Senior Lead, Cyber Security (GPN) at Capital One | Mclean, VA, US | Rezi

Senior Lead, Cyber Security (GPN) at Capital One

Senior Lead, Cyber Security (GPN)

Capital One · Mclean, VA, US

Today

Senior Lead, Cyber Security (GPN)

Capital One · Mclean, VA, US

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior Lead, Cyber Security (GPN) role.

Rezi rewrites your resume against Capital One's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior Lead, Cyber Security (GPN) posting at Capital One — free, in seconds.

About the Role

At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.

Responsibilities

  • Lead, mentor, and develop associates by setting clear expectations, providing actionable feedback, and supporting career progression
  • Serve as a cybersecurity subject matter expert and advise on best practices in risk reduction through the configuration of cybersecurity tools and platforms
  • Support the development, modification, and use of capability, risk, and/or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations
  • Support the development, implementation, and execution of continuous improvement programs, including risk and issue identification, corrective action implementation, and results validation
  • Support the identification and operationalization of cross-programmatic linkages among threats, risks, controls, capabilities, tooling, and data analytics to facilitate initiative prioritization and decisioning on spending and resource allocation
  • Lead solutioning for, and manage activities in response to, large-scale enterprise risk reduction efforts
  • Effectively communicate the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures
  • Lead cross-domain cybersecurity risk assessments and capability reviews, ensuring alignment between enterprise control standards, business objectives, and regulator expectations
  • Influence and coordinate risk reduction initiatives across multiple cyber programs, driving consistency in control design, testing and reporting practices

Requirements

  • Bachelor's degree
  • At least 7 years of experience in cybersecurity or information technology
  • At least 6 years of experience evaluating, contributing to, or supporting development of cybersecurity capabilities
  • 7+ years of experience with cybersecurity frameworks and concepts such as NIST CSF, MITRE ATT&CK, CMMC, FedRAMP, etc.
  • 7+ years of experience performing analysis of or developing solutions for cyber threats, vulnerabilities, risks, or, events
  • 7+ years of experience working on teams and presenting to stakeholders cybersecurity information such as metrics, threat intelligence, controls and/or requirements
  • 6+ years of experience working in multi-cloud environments
  • 6+ years of experience using security tools (e.g., Splunk, Crowdstrike, Qualys, or AWS Security Hub)
  • 3+ years of experience developing or interpreting cybersecurity metrics or dashboards
  • 2+ years of experience developing or overseeing cybersecurity or technology risk programs
  • Demonstrated familiarity with industry governance or financial governance processes
  • Advanced experience with risk management concepts, including identifying threats, assessing vulnerabilities, and recommending mitigation strategies
  • Ability to perform security incident analysis and assist with resolution, translating technical findings into clear, actionable reports for technical and non-technical stakeholders

Skills

  • Cloud Service technologies
  • Storage Services
  • Security & Access Control Management
  • Container Services
  • API Implementation and Management
  • IaaS
  • PaaS
  • SaaS
  • NIST CSF
  • MITRE ATT&CK
  • CMMC
  • FedRAMP
  • Splunk
  • Crowdstrike
  • Qualys
  • AWS Security Hub
  • Risk management concepts
  • Security incident analysis

Location

  • McLean, VA
  • New York, NY
  • Plano, TX
  • Richmond, VA

Work Type

  • Full-time

Experience Level

  • Senior
  • 7+ years of experience in cybersecurity or information technology
  • 6+ years of experience evaluating, contributing to, or supporting development of cybersecurity capabilities
  • 7+ years of experience with cybersecurity frameworks and concepts
  • 7+ years of experience performing analysis of or developing solutions for cyber threats, vulnerabilities, risks, or, events
  • 7+ years of experience working on teams and presenting to stakeholders cybersecurity information
  • 6+ years of experience working in multi-cloud environments
  • 6+ years of experience using security tools
  • 3+ years of experience developing or interpreting cybersecurity metrics or dashboards
  • 2+ years of experience developing or overseeing cybersecurity or technology risk programs

Education Level

  • Bachelor's degree

Salary/Compensations

  • McLean, VA: $229,900 - $262,400
  • New York, NY: $250,800 - $286,200
  • Plano, TX: $209,000 - $238,500
  • Richmond, VA: $209,000 - $238,500

Benefits

  • Comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being.
  • Performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI).

About the Company

  • At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security.
  • Security is essential to what we do here, from protecting our customers to our associates.
  • Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being.
  • Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws.
  • Capital One promotes a drug-free workplace.
  • Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries.
  • Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Equal Opportunity

  • Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws.
  • Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.