Senior Lead Information Security Office (ISO) Consultant
You will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate.
Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
- Act as a central Information Security point of contact for the Commercial line of business
- Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
- Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
- Collaborating with enterprise cyber teams and tech architects in defining and driving the cyber architecture strategy and guiding principles for the architecting and designing of the modern platforms
- Support security architecture and implementation needs for technology modernization efforts
- Overseeing all cyber related dependencies across the multiple components being built for the modernization effort
- Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
- Escalate and manage cyber security risk
- Provide ad hoc support on special Information Security hot topics for the business
- Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
- Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
- Support the team on collectively mapping technologies to a standardized framework in order to identify and execute on best practices in risk reduction through the configuration of cybersecurity tools and platforms
- Support the development, modification, and use of capability, risk, or threat classification frameworks and standardization methodologies to facilitate the conduct of correlative capability, maturity, and effectiveness evaluations
- Support data validation and communications on the impact of identified operational, compliance, process, control, and tooling gaps and potential remediation courses of action to multiple audiences, including leadership, to support the enhancement of their cybersecurity postures
About You:
- You have a desire to work in a very fast moving, forward leaning, and modern computing environment
- You have a deep passion for Securing modern computing platforms
- You have a strong desire to continually learn about new technologies
- You possess strong conceptual thinking and communication skills
- You are able to work well under minimal supervision
- You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
- You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
- You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
- High School Diploma, GED or equivalent certification
- At least 6 years of experience working in cybersecurity or information technology
- At least 5 years of experience providing guidance and oversight of cyber security concepts
- At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
- At least 4 years of experience with cloud security
- At least 2 years of experience in Cyber Technical Program Management
- At least 3 years of experience in Cyber Risk Management
Preferred Qualifications:
- Bachelor's Degree
- 7+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
- Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)