Senior Associate, Technology Controls Testing - Enterprise Services Risk

Capital One Financial

Actively hiring
McLean, VA · Richmond, VA · Chicago, IL · New York, NY Posted 17 days ago $101,100$115,400 / year

At a glance

AI generated

TL;DR

As a Senior Associate in the Control Governance Team within Enterprise Services Risk, you will collaborate with Cloud Engineering, Information Security, and Audit teams to develop automated testing solutions that support innovation while ensuring security compliance across multi-cloud environments. Your day-to-day responsibilities include designing and executing "Audit-as-Code" test plans, identifying control gaps through code analysis, and enhancing processes to reduce manual audit overhead. You will leverage cloud technologies such as AWS, GCP, and Azure, along with tools like Python, SQL, and Google Apps Script, to automate workflows, extract data from APIs, and create dashboards for continuous monitoring. The ideal candidate has a strong background in risk management, process maturity, and workflow automation, with experience in evaluating controls testing and implementing risk assessment activities across cloud services.

Skills

Python SQL JavaScript Google Apps Script AWS GCP Azure CI/CD Cloud Security Data Integration API Integration Risk Management Process Automation Visualization Dashboard Creation Policy Recommendation Continuous Auditing Communication Skills

What you'll do

  • Design and execute automated "Tests of Effectiveness" (ToE) for controls across AWS, Azure, and GCP.
  • Use code to perform analysis and repeatable tasks to streamline internal audit workflows.
  • Execute data extraction and API integration from cloud services using Python/SQL.
  • Identify critical risks in major cloud service providers and escalate them appropriately.
  • Research industry practices and regulatory changes to recommend policy updates.
  • Build process enhancements to reduce manual audit overhead through automation tools.
  • Maintain a broad understanding of cloud vulnerabilities and contribute to risk mitigation.

What we're looking for

  • At least 2 years of experience in risk management or related fields.
  • Hands-on experience with cloud technologies (AWS, GCP, Azure) and automation tools.
  • Experience designing and executing automated control testing plans.
  • Skilled at identifying control gaps through code analysis and process enhancement.
  • Professional certifications such as CRISC, CISM, CISSP, or cloud-specific certifications.
  • Ability to communicate technical risks effectively to non-technical stakeholders.
  • Experience with data extraction, analysis, and visualization from cloud APIs.

Market check

Salary context

This $101,100–$115,400 range sits above 6% of similar postings on FindRole.

Peer median band

$123,700$195,050

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$135,375$195,110

Middle half of comparable postings.

Based on 240 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About Capital One Financial

Capital One Financial is a bank holding company specializing in credit cards, auto loans, banking, and savings products, known for its data-driven approach to consumer and commercial finance. Industry: Financial Services & Banking

Capital One Financial currently has 489 open roles on FindRole.

Listed pay typically runs $197,300–$225,100 across 483 roles with salary data.

Most-posted roles

View all roles at Capital One Financial

More like this

Similar roles

Manager - Technology Risk - Enterprise Services Risk Office

Capital One Financial

Mclean, Va, US 113 days ago $149,800$171,000
CI/CD AWS Kubernetes Python PostgreSQL Risk Management Frameworks RCSA PLA Internal Audit Cyber Security GRC Tools ISO 27001 NIST COBIT ITIL PCI DSS SOX Compliance CISA CRISC CISSP CISM

Senior IT Analyst - Technical Infrastructure

Caterpillar

East Peoria, Illinois, US 23 days ago $112,710$183,140
Intune Microsoft Windows Apple MacOS Ubuntu Android iOS MS Intune PC Benchmarking Tools CI/CD Git AD DTE Lab Equipment Management Vendor Management System Testing Requirements Analysis Technical Writing Emerging Technologies Hardware Infrastructure Entra Identities Conditional Access Rules

Senior System Test & Automation Engineer

Motorola Solutions

Los Angeles, Ca, US 29 days ago $130,000$180,000
C Python Linux TCP/IP signal generators spectrum analyzers logic analyzers wireless communication systems RF signal propagation digital communication technologies