Director, Metrics Strategy and Reporting

Capital One Capital One · Banking · McLean, VA +5

Capital One is seeking a Director, Metrics Strategy and Reporting to develop and implement a strategy for using metrics to drive change in cybersecurity, technology risk, and developer quality. The role involves updating existing metrics, improving reporting processes, and coordinating key reports for executive audiences, including the Board of Directors. The ideal candidate will have strong knowledge of quantitative methods applied to technology/cyber risk and experience in people leadership.

What you'd actually do

  1. Understand our current approach and develop a strategy to better use metrics, dashboards, and governance fora to drive change. The intended audience starts at the program manager level and progresses up through the Board of Directors and formal risk appetite metrics.
  2. Develop suites of metrics across the technology, technology risk, and cybersecurity domains, aligned to industry frameworks.
  3. Engage stakeholders across the first, second, and third lines of defense to align on the metrics and thresholds.
  4. Dive deeply into different domains to understand the shortcomings and limitations of metrics and ensure they are appropriately documented and communicated.
  5. Monitor metrics, investigate anomalies, and escalate necessary response actions.

Skills

Required

  • Bachelor’s degree or military experience
  • 10 years of experience in cybersecurity or technology risk
  • 5 years of experience with cybersecurity or technology risk metrics
  • 5 years of experience with governance fora
  • 3 years of experience leading people

Nice to have

  • Master’s degree in computer science, mathematics, or engineering
  • 12 years of experience in cybersecurity or technology risks related to resilience, reliability, or code quality
  • 3 years of experience in cloud computing
  • Understanding of cybersecurity, site reliability engineering, dev/ops, and developer excellence
  • Experience revamping an organizational metrics program
  • Experience with governance fora in which senior leaders use metrics to manage their organizations

What the JD emphasized

  • At least 10 years of experience in cybersecurity or technology risk
  • At least 5 years of experience with cybersecurity or technology risk metrics
  • At least 5 years of experience with governance fora
  • At least 3 years of experience leading people