Manager, Network Security, Tech & Data Risk Management
- Baltimore, Maryland, United States
- Baltimore, Maryland, United States
Über
Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, software quality, and data management.
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 professionals in TDRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, and tech risk, and data management risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.
For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Tech & Data Risk Management (TRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and the risk of failing to manage our data. The CTRO is independent and oversees the work of the CISO, the CIO/CTO, and the Chief Data Officer. The CTRO reports to the Chief Risk Officer, who reports directly to the CEO.
Our business leaders must make technology decisions constantly. TDRM makes sure they have the tech and data risk information they need to make good decisions. Associates within TDRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.
Role-specific text
This position - Manager, Network Security - is a unique opportunity for candidates with technical cybersecurity experience who have a desire to expand that expertise in a risk management organization. This individual will have the opportunity to leverage their technical subject matter expertise to provide advisory, oversight, and effective challenge to stakeholders within the first line of defense. This role will engage with and build relationships across multiple lines of defense while overseeing network security across Capital One’s private and public cloud footprints.
Responsibilities:
Provide advisory, oversight, and effective challenge to the first line of defense.
Provide technical assessments of cybersecurity controls design and effectiveness.
Draft assessments for senior management and other stakeholders, to include regulatory agencies and the Board of Directors, as needed.
Stay current on emerging cyber threats and potential implications to the firm.
Collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to achieve objectives.
Coordinate program-related activities and deliverables to ensure effective collaboration within the team and across stakeholder groups.
Proven track record of leading, mentoring, and influencing others.
Ability to communicate clearly in written and verbal form.
Ability to manage multiple projects while maintaining superior results.
Ability to work individually and cross-functionally.
Execution oriented and a self-motivator.
Basic Qualifications:
Bachelor’s degree or military experience
3+ years of experience in the financial services industry or highly regulated industry (healthcare, energy, telecommunications)
3+ years of experience implementing network defenses (firewalls, network access control, intrusion detection, intrusion prevention, web application firewalls, web gateways, and proxies) in AWS (Amazon Web Services) or GCP (Google Cloud Platform)
2+ years of experience implementing Zero Trust or Secure Access Service Edge (SASE) in AWS or GCP
1+ certifications for AWS or GCP
2+ years of audit or risk management experience
Preferred Qualifications:
2+ years of experience with Palo Alto Networks technologies
1 or more audit or risk-focused certification: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), or CISSP (Certified Information System Security Professional)
2+ years of experience implementing network defenses for global
Sprachkenntnisse
- English
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klicken Sie auf „Jetzt Bewerben“, um Ihre Bewerbung direkt auf deren Website einzureichen.