Principal Auditor - Cyber, Risk and Analysis Technology Audit (Hybrid)

Capital One Financial

Actively hiring
Mclean, Va, US Posted 35 days ago $119,400$136,200 / year

At a glance

AI generated

TL;DR

Capital One is seeking a Principal Technology Associate to join its dynamic Audit team, focusing on evaluating and analyzing technology and cybersecurity risks. This role involves executing major components of audits across critical technology functions such as cloud-based infrastructure, application controls, and cybersecurity, while also assisting in leading smaller audit projects. The ideal candidate will perform risk assessments, design audit procedures, document findings, and communicate results to management through reports and presentations. Key responsibilities include managing multiple priorities, coordinating with team members, and leveraging data analytics for insights. The position requires at least 4 years of experience in information systems auditing or related fields, including cloud computing and IT control frameworks, along with relevant certifications like CISSP, CISA, or CIA. Candidates should be adept at using tools such as AWS, GCP, or Azure, and possess strong analytical skills to identify trends and anomalies in data. This hybrid role offers a blend of remote and in-office work, fostering an environment that values innovation and collaboration within the financial technology sector.

Skills

AWS Azure GCP Python SQL CI/CD Kubernetes Terraform PostgreSQL Docker Git Jira Confluence Splunk Tableau Nessus OpenVAS OWASP PCI DSS SOX ISO 27001

What you'll do

  • Execute audits of critical technology functions including cloud-based infrastructure and cybersecurity.
  • Perform risk assessments and design audit procedures to verify control effectiveness.
  • Document client processes and communicate audit results to management.
  • Analyze data extracts to identify trends, patterns, and anomalies in technology risks.
  • Prepare clear documentation supporting work performed during audits.
  • Coordinate with team members and take on additional responsibilities proactively.

What we're looking for

  • At least 4 years of experience in information systems auditing or risk management.
  • Minimum 1 year of cloud computing and controls experience (design, operation, risk management, or auditing).
  • 2+ years of experience managing audit engagement components or project management.
  • Certifications in Cloud, Cyber, Technology Operations, Auditing, or related fields required.
  • Experience with IT control frameworks and planning/leading audits for at least 2 years.
  • Proficiency in data analysis and scripting/coding to identify trends and anomalies.

Market check

Salary context

This $119,400–$136,200 range sits above 19% of similar postings on FindRole.

Peer median band

$121,550$198,000

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$135,650$195,500

Middle half of comparable postings.

Based on 239 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About Capital One Financial

Capital One Financial is a bank holding company specializing in credit cards, auto loans, banking, and savings products, known for its data-driven approach to consumer and commercial finance. Industry: Financial Services & Banking

Capital One Financial currently has 489 open roles on FindRole.

Listed pay typically runs $197,300–$225,100 across 483 roles with salary data.

Most-posted roles

View all roles at Capital One Financial

More like this

Similar roles

Technology Audit Associate

T. Rowe Price

Owings Mills, Md - Building 2, US 30 days ago $96,500$164,000
COBIT NIST ISO Python SQL Kubernetes AWS Azure GCP Terraform CI/CD PostgreSQL Oracle DevOps SDLC Git Jira Confluence Tableau PowerBI

Internal Auditor - Security - Adyen

Ayden

US 21 days ago
Cloud Kubernetes AWS Azure GCP CI/CD Python Go Ruby SQL PostgreSQL Docker Terraform CISA CISSP CIA RE PCI DSS ISO 27001 NIST Cybersecurity Framework

Internal Auditor - Security - Adyen

Ayden

US 9 days ago
AWS Kubernetes Terraform Python PostgreSQL CI/CD Docker Prometheus Grafana PCI DSS ISO 27001 NIST Cybersecurity Framework CISA CISSP CIA RE Data Analytics Automation AI