Center 2 (19050), United States of America, McLean, Virginia
Information Security Office, Director
Cyber is essential to Capital One success and culture as we seek to safeguard and enable our customers and associates. As part of the Information Security Office team for a line of business, you are passionate about security and risk management. You see security as an enabler and differentiator to enable the business through innovation, not a step in the compliance process. You work with the business and technology partners to achieve goals and objectives in a secure manner with a heavy forward lean on modern data and technology architectures.
At Capital One, you will help advise on strategic initiatives, programs, and projects to create business value in a risk-based and agile manner. You are pragmatic and practical in your understanding of security and associated risks, but also willing to know when to pull in experts and escalate. You will lead a team of dynamic and talented Information Security professionals who want to learn from your experience and skills. You are an advocate in the value of data driven business decisions and products, as well as comfortable with big data and cloud based technologies and tools, proactive protective methods, and concepts like Apache Kafka, APIs, tokenization, encryption, virtualization and containerization, machine learning/artificial intelligence and data analysis/modeling.
Execute Information Security advisory services for an enterprise wide multi-year machine learning strategy within cloud based environments
Lead a team of Information Security Consultants to provide subject matter expertise to both business and development teams
Educate and influence executive leadership and associates to effectively leverage security capabilities and solutions to mitigate risks and emerging threats
Escalate and manage cyber security risk as the primary point of contact for a line of business area
Serve as an expert and thought leader in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Lean in as a change agent to shift security risk identification and solutions left in enterprise processes, through coordination and execution of proactive Information Security consulting practices
Drive innovation activity as an outcome; partner extensively with other Cyber organizations such as Security Engineering, to derive both novel and patent activity as outcomes
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
Deliver Cyber agenda and integration of Information Security within business objectives for line of business area
Provide ad hoc support on special Information Security hot topics for the business
In addition to the qualifications listed below, ideal candidates should also have: Experience with secure SaaS service delivering and SOC assessment, machine learning deployment and execution, data protection techniques and tools such as encryption, tokenization, container security, cloud access security brokers. Experience in a regulated environment, specifically financial services industry experience is a plus.
You have a desire to work in a very fast moving, forward leaning, modern computing environment
You have a deep passion for securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including business executives, technology leaders, and enterprise suppliers
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
You have the ability to describe the risks of a security exposure or vulnerability in business-impact terms
At least 7 years of experience in Information Security
At least 5 years of people leadership experience
10+ years of combined experience with Data and Security Architecture, Data Security, and Machine Learning.
8+ years of experience performing security risk assessments
5+ years of experience leading teams of information security professionals
5+ years experience with threat modeling
2+ years experience in securing a public cloud environments and services (AWS, GCP, Azure)
2+ years experience utilizing Agile methodologies
Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Solutions Architect
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.