Website Capital One
This role offers growth opportunities across many disciplines as the right candidate will be able to present, influence, educate, enable, and collaborate with application teams and varying levels of leadership across the organization in defining, improving, and maintaining their applications’ threat models.
- Partner with other functions in Cyber to enable those functions to consume threat models to drive greater value from threat modeling across Cyber
- Evolve the practice of threat modeling in Capital One, and fully integrate threat modeling with Risk Management practices and Software Development Life Cycle processes.
- Develop and execute governance for threat modeling and provide reporting of compliance and adoption
- Develop and execute data driven controls and reporting, and drive outcomes into the teams that need to take action.
- Support our customers in adopting and using the threat modeling tools we deliver for the business. Provide documentation to aid our customers in using those tools, and establish process and governance for the use of those tools.
- Integrate threat modeling into organizational Risk Management practices
- Play a key role in Cyber security and risk management processes and a broad view of Cyber security risk frameworks (NIST, ISO, COBIT) that you can tap to help us to align the threat modeling program to the broader risk management practices at Capital One
- Work with the customers and stakeholders of the threat modeling program, feedback on our work and strive to use that feedback to improve the delivery for the team and yourself.
- Work with the Program leadership to present information and influence change at senior management level.
- Identify and implement process improvements for the work through KPIs and OKRs.
- Plan and deliver work with the team through Agile and Scrum practices to provide visibility and transparency.
- Produce educational training materials, whitepapers and blog posts that support the adoption of threat modeling by associates across the business
- 1+ years of experience in developing dashboards and performance reporting
- At least 3 years of experience in a Security Operations or Risk or Process and Operations role
- 1+ years financial services industry experience
- 1+ years of experience with cyber risk frameworks (CIS-RAM, NIST)
- At least 2 years of experience with Cloud technologies (Amazon Web Services, Microsoft Azure, Google Cloud Platform)
- 1+ years of experience utilizing Agile methodologies
- 1+ years of experience with producing educational and training materials
- 1+ years of experience with developing Standards and Procedures
- At least 4 years of Information Technology or Cybersecurity experience
- 1+ years of experience with Threat Modeling methodologies
- 1+ years experience in Offensive or Defensive Security techniques
- High School Diploma, GED, or equivalent certification
Company: Capital One
Vacancy Type: Full Time
Job Location: McLean, VA, US
Application Deadline: N/A