Director, Cyber Risk and Analysis
$226k - $257.9kCapital One National Association
Director, Cyber Risk and Analysis Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, and managing technology risk. For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Technology Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and other technology risks. The CTRO is independent, reports to the Chief Risk Officer, and oversees the work of the CISO and the CIO. Technology Risk Management (TRM) is a small organization that packs a big punch. The ~100 professionals in TRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk. As a Director, Cyber Risk and Analysis, you will apply expertise on risk frameworks and best practices to assess current state, identify methodology gaps, and evaluate threats and/or business impact to enable advisory partnerships and effective oversight of tech and cyber risk across Capital One. You will lead risk aggregation initiatives, define mitigation strategies, prioritize and escalate recommendations to senior leadership. You will also participate in the design, socialization and implementation of risk management products and programs through your deep knowledge of risk assessments, information risk controls, regulatory and internal governance standards, data analysis, metrics / reporting, and customer engagement. Responsibilities: Maintains a broad, expert understanding of technology risk frameworks, has innate ability to leverage these frameworks in risk identification processes. Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting risk management policies or programs; recommends sound, practical solutions to complex issues. Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise. Advises Accountable Executives of tech and cyber-related risk on a consistent basis via relevant risk forums and through existing processes such as exception and issue management. Exhibits strong critical thinking and communication skills, with proven ability to navigate the unknown to devise and socialize innovative risk management solutions. Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change. Understands associated reporting metrics and is able to inform on tech and cyber risks. Quickly and accurately analyzes data, assesses risk, & prioritizes potential risks to differentiate critical, high-risk, and low-risk issues, and remediates and escalates as appropriate. Makes recommendations regarding changes to first line policy, procedures, and control programs to mitigate evolving risks. Effectively self-challenges tech and cyber control and risk management programs as part of first line duties and escalates risks where appropriate. Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement. Basic Qualifications: Bachelor's Degree or military experience At least 5 years of experience with Technology Risk Management or Cyber Security Risk Management At least 5 years of experience building risk control environments or risk frameworks At least 5 years of experience in People Management Preferred Qualifications: Master’s Degree Process or Project Management certification (i.e. Lean, Six Sigma, PMP), Business Management certification 10+ years of experience with Technology or Cyber Security Risk Management 9+ years of experience in People Management At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $226,000 - $257,900 for Director, Cyber Risk & Analysis New York, NY: $246,500 - $281,300 for Director, Cyber Risk & Analysis Plano, TX: $205,400 - $234,400 for Director, Cyber Risk & Analysis Richmond, VA: $205,400 - $234,400 for Director, Cyber Risk & Analysis Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days. No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries. #J-18808-Ljbffr Capital One National Association
$126k - $255k
...The Role The Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Director-level risk professional to lead in the creation of... ...with proven ability to integrate data into risk analysis tools and communicate progress effectively across...CyberWork from home- ...York is seeking a Manager for Generative AI Advisory and Oversight. The role demands a subject matter expert in AI/ML risk analysis, collaborating with Cyber and Technology teams. Responsibilities include evaluating AI architectures, providing risk guidance, and mentoring...Cyber
- ...Technology Operational Risk Officer Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at... ...and AI-enabled development to identify and assess technology and cyber operational risk in the Wealth Management line of business. You...Cyber
- ...Head Of Enterprise Risk Management The Head of Enterprise Risk Management (ERM) is... ...capital management, operational risk, IT/Cyber, compliance, legal, internal audit, and business... ...), early‑warning mechanisms, scenario analysis, stress testing, and emerging risk...Cyber
$105k - $115k
Morgan Stanley Investment Management Global Risk & Analysis Morgan Stanley Investment Management (... ...position will report into an Executive Director of Risk and will interface with... ..., internal audit, regulatory projects, cyber & information security or technology integration...CyberTemporary workWorldwide$132.42k - $217.55k
...As the Head of Risk & Resiliency, you will execute the Risk & Resiliency frameworks for... ...aggregating risk across domains (Technology, Cyber, Data, Model, Compliance, Third Party,... ...Indicators(KRIs), and stress scenario analysis, ensuring appropriate linkage, escalation...CyberFull timeWork at officeRemote workWork from homeVisa sponsorshipWork visaFlexible hours$85.77k - $153.09k
...internal use): 11 The Role: Manager, Insurance Risk Management The Team: The Risk Management... ...of S&P Global's Casualty, Property, E&O, Cyber, D&O, Fiduciary and Crime coverages.... ..., status updates to insurers and analysis of coverage position letters. Compensation...CyberContract workSecond jobLive inWork at officeWorldwideFlexible hours2 days per week- ...investigations, improving efficiency through automation, and authoring detailed technical reports. Candidates should have strong skills in network traffic analysis and relevant cybersecurity tools, along with a desire to adapt in a rapidly changing field. #J-18808-Ljbffr...CyberRemote work
- ...Gartner is seeking a Director, Analyst to provide expert insights into infrastructure cybersecurity technologies. The successful candidate... ...remote position emphasizes a keen understanding of evolving cyber threats and security frameworks, contributing significantly to...CyberRemote work
- ...Cyber Security - IAM Professional Services Location: Dallas, TX / Tampa, FL / Jersey... ...requirements. Monitored changes in the risk profile of the highly critical systems.... ...investigation of incidents and Root Cause Analysis. Assisted the developer and infrastructure...CyberContract work
- ...West Coast. This remote role involves triaging and investigating cyber threats, mentoring junior analysts, and developing detection... ...incident response experience and a strong background in malware analysis, threat actor techniques, and cloud attack methodologies. Competitive...CyberRemote work
- ...Gilder Search Group is seeking a Senior Cyber Security Ops Analyst for a remote, 6+ month contract. The analyst will conduct investigations... ...will also have expertise with automation scripting and threat analysis, and willingness to provide off-hour support as needed. #J-1880...CyberContract workRemote work
- .... In this fully remote role, you will lead investigations into cyber incidents, work alongside a passionate team, and mentor junior... ...cybersecurity, with expertise in incident response and malware analysis. This position offers a competitive salary and various benefits...CyberRemote work
- ...in Digital Forensics and Incident Response to provide expert guidance during cyber incidents. This remote role requires a seasoned professional with a strong background in forensic analysis and incident management. Key responsibilities include leading investigations,...CyberRemote work
- ...would have real-world experience responding to externally driven cyber incidents, as well as investigating potential insider threat... ...mixed Linux/Windows environment is a plus Has used forensic analysis to investigate potential breaches with supporting detail to determine...CyberFlexible hours
$40 per hour
A cybersecurity innovations company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. Candidates should have at least 2 years of hands-on cybersecurity experience and be fluent in English. This offers...CyberHourly payRemote workFlexible hours- A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls, ...CyberRemote work
- ...Threat Detection and Vulnerability Assessments Implementing Deception Technology (Honeypot/Honeynets) Data Analysis DWDM and SONET Nozomi maintenance and management TDI administration and management Gigamon maintenance...Cyber
- ...Alignerr is seeking a Vulnerability Management Analyst to evaluate and improve AI systems regarding real-world cyber risks. You will analyze vulnerability reports, classify severity, and generate data to train AI models that understand cybersecurity tradeoffs. The ideal...CyberRemote work
$80 - $105 per hour
...leverages artificial intelligence to detect, prevent, and respond to cyber threats in real-time. Please include a cover letter with... ...and Functional Skills Skilled in anomaly detection and pattern analysis. Experience with real-time monitoring platforms. Knowledge of automated...CyberHourly pay- ...Remote Jobs is looking for Security Specialists who are knowledgeable in risk management, HIPAA, and NIST privacy and security requirements for health information networks. The role involves being comfortable leading internal risk assessments and developing risk management...CyberRemote work
- ...best practices. • User behavior monitoring. • Data analysis of Network, Cloud, and Endpoint data. • Centralized management... ...recommend security infrastructure from scratch and raise security risks in a timely manner. • Develop security requirements for...CyberWork experience placement
$103.24k - $133.2k
...special agents in New York City. In this role, you will leverage analytical and data analysis skills to conduct investigations into federal law violations, ensuring national security against cyber threats and terrorism. A bachelor's degree in a relevant field is required,...CyberWork at office$15 - $20 per hour
...Col of Engineering Req ID: 8836 Overview The position of Student Cyber Security Operations Center (SOC) Support within the McCrary... ...accurate and detailed documentation related to security event analysis, actions taken, and resolutions for each event Other duties as...CyberWork at office- ...A dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role involves leading client engagements to implement cybersecurity programs and managing daily compliance operations. Ideal candidates will...Cyber
$110k - $230k
...information security assessments, vulnerability analysis, and implementing controls to address... ...Conduct periodic information security/Cyber Security assessments (e.g., information security... ...s degree required in Computer Science or Risk Management Minimum 6 years of...Cyber- ...JOB SUMMARY Cyber Metrics Reporting JOB DESCRIPTION We are seeking a highly... ...with different departments, including IT, Risk Management, and Compliance, to collect... ...Have ~5+ years of experience in data analysis ~ Able to work independently and have good...Cyber
- ...dedicated to keeping the firm safe. Our work covers a wide range of topics, from software engineering and DevOps to risk analysis, security governance, and cyber awareness. About You Offensive security background Can help build and implement secure solutions...Cyber
- ...Title: Sr. Cyber Security & Threat Analyst Location: New Hyde Park, NY (Hybrid Onsite) Duration: 12+ months contract... ...HOT BUTTONS: Working experience in Cyber Threat & Attack Analysis / DevOps/Engineering /Coding exp Scripting: Python/Bash/PowerShell...CyberContract workWork experience placement
- ...Cyber Threat Intelligence Hiring for 'Cyber Threat Intelligence' role: The Identify Service Line is responsible for identifying, assessing... ...in open source intelligence investigations and malware analysis. In-depth knowledge of security tools such as SIEM, IDS/IPS, web...CyberFull timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Risk and Analysis. Be the first to apply!
- enterprise risk manager New York, NY
- risk management specialist New York, NY
- risk management associate New York, NY
- group risk manager New York, NY
- director credit risk New York, NY
- risk management manager New York, NY
- head of risk management New York, NY
- senior risk manager New York, NY
- operational risk manager New York, NY
- director of risk management New York, NY

