Senior Risk Specialist, Tech Risk | Retail Bank

Capital OneMcLean, VA
$111,200 - $126,900Onsite

About The Position

As a Principal Associate of Tech & Cyber Risk within Capital One’s Business Risk Office, you will enable and drive end-to-end risk management of the portfolio by partnering directly with risk partners, technology stakeholders, operations and engineering teams to identify, assess, and mitigate technology and cyber risks. In this high-impact role, as a practices partner, you will leverage your strong project management, communication, and analytical skills to support cutting-edge technology initiatives and promote strategic risk management across the organization. You will be hands-on in evaluating and mitigating risks related to AI implementations, supporting the technology integration of acquired companies, and monitoring risk posture within large-scale architecture transformation programs. By overseeing portfolio health, remediation efforts, tracking key metrics and performing assessments you will help teams proactively align with enterprise policies, ensuring the ongoing resilience and security of our technology ecosystem.

Requirements

  • Bachelor’s Degree or military experience
  • At least 2 years of experience in technology (software delivery, distributed systems, cloud-native architecture, infrastructure as code), cybersecurity (identity and access management, application security, cloud security, data protection), technology auditing, systems risk management, technology risk assessments, resilience engineering (operational resilience, business continuity, disaster recovery, high availability), chaos engineering (fault injection, blast radius mitigation, automated security validation), site reliability engineering (SLAs/SLOs, observability, incident response), or a combination

Nice To Haves

  • Master’s Degree in Information Technology, Cybersecurity, or equivalent
  • 2+ years of Risk Management experience in Cyber or Information Security practice
  • 2+ years of experience in cloud computing (AWS, GCP, or Azure)
  • 2+ years of experience in a second-line or oversight role at a financial institution or regulatory agency
  • Professional Security Certification or Professional Risk Management Certification
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Open FAIR Certified

Responsibilities

  • Drive end-to-end technology and cyber risk assessments, managing the lifecycle from tactical implementation and ongoing evaluation through to remediation tracking and successful risk finding closure.
  • Support the responsible implementation of AI applications and large-scale architecture transformations by conducting timely risk assessments and ensuring project teams align with well managed best practices and enterprise risk frameworks.
  • Utilize strong project management skills to effectively prioritize risk initiatives, ensuring clear project scope and the timely delivery of impactful results.
  • Exhibit outstanding communication skills to build and manage strong stakeholder relationships across engineering, operations, cyber, risk functions, keeping all levels and lines of defense informed and influencing outcomes to drive project success.
  • Display strong advisory skills to guide risk and engineering partners through complex risk landscapes, adapting with agility to changing business demands and evolving technology environments.
  • Drive continuous improvement within the Tech & Cyber Risk Office by identifying, designing, and implementing enhancements to streamline risk identification, assessment, and mitigation workflows.
  • Monitor and analyze key risk metrics and dashboards, partnering closely with stakeholders to oversee remediation efforts and drive metrics toward target compliance levels.
  • Assist in preparing accurate compliance documentation and data for audit engagements, ensuring the overall tech risk posture is transparent and well-documented.
  • Lead and facilitate recurring risk forums (e.g., Metrics reviews) to ensure progress visibility and stakeholder alignment.
  • Proactively own and drive RCSA (risk and control self assessment) workflows, acting as a lead or delegate to improve operational efficiency and risk coverage.
  • Develop and manage comprehensive risk measurement frameworks (KRI/metrics), ensuring actionable data-driven insights are communicated to senior leadership.

Benefits

  • comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being
  • performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service