Director, Cyber Risk and Analysis
$226k - $257.9kCapital One National Association
Director, Cyber Risk and Analysis Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, and managing technology risk. For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO. Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk. As a Director, Cyber Risk and Analysis, you will apply expertise on risk frameworks and best practices to assess current state, identify methodology gaps, and evaluate threats and/or business impact to enable advisory partnerships and effective oversight of tech and cyber risk across Capital One. You will lead risk aggregation initiatives, define mitigation strategies, prioritize and escalate recommendations to senior leadership. You will also participate in the design, socialization and implementation of risk management products and programs through your deep knowledge of risk assessments, information risk controls, regulatory and internal governance standards, data analysis, metrics / reporting, and customer engagement. Responsibilities: Maintains a broad, expert understanding of technology risk frameworks, has innate ability to leverage these frameworks in risk identification processes. Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting risk management policies or programs; recommends sound, practical solutions to complex issues. Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise. Advises Accountable Executives of tech and cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management. Exhibits strong critical thinking and communication skills, with proven ability to navigate the unknown to devise and socialize innovative risk management solutions. Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change. Understands associated reporting metrics and is able to inform on tech and cyber risks. Quickly and accurately analyzes data, assesses risk, & prioritizes potential risks to differentiate critical, high-risk, and low-risk issues, and remediates and escalates as appropriate. Makes recommendations regarding changes to first line policy, procedures, and control programs to mitigate evolving risks. Effectively self-challenges tech and cyber control and risk management programs as part of first line duties and escalates risks where appropriate. Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement. Basic Qualifications: Bachelor's Degree or military experience At least 5 years of experience with Technology Risk Management or Cyber Security Risk Management At least 5 years of experience building risk control environments or risk frameworks At least 5 years of experience in People Management Preferred Qualifications: Master’s Degree Process or Project Management certification (i.e. Lean, Six Sigma, PMP), Business Management certification 10+ years of experience with Technology or Cyber Security Risk Management 9+ years of experience in People Management At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis New York, NY: $246,500 - $281,300 for Director, Cyber Risk & Analysis Plano, TX: $205,400 - $234,400 for Director, Cyber Risk & Analysis Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries. #J-18808-Ljbffr
$126k - $255k
...The Role The Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Director-level risk professional to lead in the creation of... ...with proven ability to integrate data into risk analysis tools and communicate progress effectively across...CyberWork from home- ...York is seeking a Manager for Generative AI Advisory and Oversight. The role demands a subject matter expert in AI/ML risk analysis, collaborating with Cyber and Technology teams. Responsibilities include evaluating AI architectures, providing risk guidance, and mentoring...Cyber
$229.9k - $262.4k
...Sr. Risk Manager, Data Protection This position represents a... ...ability to use technical skills and cyber subject matter expertise to... ...to deliver high-impact analysis and recommendations that are rooted... ...regulatory agencies and the Board of Directors, as needed. Stay current on...CyberFull timePart timeLocal areaImmediate start- ...interactions, and teamwork. Within Enterprise Risk, you can expect to draw from your... ...governance, data quality, data lineage, cyber threats, evolving privacy regulations, and... ...data governance, and technology risks. Risk Analysis and Monitoring: Analyze current and emerging...CyberFull timePart timeWork at officeFlexible hours
$122.6k - $263.7k
...Opportunity: Lead Adobe's Security Risk and Governance program by advancing the security... ...through qualitative and quantitative analysis. Improve decision-making using security insights... ...from Security Architecture, Adobe CCF, Cyber Operations, and Product Security. *...CyberTemporary workLocal areaWorldwide$200.7k - $229.1k
...Senior Manager, Risk Advisor, Technology and Data Risk Management Capital One is one of the fastest growing organizations... ...deliver high-impact results. This position – Senior Manager, Cyber Risk and Analysis – will play a key role in shaping the second line’s...CyberFull timePart timeLocal area- ...Head Of Enterprise Risk Management The Head of Enterprise Risk Management (ERM) is... ...capital management, operational risk, IT/Cyber, compliance, legal, internal audit, and business... ...), early‑warning mechanisms, scenario analysis, stress testing, and emerging risk...Cyber
$266k - $295k
...Head of Insurance and Risk Management Finance - San Francisco, New York City, and... ...program covering key lines, including cyber, directors and officers (D&O), errors and omissions... ...insurance structures, including feasibility analysis, domicile and governance considerations...CyberWork at officeRelocation package$190k - $230k
...Officer. Chart Your Course: Performs analysis on profitability at a product and account... ..., travel assistance, identity and cyber protection, and beneficiary companion products... ...medical cost containment and medical risk management solutions. Learn more here ....CyberTemporary workInternshipWork at officeLocal areaWork from homeMonday to Friday2 days per week3 days per week$150k - $170k
Quantitative Enterprise Risk Manager page is loaded Quantitative Enterprise Risk Manager... ..., the role supports enterprise-wide risk analysis, including reinsurance structures,... ...Lines, Political Risk & Credit, Surety and Cyber. Perform ongoing capital adequacy analysis...CyberFull timeWork experience placementLocal areaRemote work$85.77k - $153.09k
...internal use): 11 The Role: Manager, Insurance Risk Management The Team: The Risk Management... ...of S&P Global's Casualty, Property, E&O, Cyber, D&O, Fiduciary and Crime coverages.... ...reporting, status updates to insurers and analysis of coverage position letters....CyberContract workSecond jobLive inWork at officeWorldwideFlexible hours2 days per week$105k - $115k
Morgan Stanley Investment Management Global Risk & Analysis Morgan Stanley Investment Management (... ...position will report into an Executive Director of Risk and will interface with... ..., internal audit, regulatory projects, cyber & information security or technology integration...CyberTemporary workWorldwide- ...Role Description If you are a senior risk executive who thrives on strategic judgment... ...risk, operational risk, model risk, cyber risk, governance, controls, regulatory expectations... ...remediation, model governance, scenario analysis, internal controls, and executive risk...CyberFor contractorsRemote work
$85.77k - $153.09k
...internal use): 11 The Role: Manager, Insurance Risk Management The Team: The Risk Management... ...of S&P Global's Casualty, Property, E&O, Cyber, D&O, Fiduciary and Crime coverages.... ..., status updates to insurers and analysis of coverage position letters. Compensation...CyberContract workSecond jobLive inWork at officeWorldwideFlexible hours2 days per week$130k - $180k
...Risk Manager - Engineering - CRO Location New York Business Area Legal, Compliance, and... ...Engineering stakeholders to conduct an in-depth analysis of key processes, which may include... ...compliance related to technology risk or cyber security Good understanding of all...CyberTemporary workFor contractorsWork experience placementWork at office$132.42k - $217.55k
...As the Head of Risk & Resiliency, you will execute the Risk & Resiliency frameworks for... ...aggregating risk across domains (Technology, Cyber, Data, Model, Compliance, Third Party,... ...Indicators(KRIs), and stress scenario analysis, ensuring appropriate linkage, escalation...CyberFull timeWork at officeWork from homeVisa sponsorshipWork visaFlexible hours- ...Director Investments Risk This role involves working closely with the risk management team to analyze and manage investment risks across various... ...full-time commitment. Responsibilities include portfolio analysis, risk reporting, and operational due diligence using...Full timeWork at office
- ...Gartner is seeking a Director, Analyst to provide expert insights into infrastructure cybersecurity technologies. The successful candidate... ...remote position emphasizes a keen understanding of evolving cyber threats and security frameworks, contributing significantly to...CyberRemote work
$111k
...National Grid plc is seeking a CSIRT Analyst to join its Cyber Security Incident Response team. This role involves monitoring security alerts, investigating threats, and supporting the incident response lifecycle in a fast-paced hybrid environment. Ideal candidates should...Cyber- ...Richemont is seeking a Senior Associate in Cyber Incident Response to protect against cyber threats and analyze security events in New York. The role involves incident management, detailed analysis of cybersecurity threats, and collaboration with IT and security teams...Cyber
- ...Cyber Security - IAM Professional Services Location: Dallas, TX / Tampa, FL / Jersey... ...requirements. Monitored changes in the risk profile of the highly critical systems.... ...investigation of incidents and Root Cause Analysis. Assisted the developer and infrastructure...CyberContract work
- ...West Coast. This remote role involves triaging and investigating cyber threats, mentoring junior analysts, and developing detection... ...incident response experience and a strong background in malware analysis, threat actor techniques, and cloud attack methodologies. Competitive...CyberRemote work
$120k - $198k
...difference at Fiserv. Job Title Senior Manager, Risk Product and Flows About your role: As a... ...metrics, experimentation, and data analysis to prioritize enhancements and measure product... .... Fraudulent job postings may be used by cyber criminals to target your personally...CyberFull timeTemporary workH1bWork at officeMonday to Friday- ...A health services company is looking for a Senior Cyber Incident Responder to lead investigations within the Cyber Fusion Center. The role requires expertise in malware analysis and incident handling, with responsibilities including providing support to cyber defense technicians...CyberRemote work
- .... In this fully remote role, you will lead investigations into cyber incidents, work alongside a passionate team, and mentor junior... ...cybersecurity, with expertise in incident response and malware analysis. This position offers a competitive salary and various benefits...CyberRemote work
$293.6k - $335.1k
...A major financial services company seeks a Director for Special Oversight Projects in New York. This high-impact role requires at least 10 years in cybersecurity and the ability to navigate complex risk management challenges. You will be involved in strategic oversight...Cyber- ...Gilder Search Group is seeking a Senior Cyber Security Ops Analyst for a remote, 6+ month contract. The analyst will conduct investigations... ...will also have expertise with automation scripting and threat analysis, and willingness to provide off-hour support as needed. #J-1880...CyberContract workRemote work
- ...leading IT services provider in New York is seeking a highly skilled Cyber Security Analyst to join their Security Operations Center team.... ...The ideal candidate will have significant expertise in malware analysis, threat detection, and incident response, alongside a robust...Cyber
- ...would have real-world experience responding to externally driven cyber incidents, as well as investigating potential insider threat... ...mixed Linux/Windows environment is a plus Has used forensic analysis to investigate potential breaches with supporting detail to determine...CyberFlexible hours
- A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls, ...CyberRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Risk and Analysis. Be the first to apply!
- senior risk manager New York, NY
- security risk manager New York, NY
- risk management associate New York, NY
- director credit risk New York, NY
- risk management specialist New York, NY
- enterprise risk manager New York, NY
- head of risk management New York, NY
- operational risk manager New York, NY
- group risk manager New York, NY
- risk management manager New York, NY


