This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Capital One, the AIML Division is working to bring the transformative power of emerging AI capabilities, to reimagine how we serve our customers and businesses. We are looking for an experienced Sr. Manager ISO to support the AIML Division objective to Accelerate AI Innovation and build and maintain Enterprise-grade Agentic Capabilities. As an Expert Cybersecurity ISO, you will have a deep understanding of AI ML Security Risks, possess a strong background in application security engineering, and be eager to take on challenges related to AI-driven cybersecurity threats. We are looking for individuals who are adept in both traditional security approaches and the unique challenges posed by AI and ML technologies.
Job Responsibility
Lead the development of secure, enterprise grade AI/ML and agentic AI solutions
Establish Ai-First SDLC practices and build scalable platforms
Design and implement security controls for AI/ML systems, including LLM applications
Conduct threat modeling, risk assessments and security reviews using frameworks such as NIST AI RMF, OWASP, and MITRE ATLAS
Define and enforce AI Model guardrails, safety standards, and governance policies
Identify and mitigate risk in open -source AI ML models
Build and scale processes for AI security testing, monitoring and stress validation
Partner with engineering, research, and security teams to deliver secure and compliant AI solutions
Advise senior leadership on AI cybersecurity risks, strategy, and regulatory considerations
Drive continuous improvement through vulnerability assessments, risk remediation, and security innovation
Requirements
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years in securing a public cloud environment
At least 3 years of experience with API security, observability, cloud access control and privacy best practices
Nice to have
Bachelor's Degree
7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
6+ years of cyber security advisory and technology consulting experience
5+ years of experience performing security cybersecurity assessments for enterprise AI and ML platforms
5+ years of experience with industry security frameworks such as NIST AI RMF, OWAPS, MITRE ATLAS, ISO 27001, PCI DSS and GDPR
Knowledge of networking protocols such as HTTP, DNS and TCP/IP
Knowledge of Agentic AI systems, workflows, MCP and A2A
Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
What we offer
performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
comprehensive, competitive, and inclusive set of health, financial and other benefits