Information Security Analyst jobs at Northwest Bank - 432 jobs
Lead Information Security Consultant (Third Party Oversight)
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. The associate will support the Global Payment Network's Third Party Management function from a Cyber lens. The associate will partner with Global Payment Network leaders, Third Party Manager, risk management functions, and various cyber teams to provide sound risk consulting and influence business decisions that reduce or eliminate risk to Capital One. You will challenge and innovate within your team to drive process improvements to elevate program efficiency. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Third Parties in the Global Payment Network line of business
Establish effective working relationships with key stakeholders
Proactively identify informationsecurity risk and partner with key stakeholders to reduce or eliminate risk
Coordinate and execute proactive consulting to both internal and external teams as it relates to third party informationsecurity risk
Support business related projects and initiatives and influence customers to make solid business decisions
Provide regular updates to executive leadership within Cyber and other stakeholders on the overall Third Party Management health and risk environment
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special departmental goals, objectives, and initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated team-oriented professional with interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and external third parties
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You demonstrate strong ability to analyze information and data
You demonstrate strong subject matter expertise and sound judgment when analyzing third party risk
You operate in a collaborative manner to effectively assess risk while maintaining business relationships
You develop and communicate quality recommendations to key stakeholders
You communicate technical issues to non-technical people
You demonstrate collaborative partnership skills for working with various points of contacts
You demonstrate capacity to think broadly but go deep into subject matter when needed
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 4 years of experience providing guidance and oversight of cybersecurity concepts
At least 3 years of experience performing security risk assessments and security architecture reviews
At least 3 years of experience with architecture design, software design, networking or Cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
2+ years of experience in PCI DSS, NIST, ISO, Physical Security, or IT Operations Management
2+ years of experience at a Financial Institution
2+ years of experience in Third Party Risk
Experience in a regulated environment
CISSP, CISA, or CRISC certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $179,400 - $204,700 for Manager, Cyber TechnicalMcLean, VA: $197,300 - $225,100 for Manager, Cyber TechnicalNew York, NY: $215,200 - $245,600 for Manager, Cyber TechnicalPlano, TX: $179,400 - $204,700 for Manager, Cyber TechnicalRichmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$215.2k-245.6k yearly 1d ago
Looking for a job?
Let Zippia find it for you.
Lead Information Security Consultant (Global Payment Network)
Capital One 4.7
York, PA jobs
As a Lead Consultant in Capital One's Cyber InformationSecurity Office (ISO), you will work closely with our cybersecurity team and with extended technical teams to manage and improve the cybersecurity posture specifically related to Global Payments Network. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for a portfolio of voice and customer servicing technology assets.
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
About You:
Strong technical architecture background with the ability to proactively identify and mitigate technical risks throughout delivery life-cycle
Exceptional communication and collaboration skills
Excellent problem solving and influencing skills
Strong desire to continually learn and solve security problems involving new technologies
You are able to work well under minimal supervision
Ability to simplify the technically complex and drive well-educated decisions across product, engineering, design, and enterprise risk representatives
Exceptional cross-team collaboration; able to work across different functions, organizations, and reporting boundaries to get the job done.
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 4 years of experience providing guidance and oversight of cyber security concepts
At least 3 years of experience performing cyber security risk assessments and cyber security architecture reviews
At least 3 years of experience with architecture, software design, networking or cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
6+ years of experience with Architecture, software design, networking or Cloud infrastructure
4+ years of experience in securing a public cloud environment (AWS, GCP, or Azure)
2+ years of experience utilizing Agile methodologies
2+ years of experience in Enterprise Monitoring
2+ years of experience in web application security
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $179,400 - $204,700 for Manager, Cyber TechnicalMcLean, VA: $197,300 - $225,100 for Manager, Cyber TechnicalNew York, NY: $215,200 - $245,600 for Manager, Cyber TechnicalPlano, TX: $179,400 - $204,700 for Manager, Cyber TechnicalRichmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$215.2k-245.6k yearly 1d ago
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Menlo Park, CA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive Security Engineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
$152k-212k yearly est. 1d ago
Senior Manager, Information Security Office Consultant
Capital One 4.7
New York, NY jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
As a Senior Manager, You will play a leading role in delivering product security advisory services for a fast moving project within a line of business portfolio, working closely with other professionals as required. You have the ability to lead complex problem solving in partnership with multiple stakeholders in a fast-paced environment, driving results with critical impact. You will work with the other Informationsecurity consultants, business, technology and risk partners to achieve time sensitive goals and objectives in a secure manner with a heavy forward lean on modern software and technology architectures.
Responsibilities:
Act as an InformationSecurity point of contact for a business function within the Card line of business
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Leverage strong technical acumen and be security SME reviewing architecture, providing risk mitigation solutions and driving overall risk management.
Partner closely with engineers, product managers, and other cross-functional partners to help break down complexity and organizational silos to problem solve.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have experience in securing large-scale e-commerce platforms, with deep understanding of payments systems, customer data protection across high transaction environments ensuring protection of user data across internal and partner ecosystems.
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of Security concepts
At least 5 years of experience performing security risk assessments and security architecture reviews
At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
At least 4 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
6+ years of experience Application Security, Threat Modeling, Penetration Testing, Vulnerability Management
4+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
2+ years experience in e-commerce industry
2+ years of experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
1+ years of experience in security integration for Mergers and Acquisitions
1+ years of experience with Cloud patch management practices such as system rehydration and image management
1+ years of experience utilizing Agile methodologies
1+ years of experience with Software Security Architecture
1+ years of experience with Application Security
1+ years of experience with Threat Modeling
1+ years of experience with Penetration Testing and/or Vulnerability Management
1+ years of experience with integrating SaaS products into an Enterprise Environment
1+ years of experience with securing Container services
1+ years of experience with Splunk-Fu and Enterprise Monitoring experience
1+ years of experience in a Financial services industry experience
1+ years of experience with Offensive or Defensive Security techniques
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber TechnicalPlano, TX: $209,000 - $238,500 for Sr Manager, Cyber TechnicalRichmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$87k-113k yearly est. 1d ago
Senior Manager, Information Security Office Consultant (Third Party Oversight)
Capital One 4.7
New York, NY jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. The associate will support the Global Payment Network's Third Party Management function from a Cyber lens. The associate will partner with Global Payment Network leaders, Third Party Manager, risk management functions, and various cyber teams to provide sound risk consulting and influence business decisions that reduce or eliminate risk to Capital One. You will challenge and innovate within your team to drive process improvements to elevate program efficiency. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Third Parties in the Global Payment Network line of business
Establish effective working relationships with key stakeholders
Proactively identify informationsecurity risk and partner with key stakeholders to reduce or eliminate risk
Coordinate and execute proactive consulting to both internal and external teams as it relates to third party informationsecurity risk
Support business related projects and initiatives and influence customers to make solid business decisions
Provide regular updates to executive leadership within Cyber and other stakeholders on the overall Third Party Management health and risk environment
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special departmental goals, objectives, and initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated team-oriented professional with interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and external third parties
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You demonstrate strong ability to analyze information and data
You demonstrate strong subject matter expertise and sound judgment when analyzing third party risk
You operate in a collaborative manner to effectively assess risk while maintaining business relationships
You develop and communicate quality recommendations to key stakeholders
You communicate technical issues to non-technical people
You demonstrate collaborative partnership skills for working with various points of contacts
You demonstrate capacity to think broadly but go deep into subject matter when needed
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
4+ years of experience in PCI DSS, NIST, ISO, Physical Security, or IT Operations Management
4+ years of experience at a Financial Institution
4+ years of experience in Third Party Risk
Experience in a regulated environment
CISSP, CISA, or CRISC certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $209,000 - $238,500 for Sr Manager, Cyber TechnicalMcLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber TechnicalPlano, TX: $209,000 - $238,500 for Sr Manager, Cyber TechnicalRichmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$87k-113k yearly est. 1d ago
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Bellevue, WA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive Security Engineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
$137k-192k yearly est. 1d ago
Lead Information Security Consultant (Third Party Oversight)
Capital One 4.7
New York, NY jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. The associate will support the Global Payment Network's Third Party Management function from a Cyber lens. The associate will partner with Global Payment Network leaders, Third Party Manager, risk management functions, and various cyber teams to provide sound risk consulting and influence business decisions that reduce or eliminate risk to Capital One. You will challenge and innovate within your team to drive process improvements to elevate program efficiency. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Third Parties in the Global Payment Network line of business
Establish effective working relationships with key stakeholders
Proactively identify informationsecurity risk and partner with key stakeholders to reduce or eliminate risk
Coordinate and execute proactive consulting to both internal and external teams as it relates to third party informationsecurity risk
Support business related projects and initiatives and influence customers to make solid business decisions
Provide regular updates to executive leadership within Cyber and other stakeholders on the overall Third Party Management health and risk environment
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special departmental goals, objectives, and initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated team-oriented professional with interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and external third parties
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You demonstrate strong ability to analyze information and data
You demonstrate strong subject matter expertise and sound judgment when analyzing third party risk
You operate in a collaborative manner to effectively assess risk while maintaining business relationships
You develop and communicate quality recommendations to key stakeholders
You communicate technical issues to non-technical people
You demonstrate collaborative partnership skills for working with various points of contacts
You demonstrate capacity to think broadly but go deep into subject matter when needed
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 4 years of experience providing guidance and oversight of cybersecurity concepts
At least 3 years of experience performing security risk assessments and security architecture reviews
At least 3 years of experience with architecture design, software design, networking or Cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
2+ years of experience in PCI DSS, NIST, ISO, Physical Security, or IT Operations Management
2+ years of experience at a Financial Institution
2+ years of experience in Third Party Risk
Experience in a regulated environment
CISSP, CISA, or CRISC certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $179,400 - $204,700 for Manager, Cyber TechnicalMcLean, VA: $197,300 - $225,100 for Manager, Cyber TechnicalNew York, NY: $215,200 - $245,600 for Manager, Cyber TechnicalPlano, TX: $179,400 - $204,700 for Manager, Cyber TechnicalRichmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$74k-100k yearly est. 1d ago
Lead Information Security Consultant (Global Payment Network)
Capital One 4.7
New York, NY jobs
As a Lead Consultant in Capital One's Cyber InformationSecurity Office (ISO), you will work closely with our cybersecurity team and with extended technical teams to manage and improve the cybersecurity posture specifically related to Global Payments Network. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for a portfolio of voice and customer servicing technology assets.
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
About You:
Strong technical architecture background with the ability to proactively identify and mitigate technical risks throughout delivery life-cycle
Exceptional communication and collaboration skills
Excellent problem solving and influencing skills
Strong desire to continually learn and solve security problems involving new technologies
You are able to work well under minimal supervision
Ability to simplify the technically complex and drive well-educated decisions across product, engineering, design, and enterprise risk representatives
Exceptional cross-team collaboration; able to work across different functions, organizations, and reporting boundaries to get the job done.
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 4 years of experience providing guidance and oversight of cyber security concepts
At least 3 years of experience performing cyber security risk assessments and cyber security architecture reviews
At least 3 years of experience with architecture, software design, networking or cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
6+ years of experience with Architecture, software design, networking or Cloud infrastructure
4+ years of experience in securing a public cloud environment (AWS, GCP, or Azure)
2+ years of experience utilizing Agile methodologies
2+ years of experience in Enterprise Monitoring
2+ years of experience in web application security
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $179,400 - $204,700 for Manager, Cyber TechnicalMcLean, VA: $197,300 - $225,100 for Manager, Cyber TechnicalNew York, NY: $215,200 - $245,600 for Manager, Cyber TechnicalPlano, TX: $179,400 - $204,700 for Manager, Cyber TechnicalRichmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$74k-100k yearly est. 1d ago
Senior Manager, Information Security Office (ISO) Consultant
Capital One 4.7
Chicago, IL jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
The Senior Lead ISO Consultant will provide cyber security architecture advisory support needed to build the Technology & Business capabilities on a novel Modern platform, that will enable customer set-up, use, and management of a Capital One Credit Card, including Data Product. In this role, the responsibilities will include:
Act as a central InformationSecurity point of contact for the Global Payment Networks line of business
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.
Support security architecture and implementation needs for technology modernization efforts
Overseeing all cyber related dependencies across the multiple components being built for the modernization effort.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad-hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms.
Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations.
Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures.
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
6+ years of cyber security advisory and technology consulting experience
6+ years of experience in Cyber Risk Management
3+ years of experience on cryptography, HSMs and similar systems
Knowledge of HPNS, ATM, Mainframe technologies and other payment networks infrastructure technologies
Experience in security integration for Mergers and Acquisitions
Experience with PCI and Payment Network Compliance.
Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $209,000 - $238,500 for Sr Manager, Cyber TechnicalMcLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber TechnicalPlano, TX: $209,000 - $238,500 for Sr Manager, Cyber TechnicalRichmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$74k-96k yearly est. 1d ago
Senior Manager, Information Security Office Consultant
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security and Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Capital One's Enterprise Data organization
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering API Security, File Transfer, Data Security, Infrastructure Security, Resiliency, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures, and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of Security concepts
At least 5 years of experience performing security risk assessments and security architecture reviews
At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
At least 3 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
6+ years of experience with Software Security Architecture, Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management
6+ years of experience in securing a public cloud environment and building software utilizing public cloud
6+ years of experience with Cloud patch management practices such as system rehydration or image management
1+ years of experience utilizing Agile methodologies
1+ years of experience with API Security
1+ years of experience with File Transfer systems
1+ years of experience with data ecosystems, applications, privacy, and compliance
1+ years of experience with integrating SaaS products into an Enterprise Environment
1+ years of experience with securing Container services
1+ years of experience with Splunk-Fu and Enterprise Monitoring
1+ years of experience with Offensive or Defensive Security techniques
1+ years of Financial services industry experience
Experience in a regulated environment
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$83k-108k yearly est. 1d ago
Senior Manager, Information Security Office (ISO) Consultant
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with modern software, big data ecosystems, and cloud based technologies. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for the Enterprise Platforms line of business
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Data Security, Web Security, and Mobile Security
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures, and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in development processes
Escalate and manage cyber security risk
Educate and influence executive leadership and associates to effectively leverage security capabilities and solutions to mitigate risks and emerging threats
Deliver Cyber agenda and integration of InformationSecurity within business objectives for the line of business area
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
You are able to tailor communications and analysis to the intended audience
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 6 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing security risk assessments or security architecture reviews
At least 5 years of experience with architecture, software design, networking, or cloud infrastructure
At least 4 years of experience with cloud security engineering
At least 2 years experience utilizing agile methodologies within DevOps environments
Preferred Qualifications:
Bachelor's Degree
8+ years of experience in cyber security or information technology
6+ years of experience in securing a public cloud environment
5+ years of experience securing Identity Applications
5+ years of experience with Threat Modeling
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber TechnicalPlano, TX: $204,900 - $233,800 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$83k-108k yearly est. 1d ago
Senior Manager, Information Security Office Consultant
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
As a Senior Manager, You will play a leading role in delivering product security advisory services for a fast moving project within a line of business portfolio, working closely with other professionals as required. You have the ability to lead complex problem solving in partnership with multiple stakeholders in a fast-paced environment, driving results with critical impact. You will work with the other Informationsecurity consultants, business, technology and risk partners to achieve time sensitive goals and objectives in a secure manner with a heavy forward lean on modern software and technology architectures.
Responsibilities:
Act as an InformationSecurity point of contact for a business function within the Card line of business
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Leverage strong technical acumen and be security SME reviewing architecture, providing risk mitigation solutions and driving overall risk management.
Partner closely with engineers, product managers, and other cross-functional partners to help break down complexity and organizational silos to problem solve.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have experience in securing large-scale e-commerce platforms, with deep understanding of payments systems, customer data protection across high transaction environments ensuring protection of user data across internal and partner ecosystems.
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of Security concepts
At least 5 years of experience performing security risk assessments and security architecture reviews
At least 5 years of experience with architecture, software design, networking, and cloud infrastructure
At least 4 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
6+ years of experience Application Security, Threat Modeling, Penetration Testing, Vulnerability Management
4+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
2+ years experience in e-commerce industry
2+ years of experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
1+ years of experience in security integration for Mergers and Acquisitions
1+ years of experience with Cloud patch management practices such as system rehydration and image management
1+ years of experience utilizing Agile methodologies
1+ years of experience with Software Security Architecture
1+ years of experience with Application Security
1+ years of experience with Threat Modeling
1+ years of experience with Penetration Testing and/or Vulnerability Management
1+ years of experience with integrating SaaS products into an Enterprise Environment
1+ years of experience with securing Container services
1+ years of experience with Splunk-Fu and Enterprise Monitoring experience
1+ years of experience in a Financial services industry experience
1+ years of experience with Offensive or Defensive Security techniques
AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber TechnicalPlano, TX: $209,000 - $238,500 for Sr Manager, Cyber TechnicalRichmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$83k-108k yearly est. 1d ago
Senior Manager, Information Security Office Consultant (Third Party Oversight)
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. The associate will support the Global Payment Network's Third Party Management function from a Cyber lens. The associate will partner with Global Payment Network leaders, Third Party Manager, risk management functions, and various cyber teams to provide sound risk consulting and influence business decisions that reduce or eliminate risk to Capital One. You will challenge and innovate within your team to drive process improvements to elevate program efficiency. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Third Parties in the Global Payment Network line of business
Establish effective working relationships with key stakeholders
Proactively identify informationsecurity risk and partner with key stakeholders to reduce or eliminate risk
Coordinate and execute proactive consulting to both internal and external teams as it relates to third party informationsecurity risk
Support business related projects and initiatives and influence customers to make solid business decisions
Provide regular updates to executive leadership within Cyber and other stakeholders on the overall Third Party Management health and risk environment
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special departmental goals, objectives, and initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated team-oriented professional with interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and external third parties
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You demonstrate strong ability to analyze information and data
You demonstrate strong subject matter expertise and sound judgment when analyzing third party risk
You operate in a collaborative manner to effectively assess risk while maintaining business relationships
You develop and communicate quality recommendations to key stakeholders
You communicate technical issues to non-technical people
You demonstrate collaborative partnership skills for working with various points of contacts
You demonstrate capacity to think broadly but go deep into subject matter when needed
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
4+ years of experience in PCI DSS, NIST, ISO, Physical Security, or IT Operations Management
4+ years of experience at a Financial Institution
4+ years of experience in Third Party Risk
Experience in a regulated environment
CISSP, CISA, or CRISC certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $209,000 - $238,500 for Sr Manager, Cyber TechnicalMcLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber TechnicalPlano, TX: $209,000 - $238,500 for Sr Manager, Cyber TechnicalRichmond, VA: $209,000 - $238,500 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$83k-108k yearly est. 1d ago
Senior Manager, Information Security Office (ISO) Consultant
Capital One 4.7
York, PA jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
The Senior Lead ISO Consultant will provide cyber security architecture advisory support needed to build the Technology & Business capabilities on a novel Modern platform, that will enable customer set-up, use, and management of a Capital One Credit Card, including Data Product. In this role, the responsibilities will include:
Act as a central InformationSecurity point of contact for the Global Payment Networks line of business
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms.
Support security architecture and implementation needs for technology modernization efforts
Overseeing all cyber related dependencies across the multiple components being built for the modernization effort.
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad-hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms.
Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations.
Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures.
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cybersecurity or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 4 years of experience with cloud security
Preferred Qualifications:
Bachelor's Degree
7+ years of experience in securing a public cloud environment (AWS, GCP, Azure)
6+ years of cyber security advisory and technology consulting experience
6+ years of experience in Cyber Risk Management
3+ years of experience on cryptography, HSMs and similar systems
Knowledge of HPNS, ATM, Mainframe technologies and other payment networks infrastructure technologies
Experience in security integration for Mergers and Acquisitions
Experience with PCI and Payment Network Compliance.
Professional certifications AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $209,000 - $238,500 for Sr Manager, Cyber TechnicalMcLean, VA: $229,900 - $262,400 for Sr Manager, Cyber TechnicalNew York, NY: $250,800 - $286,200 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$83k-108k yearly est. 1d ago
Lead Information Security Consultant (Third Party Oversight)
Capital One 4.7
Chicago, IL jobs
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. The associate will support the Global Payment Network's Third Party Management function from a Cyber lens. The associate will partner with Global Payment Network leaders, Third Party Manager, risk management functions, and various cyber teams to provide sound risk consulting and influence business decisions that reduce or eliminate risk to Capital One. You will challenge and innovate within your team to drive process improvements to elevate program efficiency. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central InformationSecurity point of contact for Third Parties in the Global Payment Network line of business
Establish effective working relationships with key stakeholders
Proactively identify informationsecurity risk and partner with key stakeholders to reduce or eliminate risk
Coordinate and execute proactive consulting to both internal and external teams as it relates to third party informationsecurity risk
Support business related projects and initiatives and influence customers to make solid business decisions
Provide regular updates to executive leadership within Cyber and other stakeholders on the overall Third Party Management health and risk environment
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special departmental goals, objectives, and initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated team-oriented professional with interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and external third parties
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You demonstrate strong ability to analyze information and data
You demonstrate strong subject matter expertise and sound judgment when analyzing third party risk
You operate in a collaborative manner to effectively assess risk while maintaining business relationships
You develop and communicate quality recommendations to key stakeholders
You communicate technical issues to non-technical people
You demonstrate collaborative partnership skills for working with various points of contacts
You demonstrate capacity to think broadly but go deep into subject matter when needed
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 4 years of experience providing guidance and oversight of cybersecurity concepts
At least 3 years of experience performing security risk assessments and security architecture reviews
At least 3 years of experience with architecture design, software design, networking or Cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
2+ years of experience in PCI DSS, NIST, ISO, Physical Security, or IT Operations Management
2+ years of experience at a Financial Institution
2+ years of experience in Third Party Risk
Experience in a regulated environment
CISSP, CISA, or CRISC certification
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $179,400 - $204,700 for Manager, Cyber TechnicalMcLean, VA: $197,300 - $225,100 for Manager, Cyber TechnicalNew York, NY: $215,200 - $245,600 for Manager, Cyber TechnicalPlano, TX: $179,400 - $204,700 for Manager, Cyber TechnicalRichmond, VA: $179,400 - $204,700 for Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$71k-95k yearly est. 1d ago
Senior Security Engineer: Security Operations & IR
Goodleap, LLC 4.6
San Francisco, CA jobs
A leading technology company in San Francisco is seeking a Senior Security Engineer to enhance security measures across systems and services. You will collaborate with product, engineering, and IT teams to design and implement security monitoring and fraud detection solutions. Ideal candidates will possess strong communication skills, expertise in EDR solutions, and a solid understanding of AWS services. Competitive salary of $146,000 to $170,000 plus bonus and equity opportunities are included.
#J-18808-Ljbffr
$146k-170k yearly 5d ago
Senior Security Engineer, Security Operations
Goodleap, LLC 4.6
San Francisco, CA jobs
About GoodLeap
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy‑efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI‑powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our award‑winning nonprofit, GivePower, which is building and deploying life‑saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary
The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap to design, build, implement, and operate security and fraud monitoring, detection, and response capabilities.
Your Oversight Will Encompass
Security & Fraud Monitoring, Detection, and Response: Identification of potential misuse and abuse cases, determining corresponding events associated with manifestation of such scenarios, design of identification and detection solutions -e.g., correlated/iterative event searches across log sources ranging from infrastructure to applications/SaaS platforms, testing, implementation, monitoring, and fine‑tuning of these solutions, etc.
Toolset design and operations: Design and build the monitoring, detection, and response platform, from tool selection and integration - e.g., SIEM, SOAR, agentic SOC, EDR, to daily operations/management
Incident Response: Play a leading role in the definition, refinement, and execution of incident response activities.
Overall Security Operations: Management and operation of security platforms/solutions outside monitoring, detection, and response platform.
Support Embedded Product Security Team: Design, build, and implement monitoring and detection solutions for GoodLeap products and services.
Essential Job Duties & Responsibilities
Lead, participate in, and contribute to security and fraud monitoring, detection, and response activities, inclusive of investigations, threat hunting, etc. Create playbooks for specific incident response scenarios.
Identify potential misuse and abuse cases in enterprise systems, propose solutions to detect these scenarios, and identify and implement monitoring and detection solutions for such scenarios.
Support or develop components of the security analytics platform.
Support embedded (product) security team.
Support general security operations team with vulnerability management, tools management, and more.
Required Skills, Knowledge & Abilities
Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non‑technical audiences.
Expertise in security event management, monitoring, threat hunting, incident response, playbook creation, orchestration/automations, etc.
Experience with threat modeling methodologies.
Expertise with EDR solutions/platforms, such as CrowdStrike, S1, Palo Alto Cortex EDR, etc.
Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble. Experience designing, configuring, and implementing security and fraud monitoring for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
Experience working with and creating solutions based AI and ML toolsets - e.g., creation of AI skills, agents, MCP clients, vibe coding.
Strong understanding of both human and non‑human identity management and common enterprise and consumer authentication standards and use cases.
Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure‑as‑Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
Prior experience interfacing and supporting teams outside of security - e.g., internal product teams and other cross‑functional areas.
Proficiency in writing automation scripts in multiple languages and integrating with REST/GraphQL APIs to orchestrate workflows between security tooling and third‑party cloud/SaaS platforms, automating detection, response, and operational processes. Experience engaging with vendors in design partnerships.
Experience overseeing vulnerability and threat management at the platform and application levels.
Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
Ability to balance a high‑level view of security strategy with attention to detail, ensuring thorough and effective execution.
$146,000 - $170,000 a year
In addition to the above salary, this role may be eligible for a bonus and equity.
Additional Information Regarding Job Duties and s
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
#J-18808-Ljbffr
$146k-170k yearly 5d ago
Information Security Compliance Senior Analyst
Crypto.com 3.3
Remote
At Crypto.com, our dedication to user security is led by our highly experienced Security Team. Comprising an international roster of seasoned cybersecurity experts, our team leads the company's Security, Privacy, and Security Compliance endeavors. The team includes holders of international patents for technologies integrated in our security architecture. Under the stewardship of a distinguished CISO recognized by the Forbes Technology Council and among the Global Top 100 CISOs, our team has consistently championed industry standards, acquiring certifications like ISO27001, ISO27701, ISO22301, PCI:DSS 3.2.1 (Level 1), NIST Tier 4, and SOC 2 Type II, in addition to the MPI License from Singapore MAS. Our Chief InformationSecurity Officer reports directly to the CEO, underscoring the prioritization of security in our organization's hierarchy.
Our Security Team not only places great emphasis on credentials and expertise but also deeply values hands-on experience, rapid cognition, and dynamic learning. The challenges in the world of crypto are ever-evolving, and as such, our team prides itself on quick adaptability and robust teamwork, ensuring that we stay ahead of potential threats and always safeguard our user base.
About the Role
As our Security Compliance Senior Analyst, you will be tasked with security compliance activities along with our journey. You are expected to take the initiative to assist us with several security compliance programs and certifications. You are required to address and review compliance gaps and give recommendations and support on remediation activities. You will also be trusted to provide technical advice to ensure that security compliance requirements are met throughout all business units. This role requires technical knowledge of network security, especially on-prem and cloud native architectures. A familiarity with US derivatives regulatory frameworks would be advantageous. Job Responsibilities:
Assist in our security compliance programs, including ISO27001, ISO27701, PCI-DSS, SOC2 Type 2, and local regulations
Participate in internal security and privacy assessments, internal and external audits, compliance certifications, and risk management
Provide complete and accurate responses to internal and third-party enquiries on security compliance
Perform security compliance assessment activities, including periodic technical, organizational, and third-party risk and control assessments, and managing remediation activities to completion
Design and manage necessary control and framework required to comply with international standards and US local regulations
Identify and drive process improvements for streamlining global security compliance operations
Qualifications:
3-5 years of experience in informationsecurity, privacy, IT audit or IT risk management related roles.
Prefer experience with one or more of the following: In-house security and privacy operations, conducting security control assessments, risk assessments or audits.
Prefer experience with any of the following: ISO27001, ISO27701, SOC1, SOC2, PCI, SOX, COSO, cloud technologies, and data protection regulations and requirements.
Ability to analyze and review US and Global privacy and informationsecurity compliance and provide guidance.
Holders of security-related certifications/qualifications will be an advantage: CISSP, CRISC, CISM, CISA, ISO27001 LA, CIPT, CIPP/E, or other relevant certifications
Experience leading compliance initiatives and working with auditors and/or external regulators
It's a plus if you:
Have experience in informationsecurity and privacy management in virtual assets, fintech, online services, platform services, or global services.
Have experience in establishing informationsecurity and privacy framework to meet US regulations, (CFTC, FINRA, SEC, and other US based regulators.)
Are a strong commitment to personal learning and development
Are detail minded with an analytical mindset
Have good communication skills with an ability to explain complex technical issues to non-technical business users
Have prior experience with project management
Have an interest and understanding of Blockchain and AI technologies
***************** Empowered to think big. Try new opportunities while working with a talented, ambitious and supportive team.Transformational and proactive working environment. Empower employees to find thoughtful and innovative solutions.Growth from within. We help to develop new skill-sets that would impact the shaping of your personal and professional growth.Work Culture. Our colleagues are some of the best in the industry; we are all here to help and support one another.One cohesive team. Engage stakeholders to achieve our ultimate goal - Cryptocurrency in every wallet. Work Flexibility Adoption. Flexi-work hour and hybrid or remote set-up Aspire career alternatives through us - our internal mobility program offers employees a new scope.
Are you ready to kickstart your future with us?
BenefitsCompetitive salary Attractive annual leave entitlement including: birthday, work anniversary 401(k) plan with employer match Eligible for company-sponsored group health, dental, vision, and life/disability insurance Work Flexibility Adoption. Flexi-work hour and hybrid or remote set-up Aspire career alternatives through us. Our internal mobility program can offer employees a diverse scope.
Our Crypto.com benefits packages vary depending on region requirements, you can learn more from our talent acquisition team.
About Crypto.com:Founded in 2016, Crypto.com serves more than 150 million customers and is the world's fastest growing global cryptocurrency platform. Our vision is simple: Cryptocurrency in Every Wallet™. Built on a foundation of security, privacy, and compliance, Crypto.com is committed to accelerating the adoption of cryptocurrency through innovation and empowering the next generation of builders, creators, and entrepreneurs to develop a fairer and more equitable digital ecosystem.
Learn more at *******************
Crypto.com is an equal opportunities employer and we are committed to creating an environment where opportunities are presented to everyone in a fair and transparent way. Crypto.com values diversity and inclusion, seeking candidates with a variety of backgrounds, perspectives, and skills that complement and strengthen our team.
Personal data provided by applicants will be used for recruitment purposes only.
Please note that only shortlisted candidates will be contacted.
$81k-120k yearly est. Auto-Apply 13d ago
Information Security Analyst 2
Primerica Inc. 4.6
Duluth, GA jobs
Join Our Team In 2025, USA Today recognized Primerica as a Top Workplace USA for the fifth year in a row, and Newsweek named Primerica one of America's Greatest Workplaces for Diversity for the second consecutive year. In 2024, the Atlanta Journal-Constitution named Primerica as a Top Workplace for the eleventh consecutive year, and Forbes recognized Primerica as one of America's Best Employers for Women for the fifth year in a row. In addition, for the tenth time Primerica has been voted a Best Employer by Gwinnett Magazine. Primerica is a great place to work! Join our team to experience what it's like to work at "one of the best places to work in the metro Atlanta".
About this Position
The InformationSecurity Engineering Analyst is an integral part of the IS Engineering team. This position will lead security efforts to design, implement, administer, and support informationsecurity technologies and processes that will ensure data and systems are adequately protected. It requires performing a broad range of security duties requiring a working knowledge of cyber security and several supporting technologies. The Analyst will work with project teams to define security requirements for programs, applications, processes, and new platform systems in line with the enterprise informationsecurity architecture.
Responsibilities & Qualifications
* Support and manage security infrastructure, including but not limited to; Proxies, NextGen Firewalls, IDS/IPS, SIEM, Sandboxing technologies, APT solution, etc.
* Participate in Vulnerability and Threat Management program
* Perform root cause analysis on security incidents
* Apply effective communication to translate complex technical security deficiencies into business risks that are understood by business stakeholders when making decisions for future security investments
* Use an informationsecurity architecture framework and methodology to enable reuse of informationsecurity components across the enterprise
* Assist proof-of-concept activities for innovation initiatives to ensure coverage of informationsecurity requirements
* Perform additional security-related duties as requested
* Bachelor's degree in Computer Science, Information Systems, CyberSecurity, or 2-3 years related experience
* CISSP or other Security Certifications are preferred, or willing to obtain
* Experience with SIEM technologies, including development
* Experience with Host based Security controls
* Experience in the vulnerability assessment lifecycle from the point of identification to remediation including penetration testing and source code analysis tools
* Ability to research, analyze and resolve complex problems with minimal supervision and escalate issues as appropriate
* Able to work independently and be a self-starter; managing multiple tasks according to priorities; results oriented and proven ability to meet deadlines
Hybrid role
Location: Atlanta, GA
FLSA status:
This position is exempt (not eligible for overtime pay):
Yes
Our Benefits:
* Day one health, dental, and vision insurance
* 401(k) Plan with competitive employer match
* Vacation, sick, holiday and volunteer time off
* Life and disability insurance
* Flexible Spending Account & Health Savings Account
* Professional development
* Tuition reimbursement
* Company-sponsored social and philanthropy events
It has been and will continue to be the policy of Primerica, Inc., and its subsidiaries to be an Equal Opportunity Employer. We provide equal opportunity to all qualified individuals regardless of race, sex, color, religious creed, religion, national origin, citizenship status, age, disability, pregnancy, ancestry, military service or veteran status, genetic or carrier status, marital status, sexual orientation, or any classification protected by applicable federal, state or local laws.
At Primerica, we believe that diversity and inclusion are critical to our future and our mission - creating a foundation for a creative workplace that leads to innovation, growth, and profitability. Through a variety of programs and initiatives, we invest in each employee, seeking to ensure that our people are not only respected as individuals, but also truly valued for their unique perspectives.
$66k-93k yearly est. Auto-Apply 46d ago
Information Security Analyst 2
Primerica 4.6
Duluth, GA jobs
Join Our Team
In 2025, USA Today recognized Primerica as a Top Workplace USA for the fifth year in a row, and Newsweek named Primerica one of America's Greatest Workplaces for Diversity for the second consecutive year. In 2024, the Atlanta Journal-Constitution named Primerica as a Top Workplace for the eleventh consecutive year, and Forbes recognized Primerica as one of America's Best Employers for Women for the fifth year in a row. In addition, for the tenth time Primerica has been voted a Best Employer by Gwinnett Magazine. Primerica is a great place to work! Join our team to experience what it's like to work at “one of the best places to work in the metro Atlanta”.
About this PositionThe InformationSecurity Engineering Analyst is an integral part of the IS Engineering team. This position will lead security efforts to design, implement, administer, and support informationsecurity technologies and processes that will ensure data and systems are adequately protected. It requires performing a broad range of security duties requiring a working knowledge of cyber security and several supporting technologies. The Analyst will work with project teams to define security requirements for programs, applications, processes, and new platform systems in line with the enterprise informationsecurity architecture. Responsibilities & Qualifications
Support and manage security infrastructure, including but not limited to; Proxies, NextGen Firewalls, IDS/IPS, SIEM, Sandboxing technologies, APT solution, etc.
Participate in Vulnerability and Threat Management program
Perform root cause analysis on security incidents
Apply effective communication to translate complex technical security deficiencies into business risks that are understood by business stakeholders when making decisions for future security investments
Use an informationsecurity architecture framework and methodology to enable reuse of informationsecurity components across the enterprise
Assist proof-of-concept activities for innovation initiatives to ensure coverage of informationsecurity requirements
Perform additional security-related duties as requested
Bachelor's degree in Computer Science, Information Systems, CyberSecurity, or 2-3 years related experience
CISSP or other Security Certifications are preferred, or willing to obtain
Experience with SIEM technologies, including development
Experience with Host based Security controls
Experience in the vulnerability assessment lifecycle from the point of identification to remediation including penetration testing and source code analysis tools
Ability to research, analyze and resolve complex problems with minimal supervision and escalate issues as appropriate
Able to work independently and be a self-starter; managing multiple tasks according to priorities; results oriented and proven ability to meet deadlines
Hybrid role
Location: Atlanta, GA
FLSA status:
This position is exempt (not eligible for overtime pay):
YesOur Benefits:
Day one health, dental, and vision insurance
401(k) Plan with competitive employer match
Vacation, sick, holiday and volunteer time off
Life and disability insurance
Flexible Spending Account & Health Savings Account
Professional development
Tuition reimbursement
Company-sponsored social and philanthropy events
It has been and will continue to be the policy of Primerica, Inc., and its subsidiaries to be an Equal Opportunity Employer. We provide equal opportunity to all qualified individuals regardless of race, sex, color, religious creed, religion, national origin, citizenship status, age, disability, pregnancy, ancestry, military service or veteran status, genetic or carrier status, marital status, sexual orientation, or any classification protected by applicable federal, state or local laws.
At Primerica, we believe that diversity and inclusion are critical to our future and our mission - creating a foundation for a creative workplace that leads to innovation, growth, and profitability. Through a variety of programs and initiatives, we invest in each employee, seeking to ensure that our people are not only respected as individuals, but also truly valued for their unique perspectives.