Principal Associate, Cyber Analysis
Company: Capital One
Location: Cambridge
Posted on: September 20, 2023
Job Description:
Locations: VA - Richmond, United States of America, Richmond,
VirginiaPrincipal Associate, Cyber AnalysisAs a Risk Manager in
Capital One's Cyber DLP Operations Team, you will be responsible
for managing the Data Protection governance and risk related
activities for the service, including PLA, RCA, Audit, Regulatory,
CAMP, TRAs, and Controls testing. - You will mature and manage the
risk management processes by working with Data Protection Service
and Product teams, - horizontal partner teams (Audit, TRM, ES RIsk,
Cyber GRC) and supporting technology teams to identify, document,
and mitigate data protection risks to Capital One. - Risk Managers
at Capital One are highly motivated risk management professionals
with excellent analytical, organizational, influencing and
communication skills. These skills allow the risk manager to gain
insights, and act as a change agent to influence our partners. The
successful risk manager operates from a foundation of solid Risk
Management practices and knowledge about Data Protection, Cyber and
applicable laws / regulations. - They are forward thinking, quick
to adapt, and technologically adept.Additionally, as a member of
Cyber's DLP Operations team, you will be responsible to work across
product, engineering, and operational teams in and outside of Cyber
to oversee the governance of key initiatives that cross multiple
partners and/or have associate facing impacts. - These particular
initiatives require an additional layer of support to ensure we
have excellent communications, - change management, - and risk
management documentation that support our broad set of customers
including associates, ISOs, BROs, and other key stakeholders. -
This role defines, supports and continuously improves the work
management and risk management practices that enable transparency,
efficiency, and auditability across our products and services.
-General Responsibilities: -
- Enables clear mapping of Roadmap initiatives to Risk objects
(Risks, Issues, Mitigation Plans, Action Items, Controls, L2s,
etc)
- Support tracking remediation of risks and issues to closure in
the risk management systems. Partner with Data Protection Service
Cyber and Enterprise partners to manage remediation
commitments
- Consult and accurately document risk objects for the Data
Protection Service (DPS)
- Analyze information to proactively identify risks, trends, and
process improvements -
- Provide oversight and guidance during risk/controls assessments
(PLA, RCSA, ARA, etc.)
- Support facilitation of exam and audit responses
- Establish well managed processes to proactively and
continuously monitor and evaluate the adequacy and effectiveness of
our risk landscape
- Provide advice and counsel on risk objects with Data Protection
Service partners
- Play a key role driving select initiatives across Technology,
Lines of Business, and horizontal functions
- Identify areas of opportunity and implement improvements to
manage the flow of information between DLP and Stakeholder groups
(LOBs, ISOs, BROs, etc)
- Support accurate and up to date information about our DLP
capabilities which may be needed by partner groups, DLP
engineering, operations groups, auditors, etc. -
- Enable a consistent, organized, shared approach for all DLP
processes and documentation so that it's easy to find/use and audit
ready (ie evidence, inventories, ARs, key decisions, job aids,
etc)
- Enable a consistent and efficient approach for work management
across the service that enables 'always on' information about the
work the service is delivering tied back to roadmaps and OKRs.
-
- Support alignment of strategies and goals across Product,
Engineering, and Operations leads to produce clear delivery and
communications plans for key Initiatives
- Identify areas of opportunity to improve how work gets
delivered for DLP and then lead the implementation of those
improvementsBasic Qualifications:
- High School Diploma, GED, or equivalent certification
- At least 4 years of experience with technology or cyber
security risk management frameworks
- At least 1 year of experience developing, evaluating, or
implementing cybersecurity, technology, or risk assessment
activities -Preferred Qualifications:
- Bachelor's Degree
- 3+ years of Risk Management experience in a Cyber or
Information Security practice
- Project Management experience leading cross functional projects
in Risk
- Experience with cloud risk, governance, control, and
security
- CISA, CISM, CRISC, or CISSP Certification -At this time,
Capital One will not sponsor a new applicant for employment
authorization for this position.Capital One offers a comprehensive,
competitive, and inclusive set of health, financial and other
benefits that support your total well-being. Learn more at the -.
Eligibility varies based on full or part-time status, exempt or
non-exempt status, and management level.No agencies please. Capital
One is an Equal Opportunity Employer committed to diversity and
inclusion in the workplace. All qualified applicants will receive
consideration for employment without regard to sex, race, color,
age, national origin, religion, physical and mental disability,
genetic information, marital status, sexual orientation, gender
identity/assignment, citizenship, pregnancy or maternity, protected
veteran status, or any other status prohibited by applicable
national, federal, state or local law. Capital One promotes a
drug-free workplace. Capital One will consider for employment
qualified applicants with a criminal history in a manner consistent
with the requirements of applicable laws regarding criminal
background inquiries, including, to the extent applicable, Article
23-A of the New York Correction Law; San Francisco, California
Police Code Article 49, Sections 4901-4920; New York City's Fair
Chance Act; Philadelphia's Fair Criminal Records Screening Act; and
other applicable federal, state, and local laws and regulations
regarding criminal background inquiries.If you have visited our
website in search of information on employment opportunities or to
apply for a position, and you require an accommodation, please
contact Capital One Recruiting at 1-800-304-9102 or via email at
RecruitingAccommodation@capitalone.com. All information you provide
will be kept confidential and will be used only to the extent
required to provide needed reasonable accommodations.For technical
support or questions about Capital One's recruiting process, please
send an email to Careers@capitalone.comCapital One does not
provide, endorse nor guarantee and is not liable for third-party
products, services, educational tools or other information
available through this site.Capital One Financial is made up of
several different entities. Please note that any position posted in
Canada is for Capital One Canada, any position posted in the United
Kingdom is for Capital One Europe and any position posted in the
Philippines is for Capital One Philippines Service Corp.
(COPSSC).
Keywords: Capital One, Cambridge , Principal Associate, Cyber Analysis, Education / Teaching , Cambridge, Massachusetts
Didn't find what you're looking for? Search again!
Loading more jobs...