Senior Lead Information Security Office Consultant

Capital One Capital One · Banking · McLean, VA +3

This role is for a Senior Lead Information Security Office Consultant who will consult on initiatives, programs, and projects to improve Information Security within the Developer Experience line of business. Responsibilities include acting as a central Information Security point of contact, coordinating proactive consulting, serving as an expert in security capabilities, collaborating with enterprise cyber teams on architecture strategy, supporting DevSecOps efforts, influencing the adoption of security capabilities, managing cyber risk, and providing updates to leadership. The role requires a strong background in development tooling and processes with a cyber lens, and the ability to drive policy and support higher-level decisions.

What you'd actually do

  1. Act as a central Information Security point of contact for the Developer Experience line of business
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  4. Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.
  5. Support security architecture and implementation needs for technology modernization and DevSecOps efforts

Skills

Required

  • Information Security
  • Cybersecurity
  • Risk Management
  • Cloud Security (AWS, GCP, Azure)
  • DevSecOps
  • ISO 27001
  • ITIL
  • COBIT
  • PCI DSS
  • GDPR
  • NIST Cyber Security Frameworks
  • Software Design
  • Networking
  • Cloud Infrastructure

Nice to have

  • Threat Modeling
  • Integrating SaaS products
  • Securing Container services
  • Offensive or Defensive Security techniques
  • CISSP
  • AWS Certified Solutions Architect

What the JD emphasized

  • Experience in a financial or highly regulated environment.
  • Practical experience of working in or leading components of a structured security program, working with business teams to identify and manage cyber risk.
  • Demonstrable experience in cyber risk analysis, threat modeling, assessment, remediation, and mitigation.