Risk Remediation Assessor

Capital One Capital One · Banking · Nottingham, United Kingdom

This role focuses on assessing and managing risks associated with third-party engagements for Capital One, ensuring compliance with security standards and remediating identified issues. It involves partnering with internal and external stakeholders, evaluating control environments, and delivering assessment reports.

What you'd actually do

  1. Support kick-off, planning and scoping activities for cyber-focused risk assessments, working with cross functional resources to understand the operational and technical aspects of Third Party engagement model.
  2. Analyse Third Party control environment data against Capital One security expectations; interpreting information security requirements and reasonably apply them to specific situations.
  3. Review and support execution and delivery of reports including executive summaries and work papers detailing the assessment. work completed, evidence reviewed, and identified gaps.
  4. Maintain relationships with Third Party management, and other Enterprise colleagues to manage expectations of assessments and remediation including timing and assessment deliverables.
  5. Ensure compliance to program process and procedures.

Skills

Required

  • Information Security
  • Risk Management
  • Supply Chain Management
  • PCI DSS
  • NIST Framework
  • IT operations management

Nice to have

  • CISSP
  • CISA
  • CRISC

What the JD emphasized

  • risk assessment
  • risk remediation
  • security