Principal Risk Associate | Retail Bank Tech at Capital One McLean, VA
Listed on 2026-07-30
-
IT/Tech
Cybersecurity
Role Summary
The Principal Associate within the Tech, Cyber, Data, and Resiliency (TCDR) team will strategically apply analytical expertise to proactively identify, measure, and mitigate complex TCDR risks while simultaneously promoting and fostering innovation across the division. This highly collaborative role requires partnerships with Technology, Business, and Second Line teams to identify and mitigate risks. The Principal Associate also serves as a Dedicated Tech Risk Partner (DTRP) to key technology stakeholders, functioning as a trusted risk partner who proactively manages risk by working with engineering teams to develop effective, compliant solutions and reporting to executive leadership.
The position drives organizational change through the identification, rigorous measurement, detailed analysis, and comprehensive reporting of TCDR risks, managing and continuously improving Tech Risk Metrics across Technology, Compliance, Stability, and Resiliency, and ensuring a strong overall control environment.
- Serve as the go‑to Tech Risk Partner for assigned engineering and technology teams, providing “white glove service” to ensure all necessary risk management support, guidance, and resources are provided promptly.
- Proactively work with technical teams to develop and execute clear pathways to achieve compliance, drafting audit responses and reducing regulatory exposure and control failures.
- Ensure all TCDR governance questions, requirements, and compliance checks are addressed and integrated into new service intake processes, preventing downstream risk and redesign efforts.
- Participate in Material Tech Change (MTC) reviews to identify and vet potential risk scenarios, assess threat models, and ensure controls are updated to reflect planned changes to the technology environment.
- Support RCSA by facilitating cross‑functional risk workshops to identify and evaluate inherent risks and control effectiveness, documenting clear conclusions and insights across technical domains.
- Conduct thorough control analysis to identify design gaps, missing documentation, or outdated controls, partnering with business leaders to perform risk leveling and ensure appropriate control coverage.
- Prepare high‑quality executive reports that summarize the Tech, Cyber, Data, and Resiliency point of view on technology risks derived from the RCSA process.
- Foster collaborative relationships with stakeholders across the Second Line and Third‑Party Risk Management to ensure risk alignment.
- Monitor the progress of remediation activities, following up on outstanding control actions or delays to ensure timely risk mitigation.
- Support control dissertation by managing spreadsheets with up‑to‑date RCSA materials and comprehensive summaries.
- Serve as a subject‑matter expert for metrics in Compliance, Resiliency, Release Management, and Stability, developing and maintaining living standard spreadsheets with current metrics, thresholds, non‑compliance triggers, and associated risk.
- Establish and execute a daily process to report on non‑compliant metrics to business partners and engineers.
- Contribute to the monthly executive deck by explaining drivers for non‑compliance and proposing paths to achieve compliance.
- Provide detailed quarterly reporting on non‑compliant metrics for executive governance forums.
- Immediately investigate and validate reported critical incidents, documenting root cause theory, resolution, and lessons learned.
- Feed trend data from repeated technology outage incidents back into the RCSA program to update control narratives or increase criticality ratings.
- At least 3 years of Cyber & Tech Risk Analysis experience.
- At least 3 years of experience in Risk Management, Compliance, Audit, or Control Testing.
- 4+ years of experience in a dedicated role focused on Technology Risk, Cyber Risk, or Business Continuity.
- 2+ years of consulting experience with client and stakeholder relationships.
- Excellent written and verbal communication skills, including experience presenting complex risk topics to executive audiences.
- Relevant professional certification (e.g., CRISC, CISA, or other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).