Director, Technology & Cyber Risk Metrics

Capital One Capital One · Banking · Richmond, VA +1

This role is focused on developing and implementing metrics and reporting strategies for technology and cyber risk management within a large financial institution. The Director will oversee the creation of metrics, engage stakeholders, monitor performance, and ensure clear communication to executive audiences, including the Board of Directors. The role requires strong leadership, quantitative skills, and experience in cybersecurity and technology risk.

What you'd actually do

  1. Understand our current approach and develop a strategy to better use metrics, dashboards, and governance fora to drive change.
  2. Develop suites of metrics across the technology, technology risk, and cybersecurity domains, aligned to industry frameworks.
  3. Engage stakeholders across the first, second, and third lines of defense to align on the metrics and thresholds.
  4. Dive deeply into different domains to understand the shortcomings and limitations of metrics and ensure they are appropriately documented and communicated.
  5. Monitor metrics, investigate anomalies, and escalate necessary response actions.

Skills

Required

  • Bachelor's degree or military experience
  • At least 10 years of experience in cybersecurity or technology risk
  • At least 5 years of experience with cybersecurity or technology risk metrics
  • At least 5 years of experience with governance fora
  • At least 3 years of experience leading people

Nice to have

  • Master's degree in computer science, mathematics, or engineering
  • At least 12 years of experience in cybersecurity or technology risks related to resilience, reliability, or code quality
  • At least 3 years of experience in cloud computing
  • An understanding of more than one of the following domains: cybersecurity, site reliability engineering, dev/ops, and developer excellence
  • Experience revamping an organizational metrics program
  • Experience with governance fora in which senior leaders use metrics to manage their organizations

What the JD emphasized

  • technology risk
  • cybersecurity
  • metrics
  • governance
  • risk management