Talent.com
Director, Cyber and Tech Risk Execution

Director, Cyber and Tech Risk Execution

NYC StaffingNew York, NY, US
4 hours ago
Job type
  • Full-time
Job description

Director, Cyber And Tech Risk Execution

Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute : Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, software quality, and data management. Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 professionals in TDRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk, and data management risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.

For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is : both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Tech & Data Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and the risk of failing to manage our data. The CTRO is independent and oversees the work of the CISO, the CIO / CTO, and the Chief Data Officer. Our business leaders must make technology decisions constantly. TDRM makes sure they have the tech and data risk information they need to make good decisions. Associates within TDRM are highly skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.

Role Summary

As a Director of Cyber and Tech Risk Execution, you will play a fundamental role in supporting and guiding the first line with the practical application of our Risk Levelling Program. The program has been created to ensure Tech and Cyber risks are consistently defined and measured, leading to meaningful data that drives action to mitigate risk across the entire organization. You will be a risk expert who has proven abilities to influence across all layers of the organization, known for your ability to get things done in the right way and at the required pace. Your ability to flex your approach and provide innovative solutions to complex problems will be a key part of the role. Alongside this, you will be guiding and mentoring our Senior Risk Managers within the RAPID team, demonstrating model behavior covering risk expertise, and multi-faceted stakeholder influence, whilst delivering against Enterprise-wide targeted deadlines. In addition to leading the core program you will have responsibilities to execute risk framework activities across multiple divisions, providing counsel on risk assessment and treatment options. You will have a strong knowledge of technology / cyber risk, industry, and regulatory trends, paired with strategic thinking, and possess an intellectually curious nature, with an ability to thrive in undefined problem spaces.

Responsibilities

  • Influence executives across the Lines of Business to take accountability for complex (and sometimes sensitive) technology and cyber risks
  • Execute the Risk Leveling program across centralized and decentralized divisions
  • Leverage leadership experience and executive influencing skills to continuously improve our risk maturity journey
  • Constructively debate issues and connect the dots across various assessments (typically includes risk and control self-assessments, critical business process-level assessments, assessments of new initiatives, scenario analysis, challenge of risk acceptances, etc.)
  • Identify opportunities to influence risk-taking strategies
  • Demonstrate robust risk management oversight in supporting various internal audits and regulatory exams
  • Mentor and develop associates to meet their professional development goals
  • Maintain a broad, expert understanding of technology risk frameworks, with an innate ability to leverage this understanding for the purposes or risk identification and mitigation
  • Effectively communicates and demonstrates subject matter expertise in risk categorization, how risks can occur in a new environment, and the measures required to safeguard the enterprise
  • Exhibits strong critical thinking and communication skills, with proven ability to navigate the unknown
  • Leverages reporting & tools to perform analysis on different types of data points to inform policies and drive change; understands associated reporting metrics and is able to inform on tech and cyber risks
  • Demonstrates sound lifecycle program management to include socializing action plans, impediments and risks, and stakeholder training / engagement

A Successful Candidate Will Have

  • Superb communication skills that include active listening and executive presentation skills
  • Proven critical analytical behavior, including and the ability to express a point of view supported by data (with both technical and non-technical audiences)
  • Expertise in technology and cybersecurity domains, with an ability to identify risks and to propose multiple options to manage to an acceptable level
  • Excellent influencing skills across all levels of the organization, tailoring the style and content to meet the needs of the audience
  • The ability to understand the materiality of feedback from stakeholders, knowing when to act and when to listen, including driving discussions to find resolution where required.
  • A track record of providing strategic direction to teams, peers, and stakeholders to drive results, solve problems, and influence outcomes
  • Basic Qualifications

  • Bachelor's Degree AND at least 7 years of experience in information security, information technology or risk management OR High School Diploma, GED or equivalent certification AND at least 9 years of experience in information security, information technology or risk management
  • At least 5 years of experience developing, evaluating or implementing cybersecurity, technology or risk assessment activities
  • Professional security management or risk management certification (Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Risk & Information Systems Control (CRISC), Certified Information Privacy Professional (CIPP) or Open FAIR Certified)
  • Preferred Qualifications

  • Master's Degree
  • Knowledge of supervisory expectations expressed in the FFIEC IT Handbook, Federal Reserve Supervisory Letters, Office of the Comptroller of the Currency Bulletins or Federal Deposit Insurance Corporation Financial Institution Letters
  • Create a job alert for this search

    Director Execution • New York, NY, US

    Related jobs
    • Promoted
    Director of Cyber Security

    Director of Cyber Security

    Atlas AirCity of White Plains, NY, United States
    Full-time
    Atlas Air is currently seeking a.Director of Cybersecurity Operations.Hybrid role – White Plains, NY.Relocation assistance is available. Leads a team of highly experienced individual contributors an...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Director Analyst - Cloud Security

    Senior Director Analyst - Cloud Security

    GartnerStamford, CT, United States
    Full-time
    Senior Director Analyst - Cloud Security.Gartner Analysts are industry thought leaders who create must-have research, market predictions and best practices for a broad range of world-leading organi...Show moreLast updated: 30+ days ago
    • Promoted
    Director, Division of Infectious Diseases

    Director, Division of Infectious Diseases

    Hackensack Meridian HealthNeptune Township, US
    Full-time +1
    Director, Division of Infectious Diseases.Jersey Shore University Medical Center.Hackensack Meridian Health – Neptune, New Jersey. Hackensack Meridian Health is seeking a Director, Division of...Show moreLast updated: 25 days ago
    • Promoted
    Cybersecurity Lead / Architect

    Cybersecurity Lead / Architect

    HCLTechEast Brunswick, NJ, US
    Full-time
    Cybersecurity Lead / Architect Candidate Persona - Ability to do architecture and consulting engagement for large and complex customer environment. Self-motivated individual and creative thinker who...Show moreLast updated: 30+ days ago
    • Promoted
    Assistant Professor of Information Systems – Cybersecurity Management

    Assistant Professor of Information Systems – Cybersecurity Management

    InsideHigherEdHempstead, New York, United States
    Full-time +1
    At Hofstra University, intellectual curiosity is not just aspirational – it is central to how we engage on a daily basis. Hofstra faculty work within a diverse scholarly community committed to stude...Show moreLast updated: 30+ days ago
    • Promoted
    Director, Technology Risk- Enterprise Services Risk

    Director, Technology Risk- Enterprise Services Risk

    Capital OneNEW YORK, New York, United States
    Full-time +1
    Director, Technology Risk- Enterprise Services Risk.Director, Technology Risk- Enterprise Services Risk.The Enterprise Services Risk organization is expanding with a focus on attracting innovative,...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Director Analyst, IT Monitoring and Observability, REMOTE US

    Sr Director Analyst, IT Monitoring and Observability, REMOTE US

    GartnerStamford, CT, United States
    Remote
    Full-time
    Gartner Analysts are industry thought leaders who create must-have research, market predictions and best practices for a broad range of world-leading organizations. A Senior Director serves as a lea...Show moreLast updated: 30+ days ago
    • Promoted
    Dir of IT

    Dir of IT

    JobotNew Rochelle, NY, US
    Full-time
    Established company looking to bring on their new DIr of IT.This Jobot Job is hosted by : Adam Bennett.Are you a fit? Easy Apply now by clicking the "Apply Now" button and sending us your resume.Sal...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Director Analyst, Risk Strategy for CIOs in Financial Services, Remote-Us, Remote-EMEA

    Sr Director Analyst, Risk Strategy for CIOs in Financial Services, Remote-Us, Remote-EMEA

    GartnerStamford, CT, United States
    Remote
    Full-time
    Senior Director, Analyst - Risk Strategy for CIOs in Financial Services, Remote-US, Remote-EMEA.Gartner is looking for a Senior Research Director, Analyst to provide insight to CIOs in the Financia...Show moreLast updated: 24 days ago
    • Promoted
    Director, Analyst Enterprise Risk Management REMOTE US

    Director, Analyst Enterprise Risk Management REMOTE US

    GartnerStamford, CT, United States
    Remote
    Full-time
    Analysts provide must-have insights for our clients through published research and client interaction, helping to solve organizational challenges that lead to improved performance.As part of Gartne...Show moreLast updated: 6 days ago
    • Promoted
    • New!
    Director of Digital Content and Marketing

    Director of Digital Content and Marketing

    KIELY BUSINESS SERVICESEatontown, NJ, US
    Full-time
    Since 1952, Kiely Family of Companies has been building lasting relationships and delivering innovative design-build solutions that put our customers’ success first.Recognized on the ENR 400,...Show moreLast updated: 2 hours ago
    • Promoted
    Commercial Lines Account Manager - Cyber Security, E&O, EPL

    Commercial Lines Account Manager - Cyber Security, E&O, EPL

    King Insurance PartnersRed Bank, NJ, US
    Full-time
    Commercial Lines Account Manager.Position can be performed remotely from NH, NJ, MA, or VT.King Insurance Partners based on the guiding philosophy of his life : Do all the good you can, in all the w...Show moreLast updated: 1 day ago
    • Promoted
    Senior Director - Security Infrastructure & Endpoint Protection

    Senior Director - Security Infrastructure & Endpoint Protection

    GartnerStamford, CT, United States
    Full-time
    Senior Director Analyst - Security Infrastructure & Endpoint Protection.What makes Gartner Research a GREAT fit for you?. You are a team player who values expert insights, bold ideas and intellectua...Show moreLast updated: 30+ days ago
    • Promoted
    VP, Product Management

    VP, Product Management

    GartnerStamford, CT, United States
    Full-time
    Vice President, Product Management.Enterprise Risk Management leaders.This role will drive innovation and enhance the portfolio of products and solutions that deliver exceptional value.This person ...Show moreLast updated: 23 days ago
    • Promoted
    Director, Insights on Risks, Issues, and Strategy (IRIS) - Enterprise Services Risk

    Director, Insights on Risks, Issues, and Strategy (IRIS) - Enterprise Services Risk

    Capital OneNew York City, NY, US
    Full-time +1
    Sr Manager, Software Engineering (PL).Do you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iter...Show moreLast updated: 7 days ago
    • Promoted
    VP IT Security and Risk Management (Hybrid)

    VP IT Security and Risk Management (Hybrid)

    Selective InsuranceMillburn, NJ, United States
    Temporary
    At Selective, we don't just insure uniquely, we employ uniqueness.Selective's unique position as both a leading insurance group and an employer of choice is recognized in a wide variety of awards a...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Director Analyst - Network Security

    Senior Director Analyst - Network Security

    GartnerStamford, CT, United States
    Full-time
    Senior Director Analyst - Network Security.Gartner Analysts are industry thought leaders who create must-have research, market predictions and best practices for a broad range of world-leading orga...Show moreLast updated: 30+ days ago
    • Promoted
    Head of Technology Risk Oversight, Managing Director

    Head of Technology Risk Oversight, Managing Director

    State StreetStamford, Connecticut, United States
    Full-time
    This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Who we are ...Show moreLast updated: 30+ days ago