This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Principal Associate of Tech & Cyber Risk within Capital One's Business Risk Office, you will drive end-to-end risk management by partnering directly with technology stakeholders and engineering teams to identify, assess, and mitigate technology and cyber risks.
Job Responsibility
Drive end-to-end technology and cyber risk assessments, managing the lifecycle from tactical implementation and ongoing evaluation through to remediation tracking and successful risk finding closure
Support the responsible implementation of AI applications and large-scale architecture transformations by conducting timely risk assessments and ensuring project teams align with enterprise risk frameworks
Utilize strong project management skills to effectively prioritize risk initiatives, ensuring clear project scope and the timely delivery of impactful results
Exhibit outstanding communication skills to build and manage strong stakeholder relationships across engineering and risk functions, keeping all levels informed and influencing outcomes to drive project success
Display strong advisory skills to guide engineering partners through complex risk landscapes, adapting with agility to changing business demands and evolving technology environments
Drive continuous improvement within the Tech & Cyber Risk Office by identifying, designing, and implementing enhancements to streamline risk identification, assessment, and mitigation workflows
Monitor and analyze key risk metrics and dashboards, partnering closely with stakeholders to oversee remediation efforts and drive metrics toward target compliance levels
Assist in preparing accurate compliance documentation and data for audit engagements, ensuring the overall tech risk posture is transparent and well-documented
Requirements
3+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, or Technology Consulting
Nice to have
Certified Information Systems Auditor (CISA)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Security Manager (CISM)
Certified Information Systems Security Professional (CISSP)
Certified AI Governance Professional (AIGP)
Experience working within a Large Financial Services institution, highly regulated environment, or technology consulting organization
What we offer
Performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
comprehensive, competitive, and inclusive set of health, financial and other benefits