Risk Manager - Vulnerability Management (cyber Technical)

Capitalonecareers

McLean, VA, US
Base: $179,400 - $245,600 depending on location; b...
Vulnerability management tools (qualys, nessus)
Application security scanners (dast, sast, iast)
Container vulnerability management (kubernetes, ecs)
This position represents a unique opportunity to combine hands-on technical and operational experience with a risk-based and strategic outlook to provide effective oversight of enterprise Vulnerability Management, Application Security, and Configuration Management capabilities

Job Summary

  • This position represents a unique opportunity to combine hands-on technical and operational experience with a risk-based and strategic outlook to provide effective oversight of enterprise Vulnerability Management, Application Security, and Configuration Management capabilities.
  • As part of the second line of defense, this position collaborates closely with first line Cyber, Technology, and Lines of Business to evaluate the effectiveness of the firm’s controls infrastructure and offer independent advice to mature cyber risk management capabilities.
  • Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being.

Matching Summary

This position represents a unique opportunity to combine hands-on technical and operational experience with a risk-based and strategic outlook to provide effective oversight of enterprise Vulnerability Management, Application Security, and Configuration Management capabilities.

Salary

Base: $179,400 - $245,600 depending on location; Bonus/Equity: Performance based incentive compensation including cash bonuses and/or long term incentives; Benefits: Comprehensive health, financial and other benefits

Skills & Requirements

Must-have

  • Vulnerability Management tools (Qualys, Nessus)
  • Application Security scanners (DAST, SAST, IAST)
  • Container vulnerability management (Kubernetes, ECS)
  • Cyber risk assessments
  • Configuration Management tools (Solarwinds, Tenable)
  • Cybersecurity controls design and effectiveness

Nice-to-have

  • Red Team/penetration testing experience
  • Familiarity with cybersecurity control frameworks
  • Experience with agile software development
  • Strong communication and mentoring skills
  • Collaboration across multiple organizations
  • Execution oriented and self-motivated

Key Requirements

  • Bachelor’s degree or military experience
  • At least 3 years experience with enterprise-grade VM/AppSec/CM tools
  • At least 3 years experience with container vulnerability management
  • At least 3 years experience in information security or related fields
  • At least 2 years experience drafting senior management reports
  • At least 2 years experience with open source software
  • At least 1 year experience with Public Cloud implementations
  • Professional security management certification preferred
  • Master’s Degree preferred
  • Experience in financial services or regulated sector preferred
  • 1+ year experience building LLM integrated applications
  • 2+ years experience with agile development and APIs

Work Rights

Must have valid US work authorization; Capital One will not sponsor new applicants

Tailored Resume

Cover Letter