Senior Lead Information Security Office Consultant

Capital One Capital One · Banking · Plano, TX +1

This role involves consulting on information security initiatives, programs, and projects, with a focus on Data Protection, Endpoint Security, and Cyber Intelligence. The consultant will provide proactive security consulting across various domains including Infrastructure Security, Resiliency, Data Security, Network Architecture, and User Access Management. They will act as an expert in Capital One's security capabilities, influence customers to integrate security early in development processes, manage cyber security risk, and provide updates to leadership on the security health and risk environment.

What you'd actually do

  1. Act as a central Information Security point of contact for the Data Protection Service, Endpoint Security and Cyber Intelligence services
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  4. Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  5. Escalate and manage cyber security risk
  6. Provide ad hoc support on special Information Security hot topics for the business
  7. Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
  8. Work with line of business leadership to anticipate their objectives and needs to better serve the line of business

Skills

Required

  • High School Diploma, GED or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 5 years of experience providing guidance and oversight of cybersecurity concepts
  • At least 5 years of experience performing security risk assessments or security architecture reviews
  • At least 5 years of experience with architecture, software design, networking, or cloud infrastructure
  • At least 4 years of experience with cloud security engineering
  • At least 4 years of experience in securing a public cloud environment

Nice to have

  • Bachelor’s Degree
  • Experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
  • Familiarity with Cloud patch management practices such as system rehydration and image management
  • Experience utilizing Agile methodologies
  • Experience with Software Security Architecture
  • Experience with Application Security
  • Experience with Threat Modeling
  • Experience with Penetration Testing or Vulnerability Management
  • Experience with integrating SaaS products into an Enterprise Environment
  • Experience with securing Container services
  • Splunk-Fu / Enterprise Monitoring experience
  • Financial services industry experience
  • Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
  • Experience in Offensive or Defensive Security techniques

What the JD emphasized

  • Experience in a regulated environment