Principal Associate- Cyber Risk & Analysis
Company: Capital One
Location: Mount Sinai
Posted on: May 25, 2023
Job Description:
West Creek 5 (12075), United States of America, Richmond,
VirginiaPrincipal Associate- Cyber Risk & AnalysisRole
DescriptionAs a Risk Manager in Capital Ones Cyber DLP Operations
Team, you will be responsible for managing the Data Protection
governance and risk related activities for the service, including
PLA, RCA, Audit, Regulatory, CAMP, TRAs, and Controls testing. You
will mature and manage the risk management processes by working
with Data Protection Service and Product teams, horizontal partner
teams (Audit, TRM, ES RIsk, Cyber GRC) and supporting technology
teams to identify, document, and mitigate data protection risks to
Capital One. Risk Managers at Capital One are highly motivated risk
management professionals with excellent analytical, organizational,
influencing and communication skills. These skills allow the risk
manager to gain insights, and act as a change agent to influence
our partners. The successful risk manager operates from a
foundation of solid Risk Management practices and knowledge about
Data Protection, Cyber and applicable laws / regulations. They are
forward thinking, quick to adapt, and technologically
adept.Additionally, as a member of Cybers DLP Operations team, you
will be responsible to work across product, engineering, and
operational teams in and outside of Cyber to oversee the governance
of key initiatives that cross multiple partners and/or have
associate facing impacts. These particular initiatives require an
additional layer of support to ensure we have excellent
communications, change management, and risk management
documentation that support our broad set of customers including
associates, ISOs, BROs, and other key stakeholders. This role
defines, supports and continuously improves the work management and
risk management practices that enable transparency, efficiency, and
auditability across our products and services. General
Responsibilities:
- Enables clear mapping of Roadmap initiatives to Risk objects
(Risks, Issues, Mitigation Plans, Action Items, Controls, L2s,
etc)
- Support tracking remediation of risks and issues to closure in
the risk management systems. Partner with Data Protection Service
Cyber and Enterprise partners to manage remediation
commitments
- Consult and accurately document risk objects for the Data
Protection Service (DPS)
- Analyze information to proactively identify risks, trends, and
process improvements
- Provide oversight and guidance during risk/controls assessments
(PLA, RCSA, ARA, etc.)
- Support facilitation of exam and audit responses
- Establish well managed processes to proactively and
continuously monitor and evaluate the adequacy and effectiveness of
our risk landscape
- Provide advice and counsel on risk objects with Data Protection
Service partners
- Play a key role driving select initiatives across Technology,
Lines of Business, and horizontal functions
- Identify areas of opportunity and implement improvements to
manage the flow of information between DLP and Stakeholder groups
(LOBs, ISOs, BROs, etc)
- Support accurate and up to date information about our DLP
capabilities which may be needed by partner groups, DLP
engineering, operations groups, auditors, etc.
- Enable a consistent, organized, shared approach for all DLP
processes and documentation so that its easy to find/use and audit
ready (ie evidence, inventories, ARs, key decisions, job aids,
etc)
- Enable a consistent and efficient approach for work management
across the service that enables always on information about the
work the service is delivering tied back to roadmaps and OKRs.
- Support alignment of strategies and goals across Product,
Engineering, and Operations leads to produce clear delivery and
communications plans for key Initiatives
- Identify areas of opportunity to improve how work gets
delivered for DLP and then lead the implementation of those
improvementsBasic Qualifications:
- High School Diploma, GED, or equivalent certification
- At least 4 years of experience with technology or cyber
security risk management frameworks
- At least 1 year of experience developing, evaluating, or
implementing cybersecurity, technology, or risk assessment
activities Preferred Qualifications:
- Bachelors Degree
- 3+ years of Risk Management experience in a Cyber or
Information Security practice
- Project Management experience leading cross functional projects
in Risk
- Experience with cloud risk, governance, control, and
security
- CISA, CISM, CRISC, or CISSP Certification At this time, Capital
One will not sponsor a new applicant for employment authorization
for this position.Capital One offers a comprehensive, competitive,
and inclusive set of health, financial and other benefits that
support your total well-being. Learn more at the . Eligibility
varies based on full or part-time status, exempt or non-exempt
status, and management level.No agencies please. Capital One is an
Equal Opportunity Employer committed to diversity and inclusion in
the workplace. All qualified applicants will receive consideration
for employment without regard to sex, race, color, age, national
origin, religion, physical and mental disability, genetic
information, marital status, sexual orientation, gender
identity/assignment, citizenship, pregnancy or maternity, protected
veteran status, or any other status prohibited by applicable
national, federal, state or local law. Capital One promotes a
drug-free workplace. Capital One will consider for employment
qualified applicants with a criminal history in a manner consistent
with the requirements of applicable laws regarding criminal
background inquiries, including, to the extent applicable, Article
23-A of the New York Correction Law; San Francisco, California
Police Code Article 49, Sections 4901-4920; New York Citys Fair
Chance Act; Philadelphias Fair Criminal Records Screening Act; and
other applicable federal, state, and local laws and regulations
regarding criminal background inquiries.If you have visited our
website in search of information on employment opportunities or to
apply for a position, and you require an accommodation, please
contact Capital One Recruiting at 1-800-304-9102 or via email at
RecruitingAccommodation@capitalone.com. All information you provide
will be kept confidential and will be used only to the extent
required to provide needed reasonable accommodations.For technical
support or questions about Capital One's recruiting process, please
send an email to Careers@capitalone.comCapital One does not
provide, endorse nor guarantee and is not liable for third-party
products, services, educational tools or other information
available through this site.Capital One Financial is made up of
several different entities. Please note that any position posted in
Canada is for Capital One Canada, any position posted in the United
Kingdom is for Capital One Europe and any position posted in the
Philippines is for Capital One Philippines Service Corp.
(COPSSC).
Keywords: Capital One, Westport , Principal Associate- Cyber Risk & Analysis, Education / Teaching , Mount Sinai, Connecticut
Didn't find what you're looking for? Search again!
Loading more jobs...