Senior Manager, Information Security Office Consultant

Capital One Capital One · Banking · McLean, VA

Senior Manager, Information Security Office Consultant at Capital One, responsible for consulting on information security initiatives within the Enterprise Data organization. The role involves coordinating proactive security consulting across various domains including API security, data security, infrastructure security, and user access management. It requires influencing customers to integrate security early in development processes, managing cyber security risk, and providing updates to executive leadership. The ideal candidate has a strong background in cybersecurity, IT, security risk assessments, architecture reviews, and cloud security engineering, with a passion for securing modern computing platforms.

What you'd actually do

  1. Act as a central Information Security point of contact for Capital One’s Enterprise Data organization
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering API Security, File Transfer, Data Security, Infrastructure Security, Resiliency, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures, and standards
  4. Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  5. Escalate and manage cyber security risk

Skills

Required

  • High School Diploma, GED, or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 5 years of experience providing guidance and oversight of Security concepts
  • At least 5 years of experience performing security risk assessments and security architecture reviews
  • At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
  • At least 3 years of experience with cloud security engineering

Nice to have

  • Bachelor’s Degree
  • 6+ years of experience with Software Security Architecture, Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management
  • 6+ years of experience in securing a public cloud environment and building software utilizing public cloud
  • 6+ years of experience with Cloud patch management practices such as system rehydration or image management
  • 1+ years of experience utilizing Agile methodologies
  • 1+ years of experience with API Security
  • 1+ years of experience with File Transfer systems
  • 1+ years of experience with data ecosystems, applications, privacy, and compliance
  • 1+ years of experience with integrating SaaS products into an Enterprise Environment
  • 1+ years of experience with securing Container services
  • 1+ years of experience with Splunk-Fu and Enterprise Monitoring
  • 1+ years of experience with Offensive or Defensive Security techniques
  • 1+ years of Financial services industry experience
  • Experience in a regulated environment
  • AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification

What the JD emphasized

  • Experience in a regulated environment