Manager, Tech Risk & Analysis (International and Regulatory Risk)

Capital One•McLean, VA
•$149,800 - $205,100

About The Position

Capital One is a rapidly growing organization that leverages innovative technologies to accelerate business growth. The company prioritizes cybersecurity and technology risk management alongside technological innovation. Technology & Data Risk Management (TDRM) is a key organization within Capital One, comprising approximately 200 professionals who oversee around 14,000 developers. TDRM is responsible for setting high standards in cybersecurity, reliability, tech risk, and data management, influencing strategy, challenging activities, and conducting independent tests. In regulated financial services, a dual CISO structure is employed: a first-line CISO with operational responsibilities reporting to the CIO, and a second-line Chief Tech Risk Officer (CTRO) overseeing broader responsibilities including cybersecurity, reliability, software quality, resilience, and data risk. The CTRO is independent, oversees the CISO and CIO/CTO, and reports to the Chief Risk Officer, who reports to the CEO. TDRM provides business leaders with essential tech and data risk information for informed decision-making. Associates in TDRM are skilled professionals in information security, cybersecurity, site reliability engineering, technology, data analysis, data science, and risk management, known for their experience and ability to deliver high-impact results. As a Manager on the International and Regulatory Risk team, the role involves managing TDRM’s involvement in international risk workstreams, coordinating subject matter experts to evaluate and advise on first-line proposals for international risk management, and assisting with audit and regulatory preparations and responses. Success requires a strong understanding of technology, information security, and data requirements, with the ability to translate complex technical practices and business objectives into clear, persuasive, and compliant risk documentation. The ideal candidate is a critical thinker, intellectually curious, and possesses strong stakeholder management skills.

Requirements

  • Bachelor's Degree or military experience
  • At least 5 years of experience in technology (software delivery, distributed systems, cloud-native architecture, infrastructure as code), cybersecurity (identity and access management, application security, cloud security, data protection), technology auditing, systems risk management, technology risk assessments, resilience engineering (operational resilience, business continuity, disaster recovery, high availability), chaos engineering (fault injection, blast radius mitigation, automated security validation), site reliability engineering (SLAs or SLOs, observability, incident response), or a combination.

Nice To Haves

  • Master’s degree
  • 5+ years of experience in a second-line or oversight role at a financial institution or regulatory agency
  • 2+ years working in cybersecurity, technology, or risk management with international scope
  • Professional Security Certification or Professional Risk Management Certification (Certified Information Systems Security Professional (CISSP), or Certified Information Systems Auditor (CISA), or Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), or Open FAIR Certified)
  • Knowledge of, or experience working with agile methodology and tools (Jira or Confluence)
  • Knowledge of National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
  • Knowledge of payment networks or international technology, information security, or data management risk at a financial institution

Responsibilities

  • Design and manage a centralized process for technology, information security, and data international risk advisory requests
  • Participate in country risk assessments and advise on technology, information security, and data solutions to risk exposure for jurisdictions
  • Act as the primary liaison between TDRM and other stakeholder organizations (Legal, Compliance, other risk organizations, etc.) to ensure a unified international risk perspective for technology, information security, and data
  • Work with subject matter experts to develop TDRM’s international risk assessments to support country-level tech, cyber, and data risk decisions.
  • Coordinate TDRM’s risk advisory and challenge to first-line partners on remediation plans for audit findings and regulatory issues.
  • Support and maintain an up-to-date library of standardized responses to technology, information security, and data audit and regulatory questions.
  • Support the development of responses to regulatory inquiries, exams, and independent audits across multiple jurisdictions.

Benefits

  • comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service