Capital One
Hybrid
https://ad.doubleclick.net/ddm/clk/576968427;385924738;m?https://www.capitalonecareers.com/tech?source=rd_builtin_job_posting_tm&utm_source=builtin.com&utm_medium=job_posting&utm_campaign=Tech&utm_content=niche_site&utm_term=385924738&ss=paid

Manager, Security Testing

Sorry, this job was removed at 7:22 p.m. (CST) on Saturday, February 12, 2022
Find out who's hiring in Washington DC.
See all Cybersecurity + IT jobs in Washington DC
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Center 2 (19050), United States of America, McLean, Virginia

Manager, Security Testing

Technology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology risk activities. The Associates that make up the TRM team are highly-skilled information security, cyber, technology, and risk management professionals who bring a wealth of experience to deliver high-impact analysis and recommendations that are rooted in direct knowledge of security and technology. 

 

Manager, Security Testing, Technology Risk Management – will play a key role in the execution of technical testing to support technology risk identification, risk assessment, reporting, and effective challenge of processes, controls, and capabilities, including but not limited to material and high risk technology changes. This individual will provide subject matter expertise of key technology areas such as cybersecurity, cloud services, enterprise architecture, cloud migrations, and overall technology deployments. As part of the second line of defense, this position will also interact regularly with first line Cyber, Technology, the Lines of Business, as well as other second line of defense risk management offices to perform and support targeted technical reviews of the effectiveness of the firm’s controls infrastructure and offer independent advice and recommendations regarding ways to further mature the firm’s cyber risk management capabilities.

Essential Functions (Responsibilities):

  • Develop technical test plans and use cases in conjunction with offensive security, cyber chaos engineering, and other technology functions to test a risk hypotheses 

  • Work closely with Offensive Security and Cyber Chaos Engineering to perform technical risk analysis of findings from penetration testing, red team operations, and other technical tests

  • Review technology controls testing reports and plans for relevant technical information to inform risk based testing

  • Leverage cybersecurity testing techniques to conduct technical and non-technical risk based tests against applications, cloud infrastructure, APIs, databases, network, and devices to support risk hypotheses

  • Draft and publish technical reports for risk owners, senior management, and other stakeholders regarding risks associated with new or emerging technologies

  • Provide technical expertise in assessing the practices of designing, developing, testing and implementing cloud native solutions to crucial business problems through thoughtful use of industry best practices and Capital One policy 

  • Evaluate proposed and approved cloud technical solutions for automation, resiliency, performance, scalability, and security including appropriate tradeoffs, risks and opportunities

  • Keep up-to-date on cutting edge technology, standards, protocols and tools in areas relevant to the rapidly changing environment at Capital One, specifically cloud native architecture, serverless, and emerging AWS services

  • Demonstrate strong analytical, problem-solving, and decision-making skills

  • Consult with risk owners on the design and implementation or adjustment of mitigating controls associated with emerging technologies

Basic Qualifications:

  • High School Diploma, GED or equivalent certification, or military experience

  • At least 1 year of Software Quality Assurance Testing experience

  • At least 1 year of experience developing and or writing technical testing plans 

  • At least 1 year of experience working with data lake and data warehouse technologies

  • At least 2 years of experience developing and exploiting Application Programming Interfaces (APIs)

  • At least 2 years of experience working with cloud technologies such as AWS, Azure, Google

  • At least 2 years of experience working with serverless architectures such as AWS Lambda, Google Functions, Azure Functions

  • At least 2 years of experience exploiting web applications

  • At least 2 years of experience in penetration testing or red team operations

  • One or more of the following professional certifications: Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), Offensive Security Experienced Penetration Tester (OSEP), GIAC Cloud Penetration Testing (GCPN)

Preferred Qualifications:

  • Master’s Degree in computer engineering, cyber security, informatics, or other technical field

  • One or more of the following professional certifications: AWS Certified Cloud Practitioner, AWS Solutions Architect - Associate, AWS Certified Security Specialty, ISC2 Certified Cloud Security Professional (CCSP), or similar cloud security certifications

  • Prior experience with cloud security and or penetration testing (cloud-native applications, cloud service abuse, deployment pipelines, etc.) 

  • Prior experience working in financial services or other highly-regulated sectors

  • At least 3 years of hands-on experience executing cyber security operations such as incident response, vulnerability management, threat intelligence, identity and access management, or cloud security.

  • At least 3 years of experience identifying and communicating key risks related to cloud native implementations and architectures

  • At least 2 years experience with controls and control frameworks (e.g. NIST Cybersecurity Framework, NIST 800-53, CIS Top 20, ISO, or COBIT.)

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

No agencies please. Capital One is an Equal Opportunity Employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex, race, color, age, national origin, religion, physical and mental disability, genetic information, marital status, sexual orientation, gender identity/assignment, citizenship, pregnancy or maternity, protected veteran status, or any other status prohibited by applicable national, federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at [email protected]. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to [email protected]

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Capital One Perks + Benefits

Capital One Benefits Overview

At Capital One, we're committed to ensuring you and your family feel supported and cared for, and we know that your benefits play a large role in that support. Our goal is to provide a comprehensive and competitive set of benefits that offer the flexibility and choice to meet the diverse needs of all associates. We want each of you to Be Well physically, emotionally, and financially.

Culture
Volunteer in local community
Volunteer projects are encouraged and supported by Capital One through both traditional monetary contributions and flexibility to participate in associate-led initiatives.
Partners with nonprofits
Capital One’s philanthropy program provides grants to organizations that support education, financial literacy and community development, including affordable housing and small business development.
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Mean gender pay gap below 10%
Diversity employee resource groups
Business Resource Groups (BRGs) play an important role in attracting world-class talent, developing tomorrow’s leaders, engaging and retaining our diverse workforce and enhancing our workplace.
Hiring practices that promote diversity
Our professional recruiting teams focus on attracting underrepresented talent for our key business roles, including analyst, product, and tech roles across varied tactics and connection points.
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Capital One offers two flexible spending accounts (FSAs) – a Health Care FSA and Dependent Care FSA – administered by Anthem.
Disability insurance
Capital One automatically provides full-time associates with Short-Term Disability and Basic Long-Term Disability coverage at no cost. You have the option to purchase Supplemental Long-Term Disability
Dental insurance
Capital One offers coverage through Delta Dental to help you maintain your smile through regular preventive care and treatment for any dental problems that may arise.
Vision insurance
To help you keep life in focus, vision coverage through Anthem Blue View Vision provides benefits for eye exams and vision correction treatment.
Health insurance
Our medical plans provide comprehensive and affordable coverage for a range of health care services and are designed with the ability to be flexible and choose which benefits work for your needs.
Life insurance
We provide full-time and eligible part-time associates with Basic Life, and Accidental Death and Personal Loss (AD&PL) Insurance at no cost.
Wellness programs
Mental health benefits
Capital One's Employee Assistance Program provides a robust set of services including telephonic, virtual and/or face-to-face counseling, legal and financial assistance, ID theft recovery, and more.
Financial & Retirement
401(K)
Through automatic payroll deductions, you may contribute up to 50% of your Annual Benefits Salary (base salary, shift differential, bonuses, commission, incentives and overtime) to your account.
401(K) matching
Capital One will match 100% of the first 3% of Annual Benefits Salary that you contribute, plus 50% of the next 3% of Annual Benefits Salary that you contribute.
Employee stock purchase plan
You can elect to contribute between 1% and 15% of your base salary** to the ASPP and receive a partial match on your contributions from Capital One. **Includes standard pay and any commissions
Charitable contribution matching
Child Care & Parental Leave Benefits
Childcare benefits
The Bright Horizons Care Advantage Program provides alternative child and adult care options during a lapse or breakdown in normal care arrangements.
Generous parental leave
Flexible parental leave options are available to full-time associates at the time of their child’s birth or arrival in their home.
Family medical leave
Adoption Assistance
The Adoption Reimbursement program provides financial support to full-time associates who are building their families through adoption.
Vacation & Time Off Benefits
Generous PTO
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Some meals provided
Company-sponsored happy hours
Onsite office parking
Recreational clubs
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Onsite gym
Professional Development Benefits
Job training & conferences
Tuition reimbursement
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications

Additional Perks + Benefits

Capital One’s perks and benefits are progressive and industry leading. We have always believed in the importance of providing comprehensive and expansive benefits to complement and contribute to our associates’ total compensation package. For example, we were one of the first major companies to offer same-sex marriage benefits back in 1997 and we have since continued to build our benefits portfolio to include a host of other LGBTQ+ friendly offerings, from fertility coverage to reimbursements for associates who chose to build their families through adoption and surrogacy, to domestic partner benefits and health coverage for gender reassignment. In addition, Capital One’s campuses offer fitness facilities, cafés and, at certain locations, onsite health services for associates and their families. Our benefits package is unique as it provides flexibility for you to determine your path to health, wealth and life support.

More Jobs at Capital One

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Capital OneFind similar jobs like this