Manager, Cyber Technical

Capital One Capital One · Banking · Toronto, ON

This role is a Manager, Cyber Technical position at Capital One Canada, focusing on Information Security and Risk Management within the fintech domain. The responsibilities include consulting on initiatives, coordinating security consulting, serving as an expert in security capabilities, and influencing the adoption of security solutions. The role requires significant experience in security concepts, risk assessments, architecture reviews, cloud infrastructure, and managing industry standard audits and certifications, as well as Canadian regulators. While the company mentions responsible use of AI in recruitment, the core function of this role is not AI/ML development.

What you'd actually do

  1. Act as a central point of contact for your line of business to the rest of Capital One’s Information Security and Risk Management
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  4. Influence customers to leverage security capabilities and solutions to Shift and integrate security to the left in the development processes
  5. Work with line of business leadership to anticipate their objectives and needs to better serve line of business with strong conceptual thinking and communication skills

Skills

Required

  • At least 6 years of experience providing guidance and oversight of Security concepts
  • At least 6 years of experience performing security risk assessments and security architecture reviews
  • At least 6 years of experience with Architecture, software design, networking, and Cloud infrastructure
  • Proven experience managing industry standard security audit and certifications; ISO 27001, PCI DSS, SOC 1 or 2 TYPE I/II
  • Proven experience managing Canadian Regulators (OPC, OSFI)

Nice to have

  • Bachelor's degree in related technical fields or equivalent experience
  • Proven experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
  • Experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
  • Experience utilizing Agile methodologies
  • Experience with Software Application Security and Secure Architecture skills
  • Experience with Penetration Testing and/or Vulnerability Management
  • Professional certifications, such as AWS Certified Solutions Architect, Certified Information Systems Security Professional (CISSP) and Lead Security Auditor Certification or similar an asset
  • Experience is Offensive and/or Defensive Security techniques
  • Experience in a regulated environment

What the JD emphasized

  • Proven experience managing industry standard security audit and certifications; ISO 27001, PCI DSS, SOC 1 or 2 TYPE I/II
  • Proven experience managing Canadian Regulators (OPC, OSFI)
  • Experience in a regulated environment