Role Overview
The Senior Risk Analyst within the Tech, Cyber, Data, and Resiliency (TCDR) team plays a critical role in utilizing analytical expertise to identify, measure, and manage intricate TCDR risks. This position champions innovation while fostering collaboration across Technology, Business, and Second Line teams to effectively mitigate risks.
As a Dedicated Tech Risk Partner (DTRP), you will build trusted relationships with key technology stakeholders. Your proactive risk management approach involves working closely with engineering teams to develop compliant solutions, while also reporting to executive leadership.
Your contributions will be vital in driving organizational change through robust identification, comprehensive analysis, and detailed reporting of TCDR risks. You will act as a subject matter expert, focusing on enhancing Tech Risk Metrics in Technology, Compliance, Stability, and Resiliency, ensuring a strong control environment aligned with data risk frameworks and regulatory governance. Additionally, you will support the execution and ongoing enhancement of the Risk and Control Self-Assessment (RCSA) program and diligently track critical incidents to derive lessons learned and preventative actions.
Key Responsibilities
- Act as the primary Tech Risk Partner for engineering and technology teams, delivering exceptional risk management support and resources promptly.
- Collaborate with technical teams to achieve compliance, prepare audit responses, and minimize regulatory risks.
- Address TCDR governance queries and integrate compliance checks into service intake processes to avoid future risks.
- Engage in Material Tech Change (MTC) reviews to identify potential risk scenarios and ensure appropriate controls are implemented.
- Facilitate cross-functional risk workshops to identify inherent risks and assess control effectiveness, documenting insights and conclusions.
- Conduct control analyses to identify any design gaps or outdated controls, working with business leaders to ensure effective control coverage.
- Create high-quality executive reports summarizing technology risks from the RCSA process.
- Build collaborative partnerships with stakeholders in Second Line and Third-Party Risk Management for effective risk alignment.
- Oversee the progress of remediation activities, ensuring timely resolution of control actions and outstanding issues.
- Manage RCSA materials, maintaining up-to-date spreadsheets and summary documents.
Subject Matter Expertise
Develop and maintain a comprehensive metrics spreadsheet covering Compliance, Resiliency, Release Management, and Stability.Establish a daily reporting process for non-compliant metrics and engage with engineers and business partners.Contribute to the monthly executive deck by detailing non-compliance drivers and proposing compliance pathways.Prepare quarterly reports on non-compliant metrics for executive governance forums.Investigate critical incidents immediately, documenting root causes, resolutions, and lessons learned to minimize future occurrences.Integrate trend data from technology incidents back into the RCSA program for continuous improvement.Basic Qualifications
Minimum of 3 years of experience in Cyber & Tech Risk Analysis.Minimum of 3 years of experience in Risk Management, Compliance, Audit, or Control Testing.Preferred Qualifications
4+ years in a dedicated role focused on Technology Risk, Cyber Risk, or Business Continuity.2+ years of consulting experience with strong client and stakeholder relationships.Exceptional written and verbal communication skills, capable of presenting complex risk topics to executives.Relevant professional certification (e.g., CRISC, CISA, or other risk / audit certifications).Please note, this position will not sponsor employment authorization. The minimum and maximum full-time annual salaries for this role are $127,500 - $145,500, and are based in McLean, VA.
Capital One is an equal opportunity employer, committed to non-discrimination.