enhancing the cybersecurity and technology
risk posture for many high-profile Commercialization initiatives
across the company. - This includes identifying and assessing
potential risks, engaging in challenge activities, and reimagining
how we provide risk advisory and oversight for fledgling SaaS
solutions. In addition to overseeing risk assessment activities,
this role will be expected to identify opportunities to tailor
existing risk frameworks for emerging businesses so that they can
stay competitive with other FinTech companies. There will be
frequent opportunities to highlight emerging risks and represent
TRM's Line of Business risk view in many different risk forums and
committees.As a member of a growing organization, you are expected
to shape and further refine the risk program, and will have the
opportunity to operate with both autonomy and empowerment from
senior leadership. The demands and high-visibility nature of this
position require an individual with a proven ability to lead a
high-performing team in a fast-paced environment. - The successful
candidate will be a seasoned leader with strong knowledge of
technology or cyber risk, industry, and regulatory trends who can
think strategically, be intellectually curious, is comfortable
working in undefined problem spaces, and can influence stakeholders
at all levels of the organization.Desired Outcomes:
- Establish a robust advisory and effective challenge model,
aligned to each Line of Business, to facilitate deeper risk
conversations and surface insights in support of strategic
decision-making
- Demonstrate strong judgment to balance being both a trusted
advisor to the business and driving effective challenge
- Leverage business and domain expertise to raise the level of
challenge activities to a strategic focus
- Constructively debate issues and connect the dots across
various assessments (typically includes risk and control
self-assessments, critical business process-level assessments,
assessments of new initiatives, scenario analysis, challenge of
risk acceptances)
- Identify opportunities to influence risk-taking strategies and
ensure that aggregate risk is understood
- Succinctly frame emerging threats and risks, in contrast with
the existing risk profile, across risk reporting and governance
forums
- Introduce forward-looking risk measures that are relevant to
the Lines of Business
- Influence peers and executives across the Lines of Business to
take accountability for complex (and sometimes sensitive)
technology and cyber risks
- Enhance the business' understanding of regulatory and
compliance requirements and the implications to the firm
- Demonstrate robust risk management oversight in supporting
various internal audits and regulatory exams
- Mentor and develop associates to meet their professional
development goalsBasic Qualifications:
- A Bachelor's degree or Military experience
- At least 7 years of experience managing, consulting, auditing,
or working in the fields of information security, technology, or
risk management
- At least 5 years of experience developing, evaluating, or
implementing cybersecurity, technology or risk assessment
activities
- At least 1 professional security management certification:
Certified Information Systems Security Professional (CISSP),
Certified Informations Systems Auditor (CISA), or Certified in Risk
and Information Systems Control (CRISC) -Preferred Qualifications:
- A Master's degree
- Superb communication skills that include active listening and
executive presentation skills
- Critical analytical thinker, including the ability to express a
point of view supported by data (with both technical and
non-technical audiences)
- Excellent influencing and persuasion skills
- Raises concerns early and knows when to escalate, including the
ability to raise issues and facilitate constructive problem-solving
at all levels of the organization
- Passion and expertise in technology and cybersecurity domains,
with an ability to be confident, respectful, and articulate when
registering dissenting or unpopular opinions
- Ability to collaborate effectively with colleagues,
stakeholders, and leaders across multiple organizations to get
consensus, socialize strategy, and achieve objectives
- Ability to manage multiple parallel initiatives while
maintaining superior results
- Execution oriented and a self-motivator
- Personal resilience - the ability to to stay optimistic and
keep people focused during crises or times of change
- Experience in a second-line or oversight role at a financial
institution or regulatory agency
- Knowledge of supervisory expectations expressed in the FFIEC IT
Handbook, Federal Reserve Supervisory Letters, Office of the
Comptroller of the Currency Bulletins, and/or Federal Deposit
Insurance Corporation Financial Institution Letters -At this time,
Capital One will not sponsor a new applicant for employment
authorization for this position - -No agencies please. Capital One
is an Equal Opportunity Employer committed to diversity and
inclusion in the workplace. All qualified applicants will receive
consideration for employment without regard to sex, race, color,
age, national origin, religion, physical and mental disability,
genetic information, marital status, sexual orientation, gender
identity/assignment, citizenship, pregnancy or maternity, protected
veteran status, or any other status prohibited by applicable
national, federal, state or local law. Capital One promotes a
drug-free workplace. Capital One will consider for employment
qualified applicants with a criminal history in a manner consistent
with the requirements of applicable laws regarding criminal
background inquiries, including, to the extent applicable, Article
23-A of the New York Correction Law; San Francisco, California
Police Code Article 49, Sections 4901-4920; New York City's Fair
Chance Act; Philadelphia's Fair Criminal Records Screening Act; and
other applicable federal, state, and local laws and regulations
regarding criminal background inquiries.If you have visited our
website in search of information on employment opportunities or to
apply for a position, and you require an accommodation, please
contact Capital One Recruiting at 1-800-304-9102 or via email at .
All information you provide will be kept confidential and will be
used only to the extent required to provide needed reasonable
accommodations.For technical support or questions about Capital
One's recruiting process, please send an email to Capital One does
not provide, endorse nor guarantee and is not liable for
third-party products, services, educational tools or other
information available through this site.Capital One Financial is
made up of several different entities. Please note that any
position posted in Canada is for Capital One Canada, any position
posted in the United Kingdom is for Capital One Europe and any
position posted in the Philippines is for Capital One Philippines
Service Corp. (COPSSC).
Keywords: Capital One, Harrisonburg , Director, Technology & Cyber Risk Officer, IT / Software / Systems , Harrisonburg, Virginia
Didn't find what you're looking for? Search again!
Loading more jobs...