Search jobs > New York, NY > Associate cyber risk

Principal Associate, Cyber Risk & Analysis - Cyber External Client Assurance - Independent Assurance (SOC 2, ISO27001)

Capital One
New York, NY
$142.1K-$162.1K a year
Full-time
Part-time

Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Risk & Analysis - Cyber External Client Assurance - Independent Assurance (SOC 2, ISO27001)

The Cyber External Client Assurance (CECA) - Independent Assurance team centrally facilitates Capital One’s commercialized products and services through their Commercialized Attestation goals (SOC 2).

The associate in this role will partner across the organization to perform the following responsibilities : (1) Commercialized Attestation Scoping : Perform process and technology risk assessments to determine the optimal control mix for the products pursuing a Commercialized Technology Attestation engagement (SOC 2).

2) Issue Management : Evaluate control deviations and their impact on management's opinion over the design, implementation, and operating effectiveness of the controls in place to address the Commercialized Technology Attestation frameworks we pursue.

3) Evidence Collection : Facilitate evidence requests made by external auditors to support their independent attestation requirements.

You will :

Perform process and technology risk assessments to determine the optimal control mix for the products pursuing a Commercialized Technology Attestation engagement (SOC 2).

Proactively identify changes in our products features and evaluate their impact on the controls needed to achieve any Commercialized Technology Attestations the product is pursuing.

Monitor changes in attestation frameworks and how the changes impact the optimal mix of controls required for our products pursuing a Commercialize Technology Attestation.

Ensure seamless design of our controls around emerging technologies as they are integral in supporting our Commercialized Technology Attestation engagement.

Interpret and communicate / present appropriate control design to senior leadership.

Influence leadership with recommendations for Controls and Process improvements on an ongoing basis.

Evaluate control deviations and their impact on management's opinion over the design, implementation, and operating effectiveness of the controls in place to address the Commercialized Technology Attestation frameworks we pursue.

Draft Management Responses that are presented within Attestation Reports.

Partner with the product teams to answer any customer inquiries on issues listed within an attestation report.

Facilitate evidence requests made by external auditors to support their independent attestation requirements.

Provide advisory to control owners on ensuring the evidence they are submitted will meet the needs of the auditors.

Partner with external auditors to establish evidence collection timelines / deadlines.

The associate should be able to :

Be well organized and able to manage multiple requests

Demonstrate strong ability to analyze information and data and leverage to support recommendations

Work in collaboration across multiple teams while maintaining business relationships

Develop and communicate quality recommendations to the program

Demonstrate strong subject matter expertise and sound judgment to align appropriate risk level

Work with diverse contacts throughout Capital One

Communicate technical issues to non-technical people

Demonstrate strong problem-solving and conceptual thinking abilities

Demonstrate capacity to think broadly but go deep into subject matter when needed

Basic Qualifications :

High School Diploma, GED or equivalent certification

At least 4 years of technology experience in Internal Controls, Risk Management, or Audit or a combination

At least 3 years of experience in identifying and assessing IT general, IT application, data movement and systems implementation controls

Preferred Qualifications :

Bachelor’s Degree

5+ years of experience in Auditing and Control Evaluation

CISA, CISSP, or CRISC certification

2+ years of experience with Cloud technologies (AWS, Azure, or GCP)

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting.

Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

New York City (Hybrid On-Site) : $134,100 - $153,000 for Prin Assoc, Cyber Risk & AnalysisSan Francisco, California (Hybrid On-Site) : $142,100 - $162,100 for Prin Assoc, Cyber Risk & Analysis

16 days ago
Related jobs
Promoted
Capital One Financial Corporation
New York, New York

Principal Associate, Cyber Risk & Analysis - Cyber External Client Assurance - Independent Assurance (SOC 2, ISO27001). The Cyber External Client Assurance (CECA) - Independent Assurance team centrally facilitates Capital One's commercialized products and services through their Commercialized At...

Promoted
Capital One
New York, New York

As a Principal Associate (PA) in Capital One’s Cyber Governance & Risk organization, you will have the chance to oversee control development, enhancement, execution, testing and reporting, and ensuring controls meet quality standards. Principal Associate, Cyber Controls Monitoring. You will work...

Promoted
Capital One
New York, New York

As a Principal Data Risk Associate within the Anti-Money Laundering (AML) - Models and Advanced Data Insights (MADI) organization, you will leverage your organization, communication, and problem solving skills, and knowledge of data risk management, to maintain vital compliance requirements in a fas...

Promoted
AXIS Capital Holdings Limited
New York, New York

Provide Cyber Underwriting technical support resources: When called upon, support Underwriters in assessing individual accounts by providing technical cyber guidance, analysis of risk posture, and recommendations for Underwriting. We stand apart for our outstanding client service, intelligent risk t...

Capital One
Queens, New York

Principal Associate, Cyber Product Owner. As a Product Owner supporting the Detection and Mitigation Cyber Service Area, you will be accountable for contributing to and delivering upon the strategic agenda for our core cyber products to drive meaningful progress for our customers and our business. Y...

Recruiters
New York, New York

Principal Associate, Cyber Threat Hunter. Conduct time-sensitive analysis during cyber investigations, including active threat hunting and malware analysis. Proactively build and maintain relationships with partner teams, including but not limited to Cyber Intelligence, Red Team, Insider Threat, and...

Peloton
New York, New York

Peloton is looking for a highly motivated leader to join our growing SOX & Risk Assurance team, working primarily with our Precor business unit. This role will be responsible for operating as the Second Line of Defense within the Accounting Organization, establishing and maintaining policies and pro...

AXIS
New York, New York

Provide Cyber Underwriting technical support resources: When called upon, support Underwriters in assessing individual accounts by providing technical cyber guidance, analysis of risk posture, and recommendations for Underwriting. We stand apart for our outstanding client service, intelligent risk t...

Société Générale Assurances
New York, New York

Specific analysis to explain risk exposure and/or business performance to our different partners. Monitoring of risk limit consumptions and follow-up of limit breaches with Front-Office and Risk management;. INTERNSHIP - Market Analysis and Certification. INTERNSHIP - Market Analysis and Certificati...

Société Générale Assurances
New York, New York

The scope includes performing regulatory controls, managing programs and initiatives to enhance the risk & control framework, supporting risk assessments (, RCSA), conducting breach management, and representing the business in governance forums. Support the MARK front office annual risk and control ...