Director, Metrics Strategy and Reporting

Capital One Capital One · Banking · McLean, VA +5

Director of Metrics Strategy and Reporting at Capital One, focusing on developing and implementing metrics for cybersecurity, technology risk, and developer quality. The role involves driving improvements in reporting, coordinating with senior leadership and the Board of Directors, and supporting executive-level risk communication. Requires strong leadership, quantitative methods, and experience in technology/cyber risk.

What you'd actually do

  1. Understand our current approach and develop a strategy to better use metrics, dashboards, and governance fora to drive change. The intended audience starts at the program manager level and progresses up through the Board of Directors and formal risk appetite metrics.
  2. Develop suites of metrics across the technology, technology risk, and cybersecurity domains, aligned to industry frameworks.
  3. Engage stakeholders across the first, second, and third lines of defense to align on the metrics and thresholds.
  4. Dive deeply into different domains to understand the shortcomings and limitations of metrics and ensure they are appropriately documented and communicated.
  5. Monitor metrics, investigate anomalies, and escalate necessary response actions.

Skills

Required

  • Bachelor’s degree or military experience
  • 10 years of experience in cybersecurity or technology risk
  • 5 years of experience with cybersecurity or technology risk metrics
  • 5 years of experience with governance fora
  • 3 years of experience leading people

Nice to have

  • Master’s degree in computer science, mathematics, or engineering
  • 12 years of experience in cybersecurity or technology risks related to resilience, reliability, or code quality
  • 3 years of experience in cloud computing
  • Understanding of more than one of the following domains: cybersecurity, site reliability engineering, dev/ops, and developer excellence
  • Experience revamping an organizational metrics program
  • Experience with governance fora in which senior leaders use metrics to manage their organizations

What the JD emphasized

  • At least 10 years of experience in cybersecurity or technology risk
  • At least 5 years of experience with cybersecurity or technology risk metrics
  • At least 5 years of experience with governance fora
  • At least 3 years of experience leading people