Senior Manager Information Security Office (iso)

Capital One Capital One · Banking · McLean, VA +2

Senior Manager for Information Security Office (ISO) at Capital One, focusing on cybersecurity and risk management within a financial services context. The role involves providing product security advisory services, consulting on various security domains (API, Data, Infrastructure, Network, Access Management), and ensuring secure software and technology architectures. It requires experience in cloud security, risk assessments, and working within regulated environments.

What you'd actually do

  1. Act as a central Information Security point of contact supporting Capital One’s Enterprise Data and horizontal services organizations.
  2. Coordinate and execute proactive Information Security consulting to the business and technology teams covering API Security, File Transfer, Data Security, Infrastructure Security, Resiliency, Network Architecture and Design, and User Access Management
  3. Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures, and standards
  4. Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  5. Escalate and manage cyber security risk

Skills

Required

  • High School Diploma, GED or equivalent certification
  • At least 6 years of experience working in cybersecurity or information technology
  • At least 5 years of experience providing guidance and oversight of Security concepts
  • At least 5 years of experience performing security risk assessments and security architecture reviews
  • At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
  • At least 4 years of experience with cloud security engineering

Nice to have

  • Bachelor’s Degree
  • 6+ years of experience with Software Security Architecture, Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management
  • 6+ years of experience in securing a public cloud environment and building software utilizing public cloud
  • 6+ years of experience with Cloud patch management practices such as system rehydration or image management
  • 1+ years of experience utilizing Agile methodologies
  • 1+ years of experience with API Security
  • 1+ years of experience with File Transfer systems
  • 1+ years of experience with data ecosystems, applications, privacy, and compliance
  • 1+ years of experience with integrating SaaS products into an Enterprise Environment
  • 1+ years of experience with securing Container services
  • 1+ years of experience with ERP modernization or implementation
  • 1+ years of experience with Offensive or Defensive Security techniques
  • 1+ years of experience in a Financial services industry
  • Experience in a regulated environment
  • AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification

What the JD emphasized

  • heavy forward lean on modern software and technology architectures
  • lead complex problem solving
  • driving results with critical impact
  • play a leading role in delivering product security advisory services
  • strategic initiatives, programs, and projects
  • risk-based and agile manner
  • deep passion for Securing modern computing platforms
  • strong desire to continually learn about new technologies
  • demonstrated leader
  • team-oriented interpersonal skills
  • interface effectively with a broad range of people and roles
  • maintain calmness and clarity of thought under pressure
  • deep understanding of strategic business objectives
  • drive results toward those objectives
  • experience working in cybersecurity or information technology
  • experience providing guidance and oversight of Security concepts
  • experience performing security risk assessments and security architecture reviews
  • experience with architecture, software design, networking, and cloud infrastructure
  • experience with cloud security engineering
  • experience with Software Security Architecture, Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management
  • experience in securing a public cloud environment and building software utilizing public cloud
  • experience with Cloud patch management practices
  • experience with API Security
  • experience with data ecosystems, applications, privacy, and compliance
  • experience with Offensive or Defensive Security techniques
  • Experience in a regulated environment