Sr. Manager, Tech Risk & Analysis
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager, IT Consultant
Do you love navigating complex technology landscapes and safeguarding critical systems? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and risk-conscious delivery environment? At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors who love to solve real problems and meet real customer needs. We are seeking Tech Risk & Analysis Professionals who are passionate about cyber best practices, threat analysis, and risk mitigation to join our team.
In this role, you’ll have the opportunity to be on the forefront of driving cybersecurity governance, resilience, and risk transformation across Capital One.
The Enterprise Services Risk Operations (ESRO) organization is expanding with a focus on attracting innovative, pioneering, collaborative, and highly skilled professionals. We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we work to redefine the financial sector.
As a Senior Manager on the Enterprise Services Controls Governance team, you will work with Technology, Cyber, and other teams in both the first and second lines of defense to consult on controls and apply your risk management skills to help Enterprise Services drive a well-managed control environment. You will be responsible for overseeing the end-to-end Controls Lifecycle Management process to ensure adherence to the Enterprise Control Standard.
You will develop a strategy roadmap to enhance the overall program, identifying automation opportunities to streamline the process and enhance data-driven reporting for ESRO stakeholders.
- Applies expertise on cyber best practices to assess current state, identify gaps, and assess cyber risk, threats, and business impact
- Defines mitigation strategies, prioritises and escalates recommendations
- Participates in design and implementation of cyber control programs
- Cybersecurity area-specific SME [knowledge of risk frameworks, information security risk assessments, information risk controls, regulatory and internal governance], data analysis [metrics and reporting], and customer engagement
- Manage end to end controls lifecycle management along with ensuring adherence to Enterprise Control Standard
- Oversee the comprehensive design assessment for new controls to ensure they are well-built and ready for testing
- Lead a team of risk professionals as they help lines of business create and update controls that duly manage the risk in the system
- Work with the Enterprise Services Risk Partners to ensure that impact of control changes on processes such as regulatory gap assessments, process and risks are thoroughly assessed and reflected in the system of record
- Build metrics around data quality and periodically monitor to ensure control data is complete and accurate in the system of record
- Partner with Enterprise Services Risk Analytics to identify and implement automated solutions to enable proactive risk management
- Support development of content in response to Internal Audit and Regulatory agencies related to controls management
- Drive project and program delivery, including project and process management, reporting, facilitation of senior leadership meetings, drafting and reviewing materials for senior management and the Board of directors, and other governance activities
- Bachelor’s Degree or military experience
- At least 7 years of experience in technology (software delivery, distributed systems, cloud-native architecture, infrastructure as code), cybersecurity (identity and access management, application security, cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).