Director, Special Oversight Projects

Capital One Capital One · Banking · McLean, VA +2

Director of Special Oversight Projects at Capital One, focusing on cybersecurity and technology risk management within a regulated financial institution. This role involves leading critical projects, conducting technical assessments, researching best practices, and advising on technology and data risk to ensure compliance and strategic alignment. The position requires deep hands-on experience across multiple cybersecurity domains and strong influencing skills to communicate risks to various stakeholders, including executives and regulators.

What you'd actually do

  1. Represent our team in technology councils to ensure an appropriate risk lens is applied to cyber and technology initiatives and strategic programs.
  2. Bring a passion to stay on top of cyber trends and emerging risks, experiment with and learn new technologies, participate in internal & external technology communities, and mentor other members of the risk management and engineering community.
  3. Partner broadly across the enterprise to identify and assess continually evolving threats in a fast moving and complex environment. You’ll advise architecture decisions and roadmaps across all domains of cybersecurity and technology.
  4. Build and maintain relationships with technical leaders, engineers, architects, and other stakeholders to understand and evaluate implementation plans, business priorities and technical solutions to ensure risks are well communicated and understood by the key stakeholders.
  5. Go deep on a specific area of technology to identify the risks in our current posture and help our company identify leading solutions that raise the bar.
  6. Evaluate proposed plans from first line cyber and associate experience tech to assess risks and threats; challenge assumptions and technical approaches and recommend.
  7. Draft and communicate independent reports to inform broad audiences including engineers, executives, business leaders, product managers, board of directors, and regulators on the current cyber and associate experience technology risk environment.

Skills

Required

  • Bachelor’s degree or military experience
  • At least 10 years of experience in multiple domains of cyber security
  • At least 5 years of technical experience in at least two domains of cyber security such as identity and access management and security engineering

Nice to have

  • 3+ years of experience at a major technology company
  • 3+ years of experience drafting, tailoring, and communicating complex technical and cyber risk reports to all levels, including senior executives, the Board, and regulatory bodies
  • Demonstrated ability to work independently, manage complex, ambiguous projects, and drive outcomes across enterprise boundaries
  • Hands-on experience APPLYING and CHALLENGING major security and risk frameworks (NIST CSF, NIST 800-53, ISO 27000-1) at a large-scale
  • Cybersecurity certifications such as: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); or Certified in Risk and Information Systems Control (CRISC)

What the JD emphasized

  • deep, hands-on experience across multiple core cyber security domains
  • navigate ambiguity
  • independent reports to inform broad audiences including engineers, executives, business leaders, product managers, board of directors, and regulators
  • Hands-on experience APPLYING and CHALLENGING major security and risk frameworks (NIST CSF, NIST 800-53, ISO 27000-1) at a large-scale