Capital One · 15 hours ago
Principal Risk Associate | Retail Bank Tech
Capital One is a leading financial services company, and they are seeking a Principal Risk Associate to join their Tech, Cyber, Data, and Resiliency (TCDR) team. The role involves proactively identifying, measuring, and mitigating complex TCDR risks while fostering innovation and collaboration across various teams.
BankingCredit CardsFinanceFinancial Services
Responsibilities
Serve as the go-to Tech Risk Partner for assigned engineering and technology teams, providing a "white glove service" approach to ensure all necessary risk management support, guidance, and resources are provided promptly
Proactively work with technical teams to develop and execute clear pathways to achieve compliance, drafting audit responses and reducing regulatory exposure and control failures
Ensure all TCDR governance questions, requirements, and compliance checks are addressed and integrated into new service intake processes, preventing downstream risk and redesign efforts
Participate in Material Tech Change (MTC) reviews to proactively identify and vet potential risk scenarios, assess threat models, and ensure controls are updated to reflect the planned changes to the technology environment
Support RCSA with facilitating cross-functional risk workshops to identify and evaluate inherent risks and control effectiveness, documenting clear conclusions and insights across these technical domains
Conduct thorough control analysis to identify design gaps, missing documentation, or outdated controls, partnering with business leaders to perform risk leveling and ensure appropriate control coverage
Prepare high-quality executive reports that summarize the Tech, Cyber, Data, and Resiliency point of view on technology risks derived from the RCSA process
Foster collaborative relationships with stakeholders across the Second Line and Third-Party Risk Management to ensure risk alignment
Monitor the progress of remediation activities, following up on outstanding control actions or delays to ensure timely risk mitigation
Support control dissertation by managing spreadsheets with up-to-date RCSA materials and comprehensive summaries
Subject Matter Expert for metrics in four categories: Compliance, Resiliency, Release Management, and Stability
Develop and maintain a living standard spreadsheet detailing current metrics, defined metric thresholds, non-compliance triggers, and the associated risk of non-compliance for all four categories
Establish and execute a daily process to report on non-compliant metrics to business partners and engaging engineers
Contribute to the monthly executive deck by explaining the drivers for non-compliance and proposing the path to achieving compliance
Provide detailed quarterly reporting on non-compliant metrics for executive governance forums
Monitor the progress of remediation activities and follow up on outstanding controls actions or delays
Immediately investigate and validate the reported critical incidents and the impact caused by the incident
Document all steps taken, the root cause theory, final resolution/workaround, and the lesson learned to prevent it from occurring again
Feed trend data from repeated technology outage incidents back into the Risk and Control Self-Assessment (RCSA) program to update control narratives or increase the criticality rating of the related control
Qualification
Required
At least 3 years of Cyber & Tech Risk Analysis experience
At least 3 years of experience in Risk Management, Compliance, Audit, or Control Testing
Preferred
4+ years of experience in a dedicated role focused on Technology Risk, Cyber Risk, or Business Continuity
2+ years of consulting experience with client and stakeholder relationships
Excellent written and verbal communication skills, including experience presenting complex risk topics to executive audiences
Relevant professional certification (e.g., CRISC, CISA, or other risk/audit certifications)
Benefits
Performance based incentive compensation
Cash bonus(es)
Long term incentives (LTI)
Comprehensive, competitive, and inclusive set of health, financial and other benefits
Company
Capital One
Capital One is a financial services company that provides banking, credit card, auto loan, savings, and commercial banking services.
Funding
Current Stage
Public CompanyTotal Funding
$5.45BKey Investors
Berkshire Hathaway
2025-09-11Post Ipo Debt· $2.75B
2025-01-30Post Ipo Debt· $1.75B
2023-05-15Post Ipo Equity· $954M
Leadership Team
Recent News
2026-01-13
2026-01-13
Yahoo Finance
2026-01-13
Company data provided by crunchbase