Manager, Business & Technology Process Management - Enterprise Services Risk Operations; ESRO
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
The Enterprise Services Risk Operations (ESRO) organization is expanding with a focus on attracting innovative, pioneering, collaborative, and highly skilled professionals. We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we work to redefine the financial sector.
As a Manager on the Process Risk Optimization (PRO) Team, you will be responsible for working with business partners to proactively identify and lead risk mitigation solutions for Capital One. We are the first line of defense to help ensure our Company remains well-managed and strengthens its risk posture. Our team delivers strategic, value-added, and risk-based analysis to drive executive leadership decision-making.
In this position, you will play a key role in supporting process-based assessments to identify and evaluate risks across various Enterprise Services functional areas, such as cyber, cloud operations, network connectivity, enterprise product management, development, data management, resiliency, and third party functions.
You will learn about Capital One’s internal operations as you develop subject matter expertise while collaborating with business partners to identify, assess, measure, monitor, control, and report process-level risks. As a Manager, you will lead stakeholder interactions, facilitating assessments and completing deliverables in a fast-paced environment, working across multiple teams to drive successful project outcomes.
In this role, you will:- Perform the role of a process management risk advisor and leverage subject matter knowledge and critical thinking to drive value during assessments to ultimately improve our processes and reduce risk for Enterprise Services lines of business
- Research novel trends in an ever-changing regulatory environment, as well as internal process changes, to improve existing risks and identify emerging risks
- Lead stakeholders in applying risk management principles in accordance with Enterprise frameworks
- Research new and emerging areas of risk and the dynamic regulatory environment to understand impacts on process areas
- Lead and support project and program delivery, execute deliverables in fast paced environment, and work across multiple work streams
- Prioritize simultaneous projects and assessments, manage timelines independently, keep key stakeholders informed, and recognize when to upscale appropriately
- Participate in risk and other management forums and contribute to continuous improvement of risk and project / program management practices
- Deliver assessment outcomes to senior leadership with strong communication skills and ability to influence stakeholders
- Lead initiatives to drive efficiency and process improvements within and across teams
- High School Diploma, GED or equivalent certification
- At least 5 years of experience in process management, technology risk management, or project management
- At least 5 years of experience supporting, partnering, and interacting with internal or external business clients
- At least 1 year of experience analyzing information security or technology threats and risks
- Bachelor's Degree or military experience
- At least 1 year of Financial Services industry experience
- Experience with regulatory practices (governance, risk, compliance, and information and network security), AWS cloud, machine learning and artificial intelligence data management, third party and contingent workforce, and incident response.
- Process development, documentation, or improvement experience
- Experience in controls development, controls management, and reporting activities
- Holds one or more certifications in: any security, technology, or risk certifications (e.g., CompTIA Security+, CompTIA Tech+, Systems Security Certified Practitioner (SSCP), ISACA Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), technology vendor certifications (e.g., AWS, Microsoft, Google))
- Ability to communicate and influence clearly and to interact effectively at…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).