Manager, Information Security Office (ISO) Consultant
About the role
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security and Risk Management. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with technologies like Cloud services, Containers, Docker, Microservices, Serverless, APIs, DevOps and micro-segmentation. You are also comfortable leveraging modern AI and developer tools, including Claude, ChatGPT, Github Copilot, and similar AI-assisted development platforms, to rapidly prototype, build, automate, and improve security solutions. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities
- Act as a central point of contact for your line of business to the rest of Capital One’s Information Security and Risk Management
- Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
- Leverage modern development and AI-assisted tools to rapidly prototype and build security solutions, automations, dashboards, workflows, and other technical capabilities that address business and security needs
- Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
- Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
- Escalate and manage cyber security risk
- Provide ad hoc support on special Information Security hot topics for the business
- Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
- Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
About You
- You have a desire to work in a very fast moving, forward leaning, and modern computing environment
- You have a deep passion for Securing modern computing platforms
- You have a strong desire to continually learn about new technologies
- You are a hands-on technical leader who enjoys building and experimenting with new solutions, using automation, scripting, APIs, cloud services, and AI-assisted development tools to turn ideas into working capabilities
- You possess strong conceptual thinking and communication skills
- You are able to work well under minimal supervision
- You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
- You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
- You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications
- High School Diploma, GED, or equivalent certification
- At least 4 years of experience providing advisory and oversight of cybersecurity concepts
- At least 3 years of experience performing security risk assessments and security architecture reviews
- At least 3 years of experience with architecture design, software design, networking or Cloud infrastructure
Preferred Qualifications
- Bachelor’s Degree
- 6+ years of experience with Architecture design, software design, networking or Cloud infrastructure
- 4+ years of experience in securing a public cloud environment such as AWS, GCP, or Azure
- 2+ years of experience utilizing Agile methodologies
- 2+ years of experience in Enterprise Monitoring
- 2+ years of experience with technologies supporting finance, fintech, banking, payment cards, or a related domain
- 2+ years of experience with web and mobile application security, and solid understanding of the OWASP Top Ten
- 2+ years of experience with security testing, such as penetration testing, red teaming, vulnerability scanning, SAST and DAST
- 2+ years of experience with scripting or programming experience such as Python, SQL, PHP, PowerShell and the ability to build and automate technical solutions
- Experience leveraging generative AI and AI-assisted development tools such as Claude, ChatGPT, Github Copilot, Gemini, Cursor, or similar to accelerate software development, automation, security analysis, and solution prototyping
- Professional certifications such as AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP)
- 2+ years of experience with international regulatory cyber audits and assessments
Pay
The minimum and maximum full-time annual salaries for this role are listed below, by location. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
- McLean, VA: $197,300 - $225,100 for Manager, Cyber Technical
- Plano, TX: $179,400 - $204,700 for Manager, Cyber Technical
- Richmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.