Manager, Governance and Compliance

Capital One Capital One · Banking · McLean, VA +2

This role is for a Manager, Governance and Compliance within Capital One's Technology and Data Risk Management (TDRM) organization. The individual will partner with stakeholders to assess compliance impacts of risk-taking activities, evaluate international laws and regulatory requirements, and ensure systems and procedures are compliant and resilient. Responsibilities include compliance advisory, regulatory mapping, risk assessments, issue management, and stakeholder collaboration, focusing on technology and cyber risk within a regulated financial institution.

What you'd actually do

  1. Provide guidance and effective challenge on the compliance risk of business initiatives.
  2. Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they translate into organizational requirements and controls.
  3. Perform technology and cybersecurity risk management requirement applicability and impact assessments against business, technology and cyber processes.
  4. Coordinate and execute compliance assessments for risk taking activities and process breakdowns against these organizational technology and cybersecurity risk management requirements, including any planned remediation; ensuring the team has a documented, rationalized and repeatable assessment methodologies.
  5. Identify compliance issues requiring investigation or follow-up.

Skills

Required

  • Bachelor’s degree or military experience
  • At least 4 years of experience working in the fields of information security, technology, or risk management
  • At least 3 years of experience in a second-line or oversight role at a financial institution or regulatory agency
  • At least 3 years of experience developing, evaluating, or implementing cybersecurity, technology or compliance risk assessments

Nice to have

  • 4+ years of experience in a second-line or oversight role at a financial institution or regulatory agency; prior compliance work at Visa, Mastercard or American Express
  • Knowledge of supervisory expectations expressed in the FFIEC IT Handbook, Federal Reserve Supervisory Letters, Office of the Comptroller of the Currency Bulletins, or Federal Deposit Insurance Corporation Financial Institution Letters
  • Professional security management certifications, such as a Certified Information Systems Security
  • Working knowledge of domestic and international regulatory requirements and laws that govern credit and debit network
  • Professional (CISSP) or Certified Information Security Manager (CISM)
  • Excellent verbal and written communication skills
  • Experience in cybersecurity, with the ability to be provide credible challenge when necessary
  • Ability to manage multiple projects while maintaining superior results
  • Ability to work cross-functionally

What the JD emphasized

  • international laws and regulatory requirements
  • evolving global regulatory landscape
  • international payment requirements
  • federal, state, and international tech and cyber laws
  • industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance
  • domestic and international regulatory requirements and laws that govern credit and debit network