Principal Associate, Cyber Controls Monitoring Analyst

Capital One Capital One · Banking · McLean, VA +2

This role focuses on engineering automated health metrics for cyber controls within an enterprise reporting platform. It involves transforming telemetry data into real-time insights using Python and SQL, collaborating with stakeholders, and ensuring the full lifecycle of control health metrics. The role operates at the intersection of GRC and engineering, treating control assurance as a product.

What you'd actually do

  1. Metric Engineering: Collaborate with cross functional teams and execute control walkthroughs to understand operations, identify data sources across disparate systems, and translate control designs/requirements into health metrics
  2. ETL Pipeline Development: Design, develop, test, implement end-to-end data pipelines and metrics using Python and SQL based on control requirements
  3. Technical Troubleshooting: Manage the full lifecycle of the control health metrics to maintain, debug, troubleshoot, and govern production pipelines
  4. Stakeholder Engagement: Collaborate with Control SMEs and Accountable Executives (AEs) to define metrics and threshold logic, gain approval of control metrics, and facilitate remediation/escalation steps upon threshold breach
  5. Continuous Improvement: Provide recommendations for enhancing control effectiveness and mitigating risks based on data-driven insights

Skills

Required

  • High School Diploma, GED, or equivalent certification
  • 3 years of experience in data analysis in a compliance, audit, or risk management environment
  • 2 years of experience in data manipulation and analysis
  • 2 years of experience with SQL and Python
  • 2 years of experience with version control (Git) and Continuous integration and continuous deployment

Nice to have

  • Bachelor's Degree
  • 5+ years of experience in data analysis in a compliance, audit, or risk management environment
  • 4+ years of experience developing metrics for a continuous controls monitoring program or a controls portfolio
  • 4 + years of experience developing config-driven data pipelines end-to-end including analytical SQL (CTEs, window functions), Python-based transformations (Pandas), REST API integration (OAuth, pagination), and inline data quality validation
  • 3 + years of experience with regulatory requirements and control frameworks (NIST 800.53, SOX, or COSO)
  • 3+ years of experience with an understanding of how security controls operate in practice including control types, execution patterns, and common failure points
  • 3+ years of experience connecting control monitoring to the underlying risks and threat scenarios that the control is designed to address

What the JD emphasized

  • control assurance as a product
  • automated measurements of Capital One’s security posture
  • automated health metrics for Cyber controls
  • real-time insights
  • prevent security process degradation
  • end-to-end data pipelines and metrics
  • full lifecycle of the control health metrics
  • regulatory requirements and control frameworks (NIST 800.53, SOX, or COSO)
  • security controls operate in practice