Manager, Technology Controls Testing (ES Risk)

McLean, VA, United States

Capital One

You’re tenacious and driven, so the last place you want to work is some boring bank. Same. Learn about careers at Capital One and view jobs here.

View all jobs at Capital One

Apply now Apply later

Manager, Technology Controls Testing (ES Risk)

As a Manager in Capital One’s Enterprise Services (ES) Core Risk, you will apply your risk management skills to the company’s Technology organization. You will partner across Enterprise Services, Divisional CIO, and Information Security teams to develop and support best-in-class industry risk solutions in a manner that supports innovation and protects our customers, shareholders and associates. As a member of the 1st line controls testing team, you will collaborate with other 1st, 2nd, and 3rd line teams to monitor and test processes and control environments, report results, and evaluate compliance with requirements and regulations for the Technology organization. Your contributions will drive insight into risk and control performance, and organizational change through risk identification, measurement, analysis and reporting to enable better management of technology risks in an open and collaborative environment.

The Technology Controls Testing Team, within Enterprise Services Core Risk Controls Governance and Testing (CGT), is seeking an experienced, highly motivated Technology Controls Testing Manager, with strong interest in process maturity, cybersecurity, identity and access management (IAM), and cloud technologies. A clear understanding of requirements, controls, and testing methodologies is necessary for this role. The ideal candidate will be able to guide a team of control testers to design/execute test plans, identify process and control gaps, and compose clear and concise findings to document shortcomings. In addition, the ability to clearly communicate results is imperative in this role. This will be an exciting role in a dynamic and fast-paced environment requiring the ability to multi-task and prioritize deliverables appropriately. In this role, the associate will have the opportunity to develop and execute program strategy, learn new technologies, develop relationships with partners across technology divisions, and materially contribute to process enhancements to reduce risk. 

Responsibilities:

  • Manage execution and documentation of control testing activities aligned with regulatory, risk management, and compliance requirements

  • Guide a team of technology control testers responsible for evaluating IT controls across cybersecurity, identity and access management (IAM) and technology domains

  • Review and validate control testing results, ensuring completeness, accuracy, and consistency with testing methodology requirements

  • Identify control weaknesses or gaps and partner to facilitate timely remediation in collaboration with control owners and other stakeholders

  • Partner across lines of defense to ensure alignment on control objectives, test results, and findings

  • Provide subject matter expertise on control design, operational effectiveness, and risk mitigation strategies across complex technology environments

  • Champion continuous improvement initiatives, including process optimization, automation, and control rationalization

  • Coach and develop team members, cultivating a high-performance culture in the control testing function. 

  • Assist project and program delivery, including project and process management, reporting, and other governance activities.

Basic Qualifications:

  • High School Diploma, GED or Equivalent Certification

  • At least 5 years of experience in risk management, compliance, regulatory, audit or legal, or a combination

  • At least 5 years of experience in project or process management, or a combination

  • At least 5 years of experience supporting, partnering, and interacting with internal or external business clients, or a combination

  • At least 5 years of experience in controls development, controls management, or a combination

  • At least 2 years of experience in leadership roles

Preferred Qualifications:

  • 5+ years of information technology or cybersecurity experience

  • 5+ years of Financial Services industry experience

  • 5+ years of experience in technology control testing and governance, with a strong background in security operations, data loss prevention (DLP), and access management

  • Experience with AWS, GCP, or Azure cloud technologies

  • Project Management (PMP) or Program Management (PgMP) certification

  • Certifications including Certified in Risk & Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Compliance Certification (CRCM), AWS, GCP, or Azure certification

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

Sales Territory: $144,000 - $164,400 for Manager, Cyber Risk & Analysis


 

McLean, VA: $158,400 - $180,800 for Manager, Cyber Risk & Analysis


 

Richmond, VA: $144,000 - $164,400 for Manager, Cyber Risk & Analysis


 

New York, NY: $172,800 - $197,200 for Manager, Cyber Risk & Analysis


 


 


 


 


 


 


 

Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Apply now Apply later
Job stats:  2  0  0

Tags: Automation AWS Azure CISA CISM CISSP Cloud Compliance CRISC GCP Governance IAM Risk management Strategy

Perks/benefits: Career development Competitive pay Health care Salary bonus

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.