Capital One · 19 hours ago
Senior Associate, Technology Controls Testing - Enterprise Services Risk
Capital One is a leading financial services company that is expanding its Enterprise Services Risk organization. The Senior Associate in Technology Controls Testing will apply risk management skills to support the Technology organization, collaborating with various teams to monitor and test processes, ensuring compliance with cybersecurity requirements and driving insights into risk and control performance.
Financial Services
Responsibilities
Perform independent control testing activities and document results
Uses code to perform and/or automate analysis and repeatable tasks. Leverages tools [e.g. Python/SQL] to extract and analyze data. Visualize and create charts to support testing efforts
Maintains a broad understanding of relevant operating systems and their respective vulnerabilities in order to quickly identify the severity of potential issues [doesn't just know how the tools and reports work, but also how to recognize risk]
Demonstrates a broad understanding of major categories of cyber threats, how those threats can occur in our environment, and the measures required to safeguard the enterprise
Leverages reporting & tools [doesn't build them] to perform analysis on different types of projects, efforts, or datasets & uses data to inform policies and drive change
Possesses an understanding of technology systems at an aggregate level, including networks, applications, cloud computing, and data
Quickly and accurately analyzes data, assesses risk, & prioritizes published vulnerabilities and potential risks to differentiate critical, high-risk, and low-risk issues, and escalate as appropriate
Researches, assembles, and/or evaluates information regarding industry practices or applicable regulatory changes affecting cyber security policies or programs; recommends sound, practical solutions to complex issues
Makes recommendations regarding changes to policy, procedures, and control programs to mitigate evolving risks
Effectively self-challenges cyber control programs as part of first line duties and escalates risks where appropriate
Demonstrates sound lifecycle program management to include documenting and communicating action plans, impediments and risks, and stakeholder engagement
Reports on vulnerability assessment to ensure proper functionality and alignment with Information Security Standards [able to understand and explain, but not required to resolve]
Qualification
Required
High School Diploma, GED or Equivalent Certification
At least 2 years of experience in Risk Management, Process Management, Project Management, or a combination of these
At least 2 years of experience in technology or cyber security risk management
At least 1 year of experience working with at least one scripting language
Preferred
Bachelor's Degree or Military Experience
2+ years of experience testing Technology controls
Risk Certifications (CRISC, CISM, CRCM, CIPP, CISA, CISSP, ABA Risk Mgmt Certification)
3+ years of Risk Management experience in Cyber or Information Security
Project Management experience leading cross functional projects in Risk
Experience with AWS, GCP, or Azure cloud technologies
Strong communication and presentation skills
Experience with security operations, data loss prevention, or access management
Scripting experience in Python or SQL
Benefits
Performance based incentive compensation
Cash bonus(es)
Long term incentives (LTI)
Comprehensive, competitive, and inclusive set of health, financial and other benefits
Company
Capital One
Capital One is a financial services company that provides banking, credit card, auto loan, savings, and commercial banking services.
Funding
Current Stage
Public CompanyTotal Funding
$5.45BKey Investors
Berkshire Hathaway
2025-09-11Post Ipo Debt· $2.75B
2025-01-30Post Ipo Debt· $1.75B
2023-05-15Post Ipo Equity· $954M
Leadership Team
Recent News
Behavioral Health Business
2026-02-12
2026-02-12
2026-02-11
Company data provided by crunchbase