Senior Lead Information Security Office Consultant

Capital One Capital One · Banking · McLean, VA +2

This role is for a Senior Lead Information Security Office Consultant at Capital One, focusing on providing information security consulting to various business and technology teams. The consultant will act as a central point of contact for security services, influence the integration of security into development processes, manage cyber risk, and provide updates to leadership. The role requires experience in cybersecurity, IT, security risk assessments, architecture reviews, cloud security engineering, and securing public cloud environments. Experience in a regulated environment is preferred.

What you'd actually do

  1. Act as a central Information Security point of contact for the Data Protection Service, Endpoint Security and Cyber Intelligence services
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  4. Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  5. Escalate and manage cyber security risk

Skills

Required

  • High School Diploma, GED or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 5 years of experience providing guidance and oversight of cybersecurity concepts
  • At least 5 years of experience performing security risk assessments or security architecture reviews
  • At least 5 years of experience with architecture, software design, networking, or cloud infrastructure
  • At least 4 years of experience with cloud security engineering
  • At least 4 years of experience in securing a public cloud environment

Nice to have

  • Bachelor’s Degree
  • Experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
  • Familiarity with Cloud patch management practices such as system rehydration and image management
  • Experience utilizing Agile methodologies
  • Experience with Software Security Architecture
  • Experience with Application Security
  • Experience with Threat Modeling
  • Experience with Penetration Testing or Vulnerability Management
  • Experience with integrating SaaS products into an Enterprise Environment
  • Experience with securing Container services
  • Splunk-Fu / Enterprise Monitoring experience
  • Financial services industry experience
  • Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
  • Experience in Offensive or Defensive Security techniques
  • Experience in a regulated environment

What the JD emphasized

  • public cloud environment
  • regulated environment