Senior Manager, Cyber Threat Researcher, Cyber Intelligence (remote Eligible)

Capital One Capital One · Banking · McLean, VA +4 · Remote

This role focuses on leveraging cyber threat intelligence to counter, disrupt, and mitigate cyber adversaries targeting Capital One. It involves applying systems thinking and technical curiosity to detect, characterize, emulate, and predict cyber threats and adversary intentions. The role requires creating mechanisms to connect internal and external data sources to highlight cyber threats and fraud activity, maintaining expertise in the threat landscape, synthesizing data from various sources, and communicating findings to leadership.

What you'd actually do

  1. Create mechanisms to "connects the dots" between different internal and external data sources in order to combine “signals” in data that automatically highlight cyber threats across advanced enterprise threat activities and fraud activity
  2. Maintain industry-wide expertise of the current cyber threat landscape and attack vectors
  3. Synthesize disparate sets of data from sources such as malware, cyber attack patterns, closed and open-source intelligence, and tokenized consumer flows to inform instrumentation, detections, and threat narratives such as storyboards
  4. Build productive relationships with internal teams to contextualize, influence and inform Capital One’s business units on emerging threats
  5. Communicate investigative outcomes with technical architecture context and conclusions to a variety of audiences, including company senior leadership and business partners

Skills

Required

  • High School Diploma, GED or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 6 years of experience working in incident response, threat hunting, threat intelligence, forensics, or offensive security
  • At least 5 years of experience in conducting investigations or research into cyber-enabled fraud, cybercrime, or advanced persistent threats
  • At least 3 years of experience with cyber threat intelligence threat frameworks such as Lockheed Martin Cyber Kill Chain, Diamond Model, MITRE ATT&CK, ATLAS, Defense or Engage
  • At least 3 years of experience in programming or scripting with Python, Perl, PHP, PowerShell or SQL

Nice to have

  • Bachelor's Degree
  • 8 + years of experience working in cybersecurity or information technology
  • 8 + years of experience performing incident response, threat hunting, threat intelligence, forensics, or offensive security
  • 3+ years of experience with public cloud environments (AWS, Azure, GCP)
  • 3+ years of experience in a highly regulated industry (financial sector, financial technology, healthcare, or intelligence community)
  • 1+ year of experience working with Generative and Agentic AI tools

What the JD emphasized

  • experience in conducting investigations or research into cyber-enabled fraud, cybercrime, or advanced persistent threats
  • experience with cyber threat intelligence threat frameworks such as Lockheed Martin Cyber Kill Chain, Diamond Model, MITRE ATT&CK, ATLAS, Defense or Engage
  • experience in a highly regulated industry (financial sector, financial technology, healthcare, or intelligence community)