Vulnerability Remediation Manager, Security Testing Service

Capital One Capital One · Banking · McLean, VA +3

This role focuses on managing vulnerability remediation within Capital One's Security Testing Service, acting as a subject matter expert to guide business and engineering teams on cybersecurity best practices and risk reduction. It involves evaluating control programs, communicating security gaps, and leading enterprise-wide remediation efforts.

What you'd actually do

  1. Serve as an Cyber Security Remediation subject matter expert
  2. Collaborate with a team of Information Security professionals to provide subject matter expertise to business project & engineering teams
  3. Evaluate the status of Cyber control programs through analysis of information security metrics
  4. Articulate operations, compliance, and cybersecurity objectives for business leadership to inform prioritized risk reduction
  5. Lead activities in response to large-scale enterprise remediation efforts

Skills

Required

  • High School Diploma, GED, or equivalent certification
  • At least 4 years of experience with vulnerability identification and management
  • At least 4 years of experience with IT operations
  • At least 4 years of experience with technology or cyber security risk management frameworks
  • strong written and verbal communication skills
  • strong organizational skills
  • ability to drive tasks to completion
  • ability to negotiate and influence results without direct authority
  • team-oriented
  • interface effectively with a broad range of people and roles
  • maintain calmness and clarity of thought under pressure
  • maintain confidentiality
  • work well under minimal supervision

Nice to have

  • CISSP, CEH, AWS Cloud Practitioner or AWS Certified Solutions Architect Associate certification
  • Experience with monitoring, gathering, and assessing artifacts as part of continuous security monitoring (C&A, PO&AM, NIST 800-37)
  • Experience in operational compliance or IT audit
  • Experience as a Systems Administrator or Network Administrator
  • Experience with Static and Dynamic Application Security Testing, scanning tools and processes
  • Experience utilizing Agile methodologies

What the JD emphasized

  • vulnerability identification and management
  • IT operations
  • technology or cyber security risk management frameworks