Director, Information Security Officer

Capital One Capital One · Banking · McLean, VA +2

Director, Information Security Officer responsible for leading end-to-end security for strategic projects within a line of business at a financial services company. This role involves working with business, technology, and risk partners to achieve time-sensitive goals, providing product security advisory services, and advising on strategic initiatives in a risk-based and agile manner. The role requires comfort with modern software, data analytics, artificial intelligence, and cloud technologies, as well as associated protective methods.

What you'd actually do

  1. Be a leader at a premiere technology and financial services company
  2. Be responsible for delivery of end to end security for strategic projects, including but not limited to mergers and acquisitions
  3. Deliver divisional cyber strategy integration and execution, identification and management of risk for top business initiatives and technology platforms, threat and vulnerability management, incident management, supply chain cyber risk management, cyber risk oversight and reporting.
  4. Deliver Cyber agenda and integration of Information Security within business objectives for line of business area
  5. Serve as the central point of contact for your line of business technology executives into Capital One’s Cyber risk management priorities

Skills

Required

  • Demonstrated leader with team-oriented interpersonal skills
  • Ability to interface effectively with a broad range of people and roles
  • Expertise securing large-scale e-commerce platforms
  • Deep understanding of payments systems
  • Customer data protection across high transaction environments
  • Protection of user data across internal and partner ecosystems
  • Focused individual who thrives in a fast-paced, dynamic, and collaborative team environment
  • Deep passion for securing forward leaning, modern computing platforms
  • Intuitive knowledge and experience with Offensive and Defensive Security techniques
  • Comfortable with technologies and innovation including, Generative AI, Data Lakes, Cloud Services, Containers, Microservices, Serverless, APIs, DevOps, Encryption and Zero Trust
  • Strong desire to continually learn about new technologies
  • Enjoy leveraging engineering experience to problem solve
  • Display strong judgment, data/risk based decisioning, leadership, integrity, and communication skills
  • Ability to tailor communications and analysis to the intended audience
  • Passion and expertise in cybersecurity
  • Ability to be confident, respectful, and articulate when registering dissenting or unpopular opinions
  • Maintain calmness and clarity of thought under pressure
  • Ability to maintain confidentiality
  • Able to work well under minimal supervision
  • Deep understanding of strategic business objectives
  • Ability to drive results toward those objectives
  • Ability to describe the risks of a security exposure or vulnerability in business-impact terms
  • Bachelor's degree
  • At least 7 years of experience in Information Security

Nice to have

  • security as an enabler and differentiator
  • pragmatic and practical in understanding of risk and security
  • willing to know when to pull in experts and escalate
  • collaborate and innovate with other teams
  • lead complex problem solving in partnership with multiple stakeholders
  • driving results with critical impact
  • play a leading role in delivering product security advisory services
  • advise on strategic initiatives, programs, and projects to create business value
  • advocate in the value of data driven business decisions and products
  • comfortable with modern software, data analytics ecosystems, artificial intelligence, and cloud based technologies as well as associated protective methods
  • Educate and influence executive leadership and associates
  • Provide security expertise on prioritizing and managing information security risks and initiatives
  • Escalate and manage cyber security risk
  • Provide regular updates to executive leadership
  • Work with business leadership to anticipate their objectives and needs
  • advocate for security, business and digital innovation
  • instills a culture that works toward the highest standards in cyber
  • ensuring that business requirements are understood and adhered to
  • partner extensively with other Cyber and Technology organizations to derive solutions enabling industry leading products
  • Build relationships and influence with risk management functions across lines of defense
  • Become knowledgeable and advise on Capital One’s Cyber’s services, policies, procedures and standards
  • Staying current on the changing regulatory environment and understanding the impacts to the organization

What the JD emphasized

  • critical impact
  • heavy forward lean
  • critical impact
  • fast-paced environment
  • fast moving project
  • risk-based and agile manner
  • modern software
  • artificial intelligence
  • cloud based technologies