Senior Manager, Risk Advisor, Technology and Data Risk Management

Capital OneMcLean, VA
$182,500 - $249,900

About The Position

Capital One is a rapidly growing organization focused on customer passion and technological innovation. We are committed to cybersecurity, reliability, software quality, and data management. The Technology & Data Risk Management (TDRM) organization, comprising approximately 200 professionals, plays a crucial role in overseeing around 14,000 developers. TDRM sets high standards for cybersecurity, reliability, tech risk, and data management risk, influencing strategy, challenging activities, and conducting independent tests. In the financial services industry, a dual reporting structure for cybersecurity is essential: a first-line CISO with operational responsibilities reporting to the CIO, and a second-line Chief Tech Risk Officer (CTRO) and TDRM organization with broader responsibilities for cybersecurity, reliability, software quality, resilience, and data risk management. The CTRO is independent, oversees the CISO and CIO/CTO, and reports to the Chief Risk Officer, who reports directly to the CEO. TDRM ensures business leaders have the necessary tech and data risk information for informed decision-making. TDRM associates are highly skilled professionals in information security, cybersecurity, site reliability engineering, technology, data analysis, data science, and risk management, bringing extensive experience and delivering high-impact results. This specific role, Senior Manager, Cyber Risk and Analysis, is pivotal in shaping the second line's independent perspective on cybersecurity, reliability, and tech risk, with a focus on emerging technologies and risks. It involves analyzing the outcomes of first-line assessments to enable robust challenge, leading independent risk analysis workshops, applying quantitative and qualitative risk assessment methodologies, understanding control stacks, identifying risk reduction strategies, and systematically reviewing and analyzing assessment outputs. The role will influence the first line to drive the definition and prioritization of high-leverage risk reduction initiatives. Key responsibilities include providing expert guidance and mentorship within TDRM, fostering strong relationships with other first and second-line groups, and navigating the Enterprise Risk Management framework. As part of a growing organization, the candidate will help shape and refine the risk program, operating with autonomy and empowerment from senior leadership. The ideal candidate is a seasoned leader with practical knowledge of risk frameworks and assessment methodologies for technology/cyber risk, strategic thinking, data-driven decision-making, intellectual curiosity, and a drive for change.

Requirements

  • Bachelor’s degree or military experience
  • At least 6 years of experience managing, consulting, or auditing in the fields of risk management, information security or technology
  • At least 5 years of experience performing or challenging risk assessments leveraging qualitative and quantitative methodologies (COSO Framework, quantitative analysis, Factor Analysis Information Risk (FAIR), Process, Risk & Control (PRC) library, Risk and Control Self Assessment (RCSA), scenario analysis, new initiative risk assessments)
  • Professional security management certification (Open FAIR, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC))

Nice To Haves

  • Master’s degree in Information Technology, Cybersecurity, or equivalent
  • 5+ years of experience communicating and presenting data to both technical and non-technical audiences
  • 5+ years of experience applying risk quantification methodologies and rolling out risk framework changes
  • 4+ years of experience interacting with different stakeholders and leaders across multiple organizations
  • 4+ years of experience in a second-line or oversight role at a financial institution or regulatory agency
  • Experience implementing risk and controls framework for GenAI or other emerging technologies and risks.

Responsibilities

  • Understand new guardrails and guidelines related to emerging technology and risks, and establish systems to iteratively include them in routine risk assessments.
  • Review and challenge first line periodic and change-driven risk assessments, including risk sizing, control suite adequacy and mitigation plan relevance.
  • Prepare executive reports summarizing TDRM’s point of view on cyber and technology risks.
  • Research industry trends and internal data to substantiate risk management decisions and make recommendations.
  • Scope and facilitate cross-functional risk workshops and document the conclusions to influence 1st line’s risk framing.
  • Foster a collaborative relationship with stakeholders across 1st and 2nd line.
  • Develop and implement plans to orchestrate the operational rollout of risk methodology changes.

Benefits

  • comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service