View Our Featured Local Employer Below

McLean 2 (19052), United States of America, McLean, Virginia

At Capital One, we re building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.

Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.

Risk and Remediation Manager - Application Security

Risk and Remediation Manager - Application Security

Security is essential to what we do at Capital One, from protecting customer data to the associate experience. As a Cyber Remediation Manager within the Information Security Office, you see security as an enabler and differentiator to empower the business through innovation. You partner with the business, understanding their goals and objectives while helping teams incorporate cybersecurity best practices. You will consult on initiatives, programs, and projects to prioritize security risk reduction activities. You are pragmatic and practical in your understanding of software development and IT operations, and familiar with Capital One cybersecurity objectives. Using this knowledge, you collaborate and innovate with customers and colleagues to enhance the technology risk posture.


  • Serve as an Information Security Remediation subject matter expert
  • Collaborate with a team of Tech Risk Management and Information Security professionals to provide subject matter expertise to business project teams
  • Evaluate the status of Cyber control programs through analysis of information security metrics
  • Articulate operations, compliance, and cybersecurity objectives for business leadership to inform prioritized risk reduction
  • Effectively communicate the impact of operations, compliance, and cybersecurity gaps to multiple audiences, encouraging remediation activities to enhance their cybersecurity posture
  • Lead activities in response to large-scale enterprise remediation efforts

About You:

  • You have strong written and verbal communication skills
  • You are driven to provide excellent customer and stakeholder service and support
  • You have strong organizational skills and the ability to drive tasks to completion
  • You possess the ability to negotiate and influence results without direct authority
  • You are team-oriented and can interface effectively with a broad range of people and roles, including upper management and technology leaders
  • You maintain calmness and clarity of thought under pressure and can maintain confidentiality
  • You can work well under minimal supervision

Basic Qualifications:

  • High School Diploma, GED, or equivalent certification
  • At least 4 years of experience with vulnerability identification and management
  • At least 4 years of experience with technology or cyber security risk management frameworks
  • At least 2 years of experience with static and dynamic application security scanning tools and processes

Preferred Qualifications:

  • You are certified or intend to pursue one or an equivalent of the following certifications: CISSP, CEH, AWS Cloud Practitioner or AWS Certified Solutions Architect Associate
  • 5+ years of experience with Application Security, Penetration Testing or Vulnerability Management
  • 5+ years of experience with the OWASP top ten and using it within a corporate environment
  • 3+ years of experience developing automated scripts using JAVA, .Net, REST API or Python to automate and develop requirements, test scripts as required
  • Knowledge of domain structures, user authentication, data encryption, access audits and end-user security best practices
  • Experience with monitoring, gathering, and assessing artifacts as part of continuous security monitoring (C&A, PO&AM, NIST 800-37)
  • Experience in operational compliance or IT audit
  • Experience as a Systems Administrator or Network Administrator
  • Experience developing and maintaining written security controls, compliance, and defining remediation strategies
  • Experience utilizing Agile methodologies
  • Experience in Offensive or Defensive Security techniques
  • Experience in conducting Threat Modeling for applications
  • Experience delivering training and providing education to large audiences on application security threats and risks

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.


Continue to Job Site ❯