About The Position

The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts assessments, and ongoing finding remediation of third parties supporting Capital One. We are seeking a highly organized, analytical, and proactive CTRPP Operations Lead to oversee the day-to-day execution and continuous improvement of our third-party risk management lifecycle. In this role, you will bridge the gap between risk strategy and operational execution. You will lead the team responsible for the identification, documentation, reporting, and mitigation of realized cybersecurity risk through contracting, ongoing monitoring and risk remediation, ensuring that third-party relationships comply with internal policies and external regulatory requirements. The ideal candidate thrives on optimizing workflows, translating complex data into actionable metrics, and collaborating with cross-functional stakeholders across legal, procurement, information security, and business units.

Requirements

  • High School Diploma, GED, or equivalent certification
  • At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management
  • At least 3 years of experience in IT Operations Management

Nice To Haves

  • Bachelor’s Degree
  • CTPRP, CISSP, CISA, or CRISC certification
  • 5+ years of experience in IT Operations Management
  • 5+ years of experience at a Financial Institution

Responsibilities

  • Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring.
  • Serve as the primary escalation point for complex risk assessments, vendor disputes, or critical remediation issues.
  • Supervise and mentor a team of risk analysts, ensuring data accuracy, consistency in risk evaluations, and adherence to established Service Level Agreements (SLAs).
  • Design, generate, and maintain operational dashboards, Key Performance Indicators (KPIs), and Key Risk Indicators (KRIs) for executive leadership.
  • Monitor third-party compliance with remediation plans, tracking open findings to resolution and escalating past-due risks.
  • Support internal and external audits, examinations, and regulatory inquiries by providing necessary CTRPP documentation and evidence.
  • Partner closely with Procurement, Legal, InfoSec, and Privacy teams to ensure a seamless and unified approach to third-party oversight.
  • Provide guidance and training to internal business owners on their responsibilities regarding third-party risk and compliance.
  • Participating in on site assessments of third parties during more focused reviews
  • Participate or lead ad hoc requests of the program
  • Participate with broader program enhancements and ongoing development activity
  • Willing to jump in to support any of the program functions when needs arise

Benefits

  • performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
  • comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service