Risk Manager, Endpoint Security

Capital One Capital One · Banking · McLean, VA +3

This role is for a Risk Manager focused on Endpoint Security within Capital One's Technology & Data Risk Management (TDRM) organization. The individual will provide oversight, credible challenge, and expert advice to manage risks associated with cyber operations, specifically focusing on endpoint security controls, operational effectiveness, and associated processes. This involves technical assessments, risk identification, and reporting to senior management and regulatory agencies. The role requires significant experience in implementing various endpoint security tools and technologies, along with consulting, audit, or risk management experience. Familiarity with cybersecurity frameworks and certifications is preferred.

What you'd actually do

  1. Provide advisory, oversight, and effective challenge to the 1st Line of defense.
  2. Provide technical assessments of cybersecurity controls design and effectiveness.
  3. Draft assessments for senior management and other stakeholders, to include regulatory agencies and the Board of Directors, as needed.
  4. Stay current on emerging cyber threats and potential implications to the firm.
  5. Collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to achieve objectives.

Skills

Required

  • Bachelor's degree or military experience
  • At least 5 years of experience implementing endpoint detection and response (EDR) tools with anti-malware and anti-virus functionality
  • At least 3 years of experience implementing application whitelisting technologies
  • At least 3 years of experience implementing next-generation endpoint platforms such as virtual desktop infrastructure (VDI) or thin clients or thin platforms.
  • At least 3 years of experience implementing tools and processes that remove sensitive data off endpoints
  • At least 3 years of experience with Mobile Device Management (MDM) or Mobile Application Management (MAM)
  • At least 2 years of experience with Privileged Access Management (PAM) tools
  • At least 2 years of consulting, audit, or risk management experience

Nice to have

  • Familiarity with NIST Cybersecurity Framework controls, NIST 800-53, ISO 27000-1
  • Cybersecurity certifications such as: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); or Certified in Risk and Information Systems Control (CRISC)
  • Cloud certifications for Amazon Web Services (AWS) or Google Cloud Platform (GCP)

What the JD emphasized

  • Endpoint Security
  • cybersecurity
  • risk management
  • technical assessments
  • operational effectiveness
  • regulatory agencies