Manager Information Security Office (iso), Enterprise Data

Capital One Capital One · Banking · McLean, VA +2

Manager Information Security Office (ISO) for Enterprise Data at Capital One. This role involves consulting on information security initiatives, managing cyber risk, and ensuring security across various data and technology platforms, including cloud environments. Requires experience in cybersecurity, risk assessment, and cloud infrastructure.

What you'd actually do

  1. Act as a central Information Security point of contact for Capital One’s Enterprise Data organization
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering API Security, File Transfer, Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, Datalake Architecture, BI, and consumption tools, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  4. Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  5. Escalate and manage cyber security risk

Skills

Required

  • High School Diploma, GED or equivalent certification
  • At least 4 years of experience working in cybersecurity or information technology
  • At least 1 year of experience providing guidance and oversight of Security concepts
  • At least 1 year of experience performing security risk assessments and security architecture reviews
  • At least 1 year of experience with architecture, software design, networking, and cloud infrastructure

Nice to have

  • Bachelor’s Degree
  • 3+ years of experience with Software Security Architecture, Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management
  • 3+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
  • 1+ year of experience building software utilizing public cloud (AWS, GCP, Azure)
  • 1+ year of experience with Cloud patch management practices such as system rehydration and image management
  • 1+ year of experience utilizing Agile methodologies
  • 1+ year of experience with integrating SaaS products into an Enterprise Environment
  • 1+ year of experience with securing Container services
  • 1+ year of experience Splunk-Fu or Enterprise Monitoring experience
  • 1+ year of experience in Offensive and Defensive Security techniques
  • 1+ year of experience in a regulated environment
  • Financial services industry experience
  • Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)

What the JD emphasized

  • experience in a regulated environment