ForgeApply · Job listing
Director, Brex Integration Advisory & Oversight
Capital One
Tailor your resume to this posting in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Capital One's site. Free trial, no card required.
About this role
Director, Brex Integration Advisory & Oversight
Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the public cloud over the course of five years. Just as we prioritize driving innovation through technology, we equally prioritize cybersecurity, reliability, software quality, and data management.
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 professionals in TDRM are trusted experts who oversee ~14,000 developers at Capital One. We raise the bar for excellence in cybersecurity, reliability, tech risk, and data management risk. We shape strategy and decisions, challenge activities to ensure they meet our standards, and perform independent tests of our security and technology risk.
For years, the cybersecurity community has debated whether the CISO should report to the CIO or not. In regulated financial services, the answer is: both. The first-line CISO has operational responsibilities and reports to the CIO. The second-line Chief Tech Risk Officer (CTRO) and the Tech & Data Risk Management (TDRM) organization have broader responsibilities for cybersecurity but also reliability, software quality, resilience, and the risk of failing to manage our data. The CTRO is independent and oversees the work of the CISO, the CIO/CTO, and the Chief Data Officer. The CTRO reports to the Chief Risk Officer, who reports directly to the CEO.
Our business leaders must constantly make technology decisions. TDRM makes sure they have the tech and data risk information they need to make good decisions. Associates within TDRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a wealth of experience and a demonstrated ability to add value with their advice and to deliver high-impact results.
Role Summary The Director, Brex Integration Advisory & Oversight will serve as the primary second-line Technical Risk Advisor and Oversight Lead for the Brex integration. This highly strategic individual contributor role spans all domains of cybersecurity, technology risk, and artificial intelligence governance. In this role, you will lead the independent second-line risk oversight for Brex’s entire integration IT footprint, including cloud and application architectures, collaboration tooling, data transfer systems, HR platforms, and AI systems.
You will act as an independent advisor and a rigorous challenger—synthesizing risk assessments conducted by specialized subject matter experts across the division while leveraging your own deep technical acumen to identify gaps in first-line assessment methodologies, surface hidden risks, and challenge missing mitigations. Additionally, you will define and catalog repeatable second-line security governance standards and architectural integration review patterns to serve as the “golden” oversight blueprint for all future corporate acquisitions.
A primary deliverable of this transformational role is the design and deployment of dynamic risk-tracking methodologies. These frameworks will independently measure, aggregate, and report on the state of residual risk and overall security posture at any given point in time (at minimum quarterly) to the second-line Chief Technology Risk Officer and Chief Risk Officer.
What You'll Do • Holistic Second-Line Oversight: Lead independent risk reviews of first-line technical integration plans, orchestrating comprehensive security and risk assessments across Brex’s cloud environment, application architecture, SaaS platforms, HR systems, collaboration tooling, and AI technologies.
• Rigorous Independent Challenge: Deeply analyze first-line assessment methodologies; identify operational gaps, uncover latent vulnerabilities, and constructively challenge missing risks or insufficient technical mitigations.
• M&A Pattern Definition: Establish high-level second-line security governance standards for corporate integrations, and catalog approved architectural integration patterns to serve as a repeatable reference playbook for future acquisitions.
• Transformational Risk Reporting: Design, deploy, and execute an independent, dynamic residual risk-tracking methodology to provide real-time and quarterly security posture updates to the Chief Technology Risk Officer and the Chief Risk Officer (non-technical executive).
• Enterprise Risk Alignment: Ensure interim risk-tracking methodologies align with the Enterprise Risk Management (ERM) framework and successfully mature to onboard into destination-state Systems of Record (SoR) as integration approaches convergence.
• High-Velocity Technical Advisory: Translate legacy technology, cybersecurity, and artificial intelligence requirements into flexible, developer-friendly guardrails optimized for a high-velocity, AI-native fintech environment, ensuring second-line risk standards are met.
• MVP & Product Influence: Collaborate with engineering and product teams from the Minimum Viable Product (MVP) stage onward, offering compelling, independent risk advice that balances technical security with business value and release speed.
• Executive-Level Risk Communication: Distill complex, multi-domain technical risks into clear, high-impact risk positions tailored for executive-level, non-technical audiences.
What We Are Looking For • Second-Line Advisory & Oversight Mindset: You possess broad-spectrum expertise across cloud security, corporate IT systems, application architecture, and AI governance, with the poise to represent the independent second-line risk division to senior executive stakeholders.
• SME Orchestration & Technical Depth: You can direct and coordinate the work of specialized technical risk teams while maintaining the deep technical capability to perfor
Ready to apply to Capital One?
Tailor my resume for this roleSimilar jobs
- Director, Compliance — Figure · Remote
- Director, Compliance — Dynetherapeutics · Remote
- Director, Compliance & Control Oversight - Growth — Upstart · Remote
- Director, Corporate Development — Updater · Remote
- Director, Internal Controls & Risk Management — 103644278 · New York, NY
- Director, Internal Controls & Risk Management — Flamingo · New York, NY
- Director, Transaction Services | Financial Due Diligence | Corporate Finance — Fticonsulting (FTIConsultingCareers) · San Francisco, CA
- Director of Partner Credit Risk Management & Oversight — Coastal · Remote
More like this: More jobs at Capital One · Browse all jobs