Principal Risk Specialist, Tech & Cyber Risk | Retail Bank
As a Principal Associate of Tech & Cyber Risk within Capital One’s Business Risk Office, you will enable and drive end-to-end risk management of the portfolio by partnering directly with risk partners, technology stakeholders, operations and engineering teams to identify, assess, and mitigate technology and cyber risks.
In this high-impact role, as a pratices partner, you will leverage your strong project management, communication, and analytical skills to support cutting-edge technology initiatives and promote strategic risk management across the organization. You will be hands-on in evaluating and mitigating risks related to AI implementations, supporting the technology integration of acquired companies, and monitoring risk posture within large-scale architecture transformation programs. By overseeing portfolio health, remediation efforts, tracking key metrics and performing assessments you will help teams proactively align with enterprise policies, ensuring the ongoing resilience and security of our technology ecosystem.
Key Responsibilities:
End-to-End Risk Management & Execution
Drive end-to-end technology and cyber risk assessments, managing the lifecycle from tactical implementation and ongoing evaluation through to remediation tracking and successful risk finding closure.
Support the responsible implementation of AI applications and large-scale architecture transformations by conducting timely risk assessments and ensuring project teams align with well managed best practices and enterprise risk frameworks.
Project Management & Stakeholder Engagement
Utilize strong project management skills to effectively prioritize risk initiatives, ensuring clear project scope and the timely delivery of impactful results.
Exhibit outstanding communication skills to build and manage strong stakeholder relationships across engineering, operations, cyber, risk functions, keeping all levels and lines of defense informed and influencing outcomes to drive project success.
Display strong advisory skills to guide risk and engineering partners through complex risk landscapes, adapting with agility to changing business demands and evolving technology environments.
Process Improvement & Program Execution
Drive continuous improvement within the Tech & Cyber Risk Office by identifying, designing, and implementing enhancements to streamline risk identification, assessment, and mitigation workflows.
Role Expectations & Desired Behaviors:
Autonomy & Strategic Execution: Proactively identify, own, and resolve risks with limited supervision; exhibit structured problem-solving to lead sub-tasks and strategy.
Customer Focus & Reliability: Own the end-to-end customer process by facilitating project forums and anticipating partner needs to reduce portfolio risk.
Communication & Influence: Tailor messaging for diverse audiences (from peers to senior leadership); lead meeting agendas to drive consensus, influence outcomes, and ensure timely action.
Fungibility & SME Development: Actively develop deep domain expertise to rotate across core and adjacent risk roles, sharing knowledge to strengthen team capabilities and flexibility.
Basic Qualifications:
5+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, or Technology Consulting
Preferred Qualifications
Experience leveraging data analysis and visualization tools (e.g., Sheets, Pivot Tables, SQL, Tableau, Power BI) to derive risk insights and manage metrics.
Project management experience, including planning, execution, and delivery of strategic initiatives. Demonstrated success managing complex, cross-functional risk or technology projects utilizing agile or waterfall methodologies.
Awareness of RCSA (Risk and Control Self-Assessment) risk frameworks and methodologies.
Certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP).
Familiarity with AI risk management frameworks, or possession of/interest in obtaining certifications such as the Certified AI Governance Professional (AIGP).
Experience working within a Large Financial Services institution, highly regulated environment, or technology consulting organization.
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $131,300 - $149,800 for Prin Assoc, Cyber Risk & AnalysisRichmond, VA: $119,400 - $136,200 for Prin Assoc, Cyber Risk & Analysis
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidates offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at theCapital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.