Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
DevOps Security Engineer image - Rise Careers
Job details

DevOps Security Engineer

DevOps Security Engineer

Capital One is seeking a technical security solution leader to deliver game-changing cybersecurity solutions based on threat, data, and design thinking. We are a technology oriented company delivering financial products to market through modern technology and constant innovation at a massive scale.  Part of that innovation is leveraging technology to deliver the best cybersecurity solutions for the business.   

As a candidate for this role, you’re able to seamlessly switch from technical deep dives to collaborative discussions around team strategy and mentorship. You are naturally curious and stay on top of emerging trends and threats. You are not afraid to question existing processes and solutions, yet you display a keen sense of business value and focus on the right priorities. You are a clear thinker, thrive in working across teams, and are an expert in dealing with ambiguity. You believe that a core component of security’s role is to enable the business, not just to secure it, and the solutions you bring to life are aligned to the needs of our technology partners and business stakeholders. You thrive in working in a fast-paced, technologically forward-leaning environment and are not afraid to push the boundaries of security capabilities.  

What you'll do

  • Lead the technical implementation of cyber assessment solutions, from planning and design to execution and deployment, including hands-on configuration, integration, and testing.

  • Mentor and guide junior team members, fostering their growth in software development with a strong emphasis on secure coding practices and integration of security principles, sharing expertise in security assessments, process improvement, and data analysis.

  • Closely collaborate with team lead, product owners, and customers to ensure quality and consistency of the team's output, contributing to strategic planning and roadmap development.

  • Collaborate with business stakeholders to understand their needs and workflows related to cybersecurity assessments. Use this understanding to identify opportunities for automation and process improvement, ultimately enhancing the efficiency and effectiveness of security operations and improving the overall security posture of the organization.

  • Contribute to enriching threat models and other security assessments by integrating data from various sources, including REST APIs, enterprise security tools (SIEM, SOAR, vulnerability scanners), and data warehouses (Snowflake).

  • Continuously learn and stay up-to-date with the latest cybersecurity trends, technologies, and best practices, sharing knowledge with the team.

About You

  • You possess a strong understanding of cybersecurity assessment principles, methodologies, and best practices, and you're eager to share your knowledge with others.

  • You are detail-oriented and articulate key details clearly, both in conversation and technical documentation.

  • You are capable of driving complex technical initiatives to full delivery, leveraging your knowledge of cybersecurity practices, software engineering principles, agile frameworks, and customer engagement.  

  • You have the ability to foster collaborative, open working relationships with technology groups and other stakeholders.  

  • You have demonstrated clear communication skills, including the ability to effectively present technical concepts and demonstrations to stakeholders at all levels of the organization.

  • You have experience working in or managing multiple high-visibility and high-impact enterprise cybersecurity projects with cross-functional teams.  

  • You have hands-on experience transforming cybersecurity assessment processes, migrating them to new tools and platforms, and integrating those tools with existing security infrastructure.

  • You are a self-starter, actively identifying gaps in our security posture and determining ways to solve them.

  • You are a team player, willing to step in and assist associates both on and off the team.

Basic Qualifications:

  • High School Diploma, GED or equivalent certification

  • At least 3 years of experience in cybersecurity or information technology

  • At least 2 years of experience with Python

  • At least 1 year of experience with cloud security (AWS, Azure, GCP)

  • At least 1 year of experience working with REST APIs or data integration

Preferred Qualifications:

  • Bachelor’s Degree

  • 4+ years of experience in Information Technology

  • 4+ years of experience in Cybersecurity

  • 4+ years of experience in IT Delivery projects

  • 4+ years of experience in an Agile environment

  • Experience with scripting and automation (Python or PowerShell)

  • Experience in threat modeling and security assessment data integration

  • Experience in strategic planning and roadmap development

  • Advanced knowledge of specific cybersecurity domains (application security, network security, data security)

  • Hands-on experience transforming cybersecurity assessment processes and migrating to new tools or platforms

  • One of the following professional certifications: CISSP, CRISC, GIAC, CISM, CCSP, CISA 

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

McLean, VA: $158,600 - $181,000 for Prin Assoc, Cyber Technical


 

Plano, TX: $144,200 - $164,600 for Prin Assoc, Cyber Technical


 

Richmond, VA: $144,200 - $164,600 for Prin Assoc, Cyber Technical


 


 


 


 


 


 


 


 

Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Capital One Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Capital One DE&I Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Capital One
Capital One CEO photo
Richard D. Fairbank
Approve of CEO

Average salary estimate

$154400 / YEARLY (est.)
min
max
$144200K
$164600K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About DevOps Security Engineer, Capital One

As a DevOps Security Engineer at Capital One in Richmond, Virginia, you’ll be stepping into an exciting role that blends technical expertise with a passion for security innovation. Picture yourself leading the charge in implementing advanced cybersecurity solutions that align with the needs of our technology and business partners. Your curiosity and desire to stay informed on emerging security threats will be essential as you guide your team and mentor junior engineers in secure coding practices. You’ll navigate the fast-paced worlds of software development and cybersecurity, working alongside product owners and customers to ensure the highest quality outputs. Your role will involve analyzing existing processes, identifying gaps, and proposing solutions that enhance our security posture. Moreover, through collaboration and continuous learning, you'll help elevate the security awareness and capabilities for everyone involved. At Capital One, you’ll not only secure our innovative financial products but also contribute significantly to shaping our strategy in cybersecurity. If you're a clear communicator who thrives in complexity and ambiguity, this role offers an incredible opportunity to make a real impact in the tech landscape of finance.

Frequently Asked Questions (FAQs) for DevOps Security Engineer Role at Capital One
What are the responsibilities of a DevOps Security Engineer at Capital One?

The responsibilities of a DevOps Security Engineer at Capital One include leading the implementation of cyber assessment solutions, mentoring junior team members, collaborating with various stakeholders to ensure quality output, and identifying opportunities for process improvement. You'll also integrate data from multiple sources to enhance security assessments and continuously learn about the latest cybersecurity trends.

Join Rise to see the full answer
What qualifications are needed to be a DevOps Security Engineer at Capital One?

To qualify for the DevOps Security Engineer role at Capital One, candidates must have at least a high school diploma or equivalent, with a minimum of three years in cybersecurity or IT. Additionally, experience with Python, cloud security (AWS, Azure, GCP), and REST APIs is essential. Preferred qualifications include a Bachelor’s Degree, advanced industry certifications, and several years of relevant experience.

Join Rise to see the full answer
How does Capital One ensure the professional growth of its DevOps Security Engineers?

Capital One prioritizes professional growth by fostering a culture of mentorship and continuous learning within its teams. As a DevOps Security Engineer, you will be expected to mentor junior associates and also have access to resources and training that allow you to stay updated on security trends and best practices, enhancing both personal and professional development.

Join Rise to see the full answer
What tools and technologies should I be familiar with as a DevOps Security Engineer at Capital One?

As a DevOps Security Engineer at Capital One, familiarity with cybersecurity assessment tools, data integration tools, and cloud platforms like AWS, Azure, or GCP is vital. Proficiency in Python or PowerShell scripting, experience in threat modeling, and knowledge of enterprise security tools will significantly enhance your effectiveness in the role.

Join Rise to see the full answer
What is the work environment like for DevOps Security Engineers at Capital One?

The work environment for DevOps Security Engineers at Capital One is dynamic and collaborative. You'll engage with cross-functional teams within a technologically forward-thinking atmosphere, where pushing security boundaries and being proactive about security measures and innovations is not just welcomed but encouraged.

Join Rise to see the full answer
Common Interview Questions for DevOps Security Engineer
What attracted you to the DevOps Security Engineer position at Capital One?

When answering this question, focus on your passion for cybersecurity and how Capital One's commitment to innovation resonates with your career goals. Mention specific aspects, such as the collaborative environment or the opportunity to mentor and lead projects, that make the role appealing to you.

Join Rise to see the full answer
Can you describe a complex technical initiative you led in your previous roles?

Detail a specific initiative where you played a key role from conception to execution. Highlight your problem-solving skills, technical expertise, and ability to collaborate with diverse teams. Be sure to quantify your impact, such as improved security metrics or process efficiencies.

Join Rise to see the full answer
How do you stay current with cybersecurity trends and technologies?

Discuss your methods for continuous learning, such as attending webinars, participating in workshops, engaging in online forums, or reading industry publications. Sharing specific examples will demonstrate your proactive approach to staying informed and adapting to the rapidly changing security landscape.

Join Rise to see the full answer
What is your approach to mentoring junior team members?

Explain your mentorship style, whether it’s hands-on or through structured training sessions. Emphasize the importance of fostering a collaborative environment and how you would encourage juniors to develop their skills, especially in secure coding practices and cybersecurity methodologies.

Join Rise to see the full answer
How do you prioritize tasks when managing multiple cybersecurity projects?

Share your approach to prioritization, possibly mentioning frameworks like the Eisenhower Matrix or agile methodologies. Highlight your ability to communicate with stakeholders to understand their needs and ensure that the most critical initiatives are addressed first.

Join Rise to see the full answer
What experience do you have with threat modeling and security assessments?

Be prepared to discuss specific methodologies you’ve employed in threat modeling, such as STRIDE or PASTA. Provide examples of security assessments you've conducted, emphasizing your findings and how they informed subsequent security measures or improvements.

Join Rise to see the full answer
Describe a time when you identified a gap in a security posture and how you addressed it.

Draw from a real-world example where you successfully identified vulnerabilities or gaps in security. Explain the steps you took to resolve these issues, including stakeholder engagement, research, and the tools or strategies you implemented to enhance security measures.

Join Rise to see the full answer
How do you communicate complex technical concepts to non-technical stakeholders?

Discuss your strategies for simplifying technical terminology and using analogies or visual aids. Give examples of past situations where you effectively communicated security concepts to non-technical teams or management, ensuring they understood the implications and benefits.

Join Rise to see the full answer
What role does automation play in your approach to cybersecurity?

Explore your understanding of automation in cybersecurity processes, mentioning specific tools or practices you've implemented. Share how automation improves efficiency, reduces human error, and allows your team to focus on higher-level strategic initiatives.

Join Rise to see the full answer
How do you handle conflicting priorities among teams or stakeholders?

Describe your conflict-resolution approach, highlighting open communication, negotiation skills, and a focus on aligning objectives with the organization's broader security goals. Share an example where you effectively mediated competing interests to find a successful solution.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Capital One Hybrid Richmond, Virginia, United States
Posted 9 days ago
NXTGIG Remote No location specified
Posted 14 days ago
Posted 5 days ago
Photo of the Rise User

Join Emory Healthcare as a Clinical Informatics Specialist III to lead and optimize clinical systems for patient care.

Photo of the Rise User
Eastern Fence Hybrid Fort Mill, South Carolina, United States
Posted 5 days ago

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran

916 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 31, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
32 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Xenia just viewed Permitting Associate at Flock Safety
Photo of the Rise User
Someone from OH, Lakewood just viewed Analyst-Treasury at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Educational Program Director at Tutor Me Education
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Director, Digital Marketing at UserTesting
Photo of the Rise User
39 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Product Manager, AI & STEM Specialist at Macmillan Learning
Photo of the Rise User
Someone from OH, Ashland just viewed Prior Authorization Specialist at LifeStance Health
Photo of the Rise User
Someone from OH, Ashland just viewed Prior Authorization Specialist at LifeStance Health
F
Someone from OH, Grove City just viewed Director of Internal Communications at Filevine
Photo of the Rise User
Someone from OH, Amelia just viewed Copy Editor (contract) at Morning Brew Inc.
Photo of the Rise User
Someone from OH, Versailles just viewed Parts Manager at Crown Equipment
Photo of the Rise User
Someone from OH, Cincinnati just viewed Bookkeeper - Franchise Location at H&R Block
Photo of the Rise User
Someone from OH, Dublin just viewed Cashier - Sawmill Road Market District at Giant Eagle
M
Someone from OH, Cincinnati just viewed Dental Practice Manager at Mortenson Family Dental
Photo of the Rise User
Someone from OH, Columbus just viewed Summer 2025 Data Intern at Reproductive Freedom for All
Photo of the Rise User
Someone from OH, Athens just viewed Medical Assistant - Podiatry - Athens at OhioHealth
K
Someone from OH, Dublin just viewed UI/UX Designer at Konrad
Photo of the Rise User
Someone from OH, Cleveland just viewed Marketing Analytics Intern - Summer 2025 at Spectrum