Cybersecurity Exercise Program - Manager
At Capital One, we’re building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.
Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.
Pick up the newspaper on any given day and you will read about yet another organization having its systems disrupted and valuable data lost or compromised. Building a resilient cybersecurity organization is the new frontier and Capital One’s Information Security and Risk Management (ISRM) team is at the forefront.
Capital One’s innovative Cybersecurity Exercise Program is seeking a Manager. The Cyber Exercise Program works closely with partners in information security, the wider enterprise, and across the global financial services sector. The Cybersecurity Exercise Program supports Capital One’s ongoing readiness to protect customers and respond effectively to major cybersecurity incidents. The program leads or participates in both small and large cybersecurity exercises on a recurring basis, to include enterprise-wide events.
You will help to execute the full life-cycle of cybersecurity exercise activities, to include design, development, conduct, and evaluation. These activities will focus on strengthening ISRM’s incident response and coordination processes within Capital One as well as with public and private sector partners. Additionally, the Manager will undertake actions to apply lessons learned from exercises to improve Capital One and ISRM’s cybersecurity resilience. The successful candidate will be distinguished by excellent communications skills, a passion for delivering exceptional exercise events, and a commitment to thought leadership in cybersecurity event response.
Responsibilities and Competencies:
- Perform planning, facilitation, documentation development, and coordinate follow-up activities for ISRM’s Cybersecurity Exercise Program.
- Participate in project teams comprised of Capital One Associates with varied technical and non-technical backgrounds to plan and execute cybersecurity exercises.
- Help represent Capital One in the participation of external financial sector exercises, such as those lead by the Financial Sector Coordinating Council and the Federal Government.
- Contribute to the training and coordination between various cyber security organizations and the Bank's lines of business.
- Work with Cyber Threat Intelligence and Information Security Officers to identify cyber risks, design threat scenarios, identify key stakeholders and participants, and execute the exercise against the planned scenarios and objectives.
- Partner with other Strategy and Business Resilience Program activities, such as the business continuity management team.
- Perform in an analytic capability to interpret key performance indicators to identify cybersecurity exercise performance and outcomes.
- Possesses strengths in communication and developing interpersonal relationships, as coordination with internal cybersecurity and risk management groups will be key.
- Bachelor’s Degree or military experience
- At least 3 years of experience designing and executing a variety of exercise like tabletops, drills, functional and full-scale.
- At least 1 year of information technology or cybersecurity experience.
- 5 years of exercise or training experience as it relates to security, business continuity or continuity of operations or disaster recovery, which provide foundational understanding of information technology and security concepts
- 3 years of experience in incident response operations or supporting training for incident response
- 3 years of experience utilizing or employing the Homeland Security Exercise and Evaluation Program (HSEEP) Methodology
- 2 years of direct cyber exercise experience
- 1 year of experience with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
At this time, Capital One will not sponsor a new applicant for employment authorization for this position
Capital One is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to gender, race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity/assignment, citizenship, pregnancy or maternity, protected veteran status, or any other status protected by applicable national, federal, state or local law Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you require an accommodation to apply for a job or to perform a job, please contact Capital One Recruiting at 1-800-304-9102 or RecruitingAccommodation@capitalone.com.
All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Company Type: Public Company
Company Size: 10,001+