At a Glance
- Tasks: Evaluate third-party security and deliver quality assessment reports.
- Company: Join Capital One, a leader in information security and risk management.
- Benefits: Enjoy hybrid working, generous holidays, and access to wellness facilities.
- Why this job: Be part of a transformative team that values diversity and innovation.
- Qualifications: Experience in information security or risk management is a plus.
- Other info: Flexible working arrangements available; we celebrate diverse backgrounds.
The predicted salary is between 36000 - 60000 £ per year.
Risk Remediation Assessor page is loaded
Risk Remediation Assessor
Apply locations Nottingham, Eng time type Full time posted on Posted 4 Days Ago job requisition id R220133 Nottingham Trent House (95002), United Kingdom, Nottingham, NottinghamshireRisk Remediation Assessor
About the Role
Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, risk assessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR) program defines the framework and conducts the assessments which enable the business to protect sensitive information, physical assets, and confirms the Third Parties’ ability to provide continual services.
This role will partner with a community of internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry requirements.
Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency.
What you’ll do:
-
Support kick-off, planning and scoping activities for cyber-focused risk assessments, working with cross functional resources to understand the operational and technical aspects of Third Party engagement model.
-
Analyse Third Party control environment data against Capital One security expectations; interpreting information security requirements and reasonably apply them to specific situations.
-
Review and support execution and delivery of reports including executive summaries and work papers detailing the assessment. work completed, evidence reviewed, and identified gaps.
-
Maintain relationships with Third Party management, and other Enterprise colleagues to manage expectations of assessments and remediation including timing and assessment deliverables.
-
Ensure compliance to program process and procedures.
-
Maintain a thorough understanding of the program controls, intent, and test procedures.
-
Support third parties in appropriately managing and remediating risks identified through assessments..
-
Travel 10-25%, which may include off-site locations, to perform multi day assessments.
-
Identify and support initiatives to drive ongoing process improvements.
Other Responsibilities Include
-
Performing cyber-focused assessments of Capital One third parties, identifying risks and delivering high-quality reports.
-
Providing consultative services related to third party security while applying risk based judgement to information security issues.
-
Driving risk remediation through advice and challenge.
-
Ensuring risk is appropriately managed and escalated.
-
Assisting Third Parties, Third Party Managers, or Accountable Executives with understanding risks identified.
Would be great if you had some of these :
-
Experience in Information Security
-
Experience in Supply Chain Management
-
Experience in a Risk Management role related to Information Security, Business Continuity Management, or Supply Chain Management
-
Experience with risk assessments encompassing PCI DSS, NIST Framework, physical security controls, or IT operations management
-
Experience communicating and presenting to senior management
-
CISSP, CISA, or CRISC certification
We are committed to creating a level playing field and seek to create teams that are representative of our customers and the communities we serve. We’d love to hear from you if you identify with a typically under-represented group in our industry and are particularly keen to hear from women, the LGBTQ+ community and ethnic minority candidates.
Where and how you\’ll work
This is a permanent based in our Nottingham Head O ffice.
We have a hybrid working model, so you’ll be based in our office 3 days a week on Tuesdays, Wednesdays and Thursdays, and can work from home on Monday and Friday.
Many of our associates have flexible working arrangements, and we\’re open to talking about an arrangement that works for you.
What’s in it for you
-
Bring us all this – and you’ll be well rewarded with a role contributing to the roadmap of an organisation committed to transformation
-
We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers)
-
Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance – with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave
-
Open-plan workspaces and accessible facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms. In London, you can heighten your mood with a run on our rooftop running track or an espresso at the Workshop Coffee café
What you should know about how we recruit
We pride ourselves on hiring the best people, not the same people. Building diverse and inclusive teams is the right thing to do and the smart thing to do. We want to work with top talent: whoever you are, whatever you look like, wherever you come from. We know it’s about what you do, not just what you say. That’s why we make our recruitment process fair and accessible. And we offer benefits that attract people at all ages and stages.
We also partner with organisations including the Women in Finance and Race At Work Charters, Stonewall and upReach to find people from every walk of life and help them thrive with us. We have a whole host of internal networks and support groups you could be involved in, to name a few:
-
REACH – Race Equality and Culture Heritage group focuses on representation, retention and engagement for associates from minority ethnic groups and allies
-
OutFront – to provide LGBTQ+ support for all associates
-
Mind Your Mind – signposting support and promoting positive mental wellbeing for all
-
Women in Tech – promoting an inclusive environment in tech
-
EmpowHER – network of female associates and allies focusing on developing future leaders, particularly for female talent in ourindustry
Capital One is committed to diversity in the workplace.
If you require a reasonable adjustment, please contact ukrecruitment@capitalone.com All information will be kept confidential and will only be used for the purpose of applying a reasonable adjustment.
For technical support or questions about Capital One\’s recruiting process, please send an email to Careers@capitalone.com
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
#J-18808-Ljbffr
Risk Remediation Assessor employer: Capital One
Contact Detail:
Capital One Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Risk Remediation Assessor
✨Tip Number 1
Familiarise yourself with the Cyber Third Party Risk Reduction (CTPRR) program. Understanding its framework and objectives will help you demonstrate your knowledge during interviews and discussions, showing that you're proactive and genuinely interested in the role.
✨Tip Number 2
Network with professionals in the information security field, especially those who have experience with third-party risk assessments. Engaging in conversations can provide insights into the role and may even lead to referrals, increasing your chances of landing the job.
✨Tip Number 3
Prepare to discuss specific examples of how you've managed risks or conducted assessments in previous roles. Being able to articulate your hands-on experience will set you apart from other candidates and show that you can apply your knowledge practically.
✨Tip Number 4
Stay updated on the latest trends and regulations in information security, particularly those related to third-party management. This knowledge will not only help you in interviews but also demonstrate your commitment to continuous learning and improvement in the field.
We think you need these skills to ace Risk Remediation Assessor
Some tips for your application 🫡
Understand the Role: Before applying, make sure to thoroughly read the job description for the Risk Remediation Assessor position. Understand the key responsibilities and required skills, such as experience in Information Security and risk assessments.
Tailor Your CV: Customise your CV to highlight relevant experience and skills that align with the job requirements. Emphasise any previous roles related to risk management, information security, or third-party assessments.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for the role and the company. Mention specific experiences that demonstrate your ability to manage risks and work collaboratively with stakeholders.
Highlight Relevant Certifications: If you have certifications like CISSP, CISA, or CRISC, make sure to mention them prominently in your application. These qualifications can set you apart from other candidates and show your commitment to the field.
How to prepare for a job interview at Capital One
✨Understand the Role
Make sure you have a solid grasp of what a Risk Remediation Assessor does. Familiarise yourself with the key responsibilities, such as conducting cyber-focused risk assessments and maintaining relationships with third-party management. This will help you answer questions confidently and demonstrate your interest in the role.
✨Showcase Relevant Experience
Prepare to discuss your experience in Information Security or Risk Management. Highlight any specific projects or roles where you've successfully managed risks or conducted assessments. If you have certifications like CISSP, CISA, or CRISC, be ready to explain how they relate to the job.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills and ability to handle complex information security issues. Think of examples from your past experiences where you identified risks and implemented effective remediation strategies.
✨Demonstrate Communication Skills
As this role involves working with various stakeholders, it's crucial to showcase your communication skills. Be prepared to discuss how you would present findings to senior management and manage expectations during assessments. Practice articulating your thoughts clearly and concisely.