Find Jobs
Find Jobs Near You – Available Work in Your Location
Senior Technology Auditor - Global Payment Network
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,440 / year median in Virginia
+4% projected growth
Job Description
- Global Payment Network Capital One's Audit function is a dedicated group of professionals focused on delivering top-quality assurance services to the organization's Audit Committee.
Responsibilities:
- Execute test procedures of critical technology functions, cloud-based infrastructure, cybersecurity, risk management, application, and third-party management.
- Perform risk assessments of business activities and perform relevant testing based on the risks and processes associated with the area being audited. Assist in communicating issues, risks and recommendations to all levels of management.
- Operate independently and ensure work is completed to schedule and meets our high-quality standards.
- Prepare clear, organized and complete documentation to support work performed.
- Develop and maintain strong and effective working relationships with key business partners and the extended Audit group.
- Leverage available data and analytical tools during the planning and fieldwork phases of audit delivery.
- Proactively follow-up on agreed audit actions to ensure management delivers their commitments within the agreed timescales.
- Proactively seek out learning opportunities to enhance skills and competencies related to role. Here's what we're looking for in an ideal teammate:
- You are a critical thinker who seeks to understand the business and its control environment.
- You believe insight and objectivity are core elements to providing assurance on the effectiveness and efficiency of Capital One's governance, risk management, and internal control processes.
- You possess a relentless focus on quality and timeliness.
- You adapt to change, embrace bold ideas, and are intellectually curious. You like to ask questions, test assumptions, and challenge conventional thinking.
- You develop influential relationships based upon shared risk objectives and trust to deliver outstanding business impact and elevate Audit's value proposition.
- You're a firm believer that a rich understanding of data, innovation, and technology will only make you a better auditor. This will require leveraging the power of data analytics and furthering your technical expertise.
- You're a teacher. You do the right thing and lead by example. You have a passion for coaching and investing in the betterment of your team. You lead through change with candor and optimism.
- You create energy and an environment that fosters trust, collaboration, and belonging, making it easy to attract, hire, and retain top talent.
Basic Qualifications:
Bachelor's Degree or military experience At least 2 years of experience in tech auditing, information technology (operations, software delivery, access management, microservices), information security (application security, network security, cyber security, data protection), information systems risk management, or a combination At least 1 year of experience in analyzing data extracts to identify trends, patterns, and anomalies, including experience in testing scripting or coding (writing, reviewing, or assessing)Preferred Qualifications:
Certified Internal Auditor (CIA), Certified Public Accountant (CPA), or relevant cloud and or cyber certifications (such as AWS certifications, CISSP, etc.) 2+ years of experience in banking, in the financial services industry, in a professional services firm serving clients in large banks, or a combination 3+ years of experience auditing or performing cyber or information security 1+ years experience in cloud computing (AWS, GCP, Azure) and controls, or 1+ years of conducting audits of controls in cloud-based environments Exposure to relevant industry frameworks (e.g. NIST cyber security framework, NIST 800 series, FEDRamp, CIS benchmarks, etc) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. This role is hybrid meaning associates typically spend 3 days per week in-person at one of our offices listed on this job posting. The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.Charlotte, NC:
$101,100- $115,400 for Sr.
Assoc, Cyber Risk & Analysis McLean, VA:
$111,200- $126,900 for Sr.
Assoc, Cyber Risk & Analysis New York, NY:
$121,300- $138,400 for Sr.
Assoc, Cyber Risk & Analysis Richmond, VA:
$101,100- $115,400 for Sr.
Benefits
- Dental Insurance