Cyber Engineer - ISO Assurance
Capital One Nottingham, United Kingdom
Apply now Posted 1 month ago Permanent CompetitiveNottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire
About the Role
Capital One is one of the fastest growing organizations in the world today. The growth of the business is being accelerated by leveraging innovative and emerging technologies. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years, fully exiting our data centers. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity and managing technology risk. Cybersecurity Risk professionals at Capital One are trusted expert advisers who shape decisions, challenge activities to ensure they meet our standards, and generally oversee technology, cybersecurity, and information security risk across the business and the central technology organisation.
What You'll Do
- Ensure consistency and develop data-driven assurance practices that will facilitate deeper technical risk reviews in order to support strategic decision-making for Cyber and Technology leadership.
- Take the lead in evaluating and recommending standardized risk sloping & scoring methods across Tech and Cyber domains, including Vulnerability Management, Data Security, and Network Security across the enterprise.
- Serve as a point of contact for ISO Assurance Team service offerings and assist with onboarding junior team members.
- Standardize the review of mitigating factors and controls in support of risk management activities so that technology and business teams can prioritize risk reduction activities in order to allow teams to focus on the areas of the greatest impact.
- Work cross-functionally with Advisory, Assessment, and Risk Operations functions within the Information Security Office to measure cybersecurity and technology risk.
- Act as a key contributor to the Information Security Office leadership team on senior leader initiatives, providing insights and recommendations.
- Demonstrate a strong understanding of Capital One's Information Security offerings, policies, procedures and standards.
- Collaborate effectively with colleagues, stakeholders, and leaders across multiple organizations to achieve strategic objectives.
- Effectively communicate findings and recommendations across varying levels of leadership, with an ability to influence stakeholders.
What we're looking for- Experience working in cybersecurity or information technology.
- Experience providing guidance and oversight of cyber security concepts.
- Experience performing security risk assessments and security architecture reviews.
- Knowledge of Agile methodologies.
- Professional certifications such as AWS Cloud Practitioner, CompTIA Security+.
Where and how you'll workThis is a permanent position that will be based in our Nottingham Head Office.
We have a hybrid working model, so you'll be based in our office 3 days a week on Tuesdays, Wednesdays and Thursdays, and can work from home on Monday and Friday.
What's in it for you- Bring us all this - and you'll be well rewarded with a role contributing to the roadmap of an organisation committed to transformation.
- We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers).
- Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance - with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave.
- Open-plan workspaces and accessible facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms.
Capital One is committed to diversity in the workplace.If you require a reasonable adjustment, please contact ukrecruitment@capitalone.com. All information will be kept confidential and will only be used for the purpose of applying a reasonable adjustment.