Sr. Manager - Cyber Technical - Technology Audit (Hybrid)
Capital One’s Audit function is a dedicated group of professionals focused on delivering top-quality assurance services to the organization’s Audit Committee. Audit professionals are experienced, well-trained and credentialed, and operate within a collaborative, agile environment to deliver value-added opinions and recommendations. Audit's vision to provide high value, independent, proactive insights, to innovate with technology, and to be a top-notch talent destination, creates a dynamic and challenging atmosphere for both personal growth and professional opportunity.
About the Role
Capital One is seeking an energetic, self-motivated Sr. Technology Manager with experience in technology, cyber, and information security analysis to join the Audit team, focusing on Discover Financial Services technology audits. The role involves auditing critical technology functions, including cloud-based implementations, application and cloud technology controls, and cybersecurity risks.
Responsibilities
- Proactively monitor the technology control environment for changing risks and necessary updates.
- Lead continuous monitoring activities and updates to risk assessments, audit universe, and audit plan.
- Oversee multiple, concurrent Cybersecurity, IT Operations, and Cloud audits across assigned portfolios.
- Develop engagement planning documentation and audit programs to ensure adequate coverage of risk and sufficient rationale for audit scope.
- Supervise and coordinate work assignments amongst audit team members.
- Provide timely feedback, on-the-job training, and coaching to audit staff and direct reports.
- Establish and maintain good relationships with key business and audit partners.
- Leverage specialized knowledge and skills, providing management with insight into areas of technology risk.
- Effectively represent internal audit at management meetings, internal forums, and to external organizations.
- Assess relevance of audit findings, potential exposures, materiality, improving or deteriorating trends, and demonstrate awareness of broader issues.
- Interpret business priorities, anticipate issues and obstacles, and apply to scope of role.
- Deliver appropriate, succinct, and organized information, tailoring communication style to audience.
- Effectively review and compile relevant, material findings and recommendations into readable and concise audit reports.
- Communicate complex results and implications, incorporating different perspectives into deliverables.
- Manage timely and high-quality delivery of multiple tasks, including audits, projects, special assignments, and administrative activities.
- Self-prioritize and independently complete multiple tasks across the team and department.
- Demonstrate the ability to successfully meet deadlines and identify/escalate impediments in a timely manner.
Qualifications
Basic Qualifications
- Bachelor’s Degree or military experience
- At least 7 years of experience in information technology (operations, software delivery, access management, information security, cloud computing)
- At least 4 years of experience in managing audit engagements, project management, or a combination
- At least 4 years of experience leading a team to deliver initiatives, collection of work, or a combination
- At least 4 years of experience in analyzing data extracts to identify trends, patterns, and anomalies, including experience in test scripting, coding (writing, reviewing, or assessing), or a combination
- At least 4 years of experience in information security (application security, network security, cyber security, data protection)
- At least 2 years of experience in cloud computing and controls (design, operation, risk management, or auditing)
- At least 2 years of experience in people management
Preferred Qualifications
- 8+ years of experience in information systems auditing, information systems risk management, technology operations, or a combination
- Certifications related to or pursuing certification in Cloud, Cyber, or Technology Operations, such as Cloud provider certifications, Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM)
- Certifications related to or pursuing certification in Auditing, such as Certified Internal Auditor (CIA), or Certified Information Systems Auditor (CISA)
- 7+ years of experience with IT control frameworks
- 4+ years of experience auditing cyber or information security
- 2+ years of experience auditing emerging technologies
- 4+ years of experience in cloud computing (notably AWS, GCP, Azure) and controls, or 1+ years of conducting audits of controls in cloud-based environments
- 4+ years of experience in risk and data management
- 4+ years of experience performing data analysis in support of internal auditing
Ideal Candidate Traits
- A critical thinker who seeks to understand the business and its control environment.
- Believes insight and objectivity are core elements to providing assurance on the effectiveness and efficiency of governance, risk management, and internal control processes.
- Possesses a relentless focus on quality and timeliness.
- Adapts to change, embraces bold ideas, and is intellectually curious.
- Likes to ask questions, test assumptions, and challenge conventional thinking.
- Develops influential relationships based on shared risk objectives and trust to deliver outstanding business impact and elevate Audit’s value proposition.
- Believes a rich understanding of data, innovation, and technology will enhance auditing capabilities.
- A teacher who does the right thing and leads by example.
- Has a passion for coaching and investing in the betterment of the team.
- Leads through change with candor and optimism.
- Creates an environment that fosters trust, collaboration, and belonging, making it easy to attract, hire, and retain top talent.
Schedule
- This role is hybrid, requiring associates to spend 3 days per week in-person at one of the listed offices.
- Travel expectations: 10-15% of the time.
Pay
The minimum and maximum full-time annual salaries for this role are listed below by location. Salaries for part-time roles will be prorated based on the agreed-upon number of hours to be regularly worked.
- Charlotte, NC: $209,000 - $238,500
- Chicago, IL: $209,000 - $238,500
- McLean, VA: $229,900 - $262,400
- New York, NY: $250,800 - $286,200
- Plano, TX: $209,000 - $238,500
- Richmond, VA: $209,000 - $238,500
- Riverwoods, IL: $209,000 - $238,500
Candidates hired to work in other locations will be subject to the pay range associated with that location. The actual annualized salary amount offered will be reflected solely in the candidate’s offer letter.
This role is also eligible to earn performance-based incentive compensation, which may include cash bonus(es) and/or long-term incentives (LTI). Incentives could be discretionary or non-discretionary depending on the plan.
Benefits
Capital One offers a comprehensive, competitive, and inclusive set of health, financial, and other benefits that support total well-being. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. Learn more at the Capital One Careers website.