Sr. Risk Manager, Data Protection

Capital One Capital One · Banking · Richmond, VA +3

This role is for a Sr. Risk Manager focused on Data Protection within Capital One's Technology Risk Management (TRM) organization. The individual will provide oversight, credible challenge, and expert advice on managing risks associated with cyber operations, specifically in areas like data labeling, classification, tokenization, and encryption. The role involves assessing cybersecurity capabilities, operational effectiveness, and controls infrastructure, collaborating with various teams, and staying current on emerging cyber threats. It requires experience in cybersecurity or enterprise data management, with a focus on data protection technologies and risk management principles.

What you'd actually do

  1. Play a lead role in identifying areas of cyber risk to provide oversight, analysis, effective challenge, and risk-informed recommendations for enhancement.
  2. Provide technical assessments of cybersecurity and controls design and effectiveness.
  3. Draft assessments for senior management and other stakeholders, to include regulatory agencies and the Board of Directors, as needed.
  4. Stay current on emerging cyber threats and potential implications to the firm.
  5. Collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to achieve objectives.

Skills

Required

  • Bachelor’s degree or military experience
  • 5 years of experience in cybersecurity or enterprise data management
  • 3 years of hands-on experience with data protection, technology such as encryption, tokenization, labeling or cryptography
  • 2 years of audit, risk management, program management or technology leadership experience

Nice to have

  • 2+ years of consulting experience
  • 2+ years of experience driving enterprise remediation efforts
  • Experience as a team leader or technical lead
  • Familiarity with NIST Cybersecurity Framework controls, NIST 800-53, ISO 27000-1
  • Professional cyber certifications (Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC))
  • Professional Amazon Web Services (AWS) certifications (Solutions Architect, Security Specialty)

What the JD emphasized

  • hands-on cybersecurity technical and operational experience
  • technical skills and cyber subject matter expertise
  • assessing and challenging cybersecurity capabilities and operational effectiveness
  • subject matter expertise and oversight and effective challenge of the key cybersecurity domain of data protection
  • review, risk identification, risk assessment, reporting, and effective challenge of cybersecurity controls, operational capabilities, and associated processes
  • highly-skilled cyber, technology, and risk management professionals
  • perform and support evaluations of the effectiveness of the firm’s cyber controls infrastructure
  • offer independent advice and recommendations regarding ways to further mature the firm’s cyber risk management capabilities
  • proven ability to work independently in a fast-paced environment and who can begin contributing immediately