Manager, Cyber Security (Third Party Risk)
Core
Lead the advancement of cybersecurity capabilities and services, focusing on third-party risk management, threat intelligence, and governance maturation.
Role type
Manager, Cyber Security (Third Party Risk)
Builds
Cybersecurity governance frameworks, risk assessment programs, and automated monitoring workflows for Capital One's third-party ecosystem.
Domain
Financial Services / Cybersecurity / Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Cybersecurity capability evaluation, risk management practices, NIST Cybersecurity Framework (CSF), control and risk assessments, automation of risk reporting, stakeholder presentation of cyber-risk insights, mentorship of security teams
Preferred skills
Experience with MITRE ATT&CK, CMMC, FedRAMP, multi-cloud environments, security tools (Splunk, Crowdstrike, Qualys, AWS Security Hub), cybersecurity metrics development, industry governance processes, security incident analysis
Technologies
NIST CSF, MITRE ATT&CK, CMMC, FedRAMP, Splunk, Crowdstrike, Qualys, AWS Security Hub
Responsibilities
Lead advancement of cybersecurity capabilities through stakeholder partnerships; leverage cybersecurity data to produce risk indicators and metrics; provide expertise during control and risk assessments; drive adoption of automation for risk workflows; synthesize and present key cyber-risk insights to senior management; mentor associates on cyber-risk methodologies
Seniority
Manager, hands-on leadership with strategic oversight