Principal Associate, Operational Risk Management, Third Party Risk Manager (TPRM)
The successful candidate will play a critical role in driving the strategy, integrity, and continuous improvement of the Third Party Risk Management Framework across the enterprise. In this role, you will lead high-impact governance programs, serve as a core subject matter expert, and ensure our risk management practices are rigorously executed and well-managed. You will collaborate closely with cross-functional partners and leadership to navigate a dynamic regulatory landscape and uphold sound risk practices.
ResponsibilitiesLead Framework and Policy Governance: Support the enterprise-focused TPRM policies and standards across the full lifecycle.
Drive Risk Oversight Programs: Lead the execution of the annual TPRM Risk Oversight Program Self-Assessment and Process Criticality Assessments to ensure robust framework compliance.
Act as an Internal SME: Serve as the primary subject matter expert on TPRM requirement applicability, providing guidance to the business and participating in broader partner risk assessments (such as Cyber Program assessments) from a holistic risk perspective.
Manage Issue Remediation: Own and lead the end-to-end remediation of TPRM-related risk issues, ensuring sustainable, well-managed solutions are implemented.
Maintain Taxonomies and Diagnostics: Shape and maintain the TPRM Risk Taxonomies and Process Diagnostic guidance to ensure consistency and clarity across the enterprise.
Support Audits and Exams: Act as a key partner and facilitator for relevant first-line and second-line audits, regulatory examinations, and Process Level Assessments.
Ensure Mandate Compliance: Support Designated Mandate Owners (DMO) with rigorous requirement fulfillment and annual attestation processes.
Basic QualificationsBachelor's Degree or military experience.
At least 3 years of experience in Operational Risk Management, Third-Party Risk Management, Compliance, or Audit within a financial institution or a regulated industry.
At least 2 years of experience in process management governance.
Preferred Qualifications4+ years of experience in a dedicated Third-Party Risk Management (TPRM) role focusing on overall risk framework, governance, and policy (as opposed to technical or cyber-only security assessments).
3+ years of experience in Process Management or Project Management, with a strong understanding of how to optimize risk workflows.
Proven track record of leading risk remediation efforts and managing interactions with internal audit or regulatory examiners.
Excellent written and verbal communication skills, with the ability to influence stakeholders and synthesize complex risk concepts for leadership.
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $120,800 - $137,900 for Principal Risk Specialist
Richmond, VA: $109,900 - $125,400 for Principal Risk Specialist
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.