Cyber Risk Oversight

Not Interested
Bookmark
Report This Job

profile Job Location:

London - UK

profile Monthly Salary: Not Disclosed
Posted on: 21 hours ago
Vacancies: 1 Vacancy

Job Summary

Do you want your voice heard and your actions to count

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the worlds leading financial groups. Across the globe were 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world.

With a vision to be the worlds most trusted financial group its part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career.

Join MUFG where being inspired is expected and making a meaningful impact is rewarded.

OVERVIEW OF THE DEPARTMENT/SECTION

We are MUFG. 360 years of heritage. A world-class set of businesses. And more than 180000 employees in 50 markets. Its no surprise that MUFG has grown to become one of the top five banks in the world. Our services include commercial banking trust banking securities credit cards consumer finance asset management and leasing. MUFG offers stability in an ever-changing market providing services to high-profile clients worldwide.

The Groups operating companies include MUFG Securities EMEA plc and MUFG Bank.

The role sits in the Operational Risk Management team that reports into the Chief Risk Officer.

The Operational Risk Management team is responsible for running the Operational Risk Management Framework and conducting oversight activities across the EMEA region. Within the scope of responsibilities of ORM is the Second Line of Defense activities for Technology Risk Cyber Security. Third Party Management and Operational Resilience.

The Director of Technology Operational Risk for EMEA is seeking to enhance the organisations Cyber Risk framework and capabilities to ensure the firm remains appropriately protected in the evolving threat landscape and enable ORMD to provide appropriate input and oversight.

NUMBER OF DIRECT REPORTS

0

MAIN PURPOSE OF THE ROLE

To assist with the development of the firms Second Line of Defence capabilities (policies procedures risks and controls) to manage Information Security and Cyber risk in London and further support across the EMEA region in line with regulatory requirements and to support the achievement of the Banks strategic objectives.

KEY RESPONSIBILITIES

  • Assist with the continuous embedding of the Operational Risk framework for the Technology and Cyber risks and controls within the Technology function working in conjunction with the First Line teams and Head Office.
  • Monitoring regulatory changes in approach to Technology and Cyber and recommend changes enhancements to the Control framework.
  • Support the development and delivery of medium to long term objectives and actions within the framework including greater oversight and additional testing of the Technology and Cyber Controls and RCSAs.
  • Participate actively in the delivery of changes enhancements and projects in conjunction with the Cyber Security teams.
  • Provide robust challenge to the First Line of Defence as they identify assess manage and report their risks and issues through various tools and activities including risk and control assessments key indicators issue and incident management and control assurance.
  • Deep dive on the Technology and Cyber KPI/KRIs monitoring monthly trends and threats. Provide challenge on a SME level to the 1st line.
  • Perform Second Line of Defence activities in the evaluation of risks for new products systems and material change projects.
  • Provide subject matter expertise and monitor and communicate the risk environment to management and other key stakeholders effectively.
  • When required supervise junior members of the team in second line oversight business-as-usual (BAU) activities and change initiatives.
  • Assist in the creation and maintenance of a good 3LoD model and work across the region to promote Technology and Cyber Awareness and 2nd line challenge.

Regulatory compliance affairs and change:

  • Comply with and ensure that all staff under your responsibility (where applicable) comply with the entities policies and procedures as well as all rules laws and regulatory requirements emanating from any of the regulatory authorities to which the entities are subject.
  • Remain up to date with regulatory changes; ensure that changes are well understood and plans are developed for implementation as appropriate.

WORK EXPERIENCE

  • Knowledge of banking and securities products and services.
  • Excellent knowledge and experience of Information Security Technology and Cyber risk management and their application within the financial services industry.
  • Proven and demonstrable ability to understand identify analyse and communicate clearly an organisations Technology and Cyber risks.
  • Proven experience in interpreting understanding and applying legal/regulatory requirements to technology and cyber security.
  • Solid technical and functional knowledge of external regulations policies and developments for Information Security and Cyber Risk and ability to read across to understand organizational impact.
  • Solid technical and functional knowledge of financial services internal rules and policies.
  • Good understanding of the overall operational processes and technology challenges within the financial services industry.
  • Ability to facilitate smooth communications between London HO and EMEA offices.

SKILLS AND EXPERIENCE

Functional / Technical Knowledge and Awareness:

  • Cyber and Information Security best practice (including industry frameworks such as NIST and ISO 27001/2)
  • Cyber Security Risk Assessment and Risk management experience with a focus on;
    • Threat Modelling
    • Vulnerability Risk
    • Cloud Security Risk
    • IAM Risk
    • Network and System Risk
    • Third Party Risk
  • Knowledge of Cyber Incident detection response and remediation best practice
  • Understanding of Governance compliance and audit approaches
  • Knowledge of data analysis methods for risk modelling would be advantageous

Education / Qualifications:

  • Educated to degree level or equivalent industry experience
  • CISSP CISM or equivalent Information Security certifications are desirable

PERSONAL REQUIREMENTS

  • Strong team player with the ability to collaborate with business stakeholders.
  • Clear and concise written and oral communication.
  • Ability to translate technical requirements for a general audience
  • Strong analytical skills to evaluate risk understand and communicate underlying causes
  • Excellent accuracy and attention to detail.
  • Good time management and ability to prioritise.
  • Strong problem-solving and critical thinking skills.
  • Excellent Microsoft Office skills
  • Japanese language ability advantageous

PERFORMANCE AND DUTIES

The role holder will be assessed in accordance with their employing entitys performance framework and process with relevant input obtained from the dual hatting entity as relevant.

As duties and responsibilities change the job description will be reviewed and amended in consultation with the role holder. The role holder will carry out other duties as are within the scope spirit and purpose of the role as requested by their line manager or Department Head.

MANAGING CONFLICTS OF INTEREST

  • The role holder will have responsibilities for both MUFG Bank and MUFG Securities EMEA plc.
  • The role holder will be required to perform their duties and responsibilities on an entity neutral basis without favour.
  • The role holder is required to follow regulatory requirements applicable to ensure each business is appropriately supported and to maintain the legal entity integrity of each of MUFG Bank and MUS.
  • Working terms are dictated by functional mandates the terms of the Dual-Hat Arrangement Agreement in place between MUFG Bank and MUFG Securities EMEA plc and any other relevant agreements entered into between MUFG Bank and MUFG Securities EMEA plc.
  • The role holder will have responsibility for identifying and resolving where there may be a difference or conflict in needs between MUFG Bank and MUFG Securities EMEA plc escalating to their manager where required.

We are open to considering flexible working requests in line with organisational requirements.

MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued respected and their opinions count. We support the principles of equality diversity and inclusion in recruitment and employment and oppose all forms of discrimination on the grounds of age sex gender sexual orientation disability pregnancy and maternity race gender reassignment religion or belief and marriage or civil partnership.

We make our recruitment decisions in a non-discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law.

Do you want your voice heard and your actions to count Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the worlds leading financial groups. Across the globe were 150000 colleagues striving to make a difference for every client organization and community we serve. We stand...
View more view more

Key Skills

  • Diploma
  • DCS
  • ABAP
  • Application Development
  • Irrigation
  • Bakery

About Company

Company Logo

MUFG is a leading global financial group backed by 2,700 locations in over 50 countries and regions, offering comprehensive and tailored financial solutions to our clients worldwide.

View Profile View Profile