As a Senior Manager in Cybersecurity Consulting at Capital One, you will lead impactful security advisory services, risk management, and consulting in cloud and software architectures within a dynamic and fast-paced environment. You will work closely with diverse stakeholders, ensuring robust security for infrastructure, data, networks, and user access while promoting secure software development practices. This role demands a blend of deep cybersecurity knowledge, cloud computing expertise, and superior leadership and communication skills.
Your role will significantly influence projects, initiatives, and programs that enhance our Information Security framework. You'll possess a practical understanding of risk and security, demonstrating the ability to engage specialists when necessary. Collaborating with teams across Capital One, you'll innovate and push boundaries to enhance security measures. Your comfort with various Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Management will be vital. Understanding different Cloud computing models, including IaaS, PaaS, and SaaS, will greatly contribute to your effectiveness.
Key Responsibilities :
- Act as the primary Information Security contact for a business function within the Card line of business.
- Coordinate and deliver proactive cybersecurity consulting to business and technology teams covering areas such as Infrastructure Security, Resiliency, Data Security, Network Architecture, and User Access Management.
- Serve as a subject matter expert in Capital One's Information Security capabilities, solutions, policies, procedures, and standards.
- Utilize strong technical skills to review architectural designs, propose risk mitigation strategies, and manage overall risk.
- Work closely with engineers, product managers, and other cross-functional teams to simplify processes and facilitate problem-solving.
- Encourage clients to adopt security capabilities and integrate security measures early in the development process.
- Identify and address cybersecurity risks proactively.
- Provide support on critical Information Security topics that may arise.
- Regularly update executive leadership on the Information Security status and risk landscape within your line of business.
About You :
You thrive in a rapidly evolving, innovative computing environment.You possess experience securing large-scale e-commerce platforms, with a strong grasp of payment systems and customer data protection.You have a passion for securing modern computing landscapes.You are eager to continuously learn about emerging technologies.Your conceptual thinking and communication abilities are strong.You work effectively with minimal supervision.You are a proven leader with interpersonal skills capable of engaging with a broad range of professionals, including executives, IT leaders, and technology vendors.You maintain composure under pressure while ensuring confidentiality.You understand strategic business objectives and effectively drive results aligned with these goals.Basic Qualifications :
High School Diploma, GED, or equivalent certification.At least 6 years of experience in cybersecurity or information technology.A minimum of 5 years of experience providing guidance on Security concepts.At least 5 years of experience performing security risk assessments and architecture reviews.At least 5 years of experience with architecture, software design, networking, and cloud infrastructure.At least 4 years of experience in cloud security engineering.Preferred Qualifications :
Bachelor's Degree.6+ years of experience in Application Security, Threat Modeling, Penetration Testing, and Vulnerability Management.4+ years of experience with securing a public cloud environment (e.g., AWS, GCP, Azure).2+ years in the e-commerce industry.2+ years developing software utilizing public cloud (e.g., AWS, GCP, Azure).1+ years in security integration for Mergers and Acquisitions.1+ years of experience with Cloud patch management practices such as system rehydration and image management.1+ years using Agile methodologies.1+ years of experience in Software Security Architecture.1+ years with Application Security.1+ years of experience with Threat Modeling.1+ years in Penetration Testing and / or Vulnerability Management.1+ years with integrating SaaS products into an Enterprise Environment.1+ years with securing Container services.1+ years with Enterprise Monitoring experience.1+ years in the Financial services industry.1+ years with Offensive or Defensive Security techniques.AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification.This position is available in various locations. The minimum and maximum full-time annual salaries for this role are :
McLean, VA : $225,400 - $257,200New York, NY : $245,900 - $280,600Plano, TX : $204,900 - $233,800Richmond, VA : $204,900 - $233,800Note that salaries for part-time roles will be prorated based on the agreed number of hours. Candidates hired to work in other locations will be subject to the salary range for that location. This role may also be eligible for performance-based incentives, including cash bonuses and long-term incentives. Capital One offers a comprehensive benefits package supporting your total well-being.
Capital One is an equal opportunity employer committed to non-discrimination. We promote a drug-free workplace and will consider qualified applicants with a criminal history, adhering to applicable federal, state, and local laws.
If you require accommodation when applying, please contact Capital One Recruiting. All information will be kept confidential as needed for accommodations.