Director, Product Security-Information Security Office

Company:  Capital One
Location: Richmond
Closing Date: 22/10/2024
Salary: £150 - £200 Per Annum
Hours: Full Time
Type: Permanent
Job Requirements / Description

Center 1 (19052), United States of America, McLean, Virginia

Director, Product Security - Information Security Office

At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security and Risk Management. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. As part of the Information Security Office and Product Security team, you will lead the Integration capability team responsible for the governance, oversight and operational excellence functions, enabling the teams to effectively and consistently deliver ISO and Product Security services to their customers. You understand the needs of the unique teams and ensure that they have the tools and structure needed to operate without roadblocks, support their customers, and meet regulatory reporting requirements. You collaborate and liaise on behalf of the Information Security Office with the Cyber Department to allow the Department and Capital One to innovate and push the envelope.

Responsibilities:

  1. Act as a central point of contact for your capability to the rest of Capital One's Information Security and Risk Management.
  2. Lead the Integration team and coordinate proactive operational support to the Product Security capability teams, including Assurance, Advisory, Risk Operations.
  3. Influence Information Security Office and Product Security capability teams to leverage best practices and standards, ensure governance and oversight of ISO services.
  4. Lead Quality assurance of ISO services, proactively identify gaps and drive remediation to improve service quality and audit preparedness.
  5. Lead Product Security governance and leadership forums and drive meeting agendas and presentations.
  6. Be a champion for the adoption of Agile principles within Product Security.
  7. Provide ad hoc support on special Information Security Office/Product Security hot topics.
  8. Provide regular updates, draft ISO-wide and executive leadership level memos and communications on the overall Product Security health and risk environment.
  9. Work with divisional Information Security Office teams leadership to anticipate their objectives and needs to better serve Product Security services.
  10. Participate in functional communities of practice to ensure consistency across Information Security Office teams.
  11. Provide support on agenda and materials development and execution of Product Security PI planning, meetings and events.
  12. Be knowledgeable about Capital One's Information Security offerings, policies, procedures and standards.

About You:

  1. You have a desire to work in a very fast moving, forward leaning, and modern computing environment.
  2. You have a deep passion for Securing modern computing platforms.
  3. You have a strong desire to continually learn about new technologies.
  4. You possess strong conceptual thinking and communication skills.
  5. You are able to work well under minimal supervision.
  6. You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors.
  7. You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality.
  8. You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives.

Basic Qualifications:

  1. Bachelor's Degree.
  2. At least 7 years of experience in cybersecurity or information technology.
  3. At least 7 years of experience in security governance or risk management.
  4. At least 5 years of experience in people management.

Preferred Qualifications:

  1. Master's Degree in Computer Science, Information Systems, or Engineering.
  2. 10+ years of experience in Cybersecurity or Technology risk strategy and governance.
  3. 5+ years experience with public cloud (AWS, GCP, Azure).
  4. 5+ years experience utilizing Agile methodologies.
  5. 4+ years experience with knowledge management tools (Confluence, JIRA).
  6. 3+ years of financial services industry experience.
  7. Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA).
  8. 3+ years experience in a regulated environment.
#J-18808-Ljbffr
Apply Now
An error has occurred. This application may no longer respond until reloaded. Reload 🗙