Cyber Security Technical GRC – VP

Not Interested
Bookmark
Report This Job

profile Job Location:

Jersey, NJ - USA

profile Monthly Salary: $ 144 - 167
Posted on: 15 hours ago
Vacancies: 1 Vacancy

Job Summary

Do you want your voice heard and your actions to count

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the worlds leading financial groups. Across the globe were 150000 colleagues striving to make a difference for every client organization and community we serve. We stand for our values building long-term relationships serving society and fostering shared and sustainable growth for a better world.

With a vision to be the worlds most trusted financial group its part of our culture to put people first listen to new and diverse ideas and collaborate toward greater innovation speed and agility. This means investing in talent technologies and tools that empower you to own your career.

Join MUFG where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

Job Summary:

This role is a member of the CISO of Americas team with primary focus on the Enterprise Information Systems (EIS) Governance Risk and Compliance (GRC) team.Theposition requires adeep understanding of how cloud environments arewellarchitected andidentifyingrisks associated with the servicesutilizedand challenging the architecture(s) and implementation.

As an individual contributoryou will act within thefirst line of defense contributing to complex critical disciplines includingCloud Security Governance Policy Management Cybersecurity Controls & Reporting and Cyber Risk Quantificationacross hybrid (cloud andon premise) environments. The role emphasizes comprehensive risk managementidentifying assessing and managing inherent control and residual riskswhileauditing cloud technologies wearing multiple hatswritingexecutive-ready reports andrelaying risk clearly to senior leaders.

Responsibilities:

Cloud & Cyber Risk Management

  • Drive risk management initiatives formulticloud environments; ensure alignment with enterprise security standards and regulatory expectations.
  • Understand thetechnicalarchitecture and operational setup of cloud servers and provider integrations to evaluate exposure control effectiveness andresidual
  • Support internal projects addressing cloud cybersecurity threats; assess the effectiveness and comprehensiveness of first-linecybersecuritycontrols
  • Review and challenge risk assessments scenario analyses control testing and remediation plans;assistwith issue oversight and escalations.
  • Monitor and analyze risk trends (internal and external) to proactively mitigate potential issuesimpactingcloud security posture.
  • Promote actions to address root causes of risks

Cybersecurity Controls & Reporting

  • Represent EIS GRC in working groups focused on cloud security andmulti levels of reporting
  • Translate complex cloud and cybersecurity concepts into clearbusiness termsfor non-technical stakeholders and senior management across the Combined U.S. Operations.
  • Prepareconcise executive-level reportson risk management activities control outcomes and emerging issues for senior leadership.

Cyber Risk Quantification

  • Collaborate on initiatives that strengthen the enterprise cybersecurity program; ensure projects align with the cloud security governance model.
  • Regularly review and update risk frameworks to reflect changes in thecloud threat landscape including Oracle-specific risks.
  • Lead discussions at all levels to incorporatecloud security risk elementsinto business strategies and decision-making.
  • Guidelinesof businessthrough cloud security assessments translating technical/security questions intobusiness impact and prioritization.

Auditing & Compliance

  • Conduct and/or overseeaudits andotherassessments of cloud technologies andon-prem technologies ensuringeffectiveness sustainability and maturitycontrols.
  • Ensure adherence to regulatory requirements and internal policies including coordination on remediation of identified gaps.
  • Support oversight activities related to enforcement agencies regulatory examinationsand related obligations.

Emerging Security Trends

  • Stay current withmultipleCloudplatforms forbestpractices emerging technologies and regulatory changesimpactingcloud environments.
  • Leverage insights to enhance the security posture and influence strategic roadmaps across business and technology teams.

KRIs & Metrics

  • Influence comprehensive and consistent practices toidentify measure monitor report and manageinformation risks.
  • Ensure metric quality and relevance (e.g. control efficacy incident trends misconfiguration rates vulnerability aging and remediation timeliness).

Qualifications:

  • 610 yearsof experience across risk management cloud information security governance and/or IT audit; prioraudit experience is a plus.
  • Strong understanding ofcloud architecture and provider integrations including how enterprise servers and services interface with cloud providers
  • Experienceauditing cloud technologies wearing multiple hats in GRC contextswritingexecutive-ready reports andrelaying risk to executives.
  • High technical knowledge across cybersecurity domains (IAM Data Security Configuration Management Log Generation Incident ResponseSecurity riskAssessment/TestingMethodologies Secure SDLC) with specific experience evaluating the adequacy and efficiency ofCloudControls.
  • Knowledge of domestic and international banking regulations (e.g.Reg W Basel II FFIEC GDPR) and experience with enforcement agency oversight activities (e.g.MRAs consent orders) especially within systemically important financial institutions.
  • Understanding ofthe regulatory environment and expectations related to technology risk (OCCFRB and Cyber Risk Institute (CRI)).
  • Professional certifications in major cloud providers for security

Education & Certifications:

  • Bachelors degree in Information Security or a closely related discipline or equivalent related experience

Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.

The typical base pay range for this role is between $144K - $167K depending on job-related knowledge skills experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits retirement plans educational assistance and training programs income replacement for qualified employees with disabilities paid maternity and parental bonding leave paid vacation sick days and holidays. For more information on our Total Rewards package please click the link below.

MUFG Benefits Summary

We will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance (ii) the City of Los Angeles Fair Chance Initiative for Hiring Ordinance (iii) the Los Angeles County Fair Chance Ordinance and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment if any.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.

We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race color national origin religion gender expression gender identity sex age ancestry marital status protected veteran and military status disability medical condition sexual orientation genetic information or any other status of an individual or that individuals associates or relatives that is protected under applicable federal state or local law.


Required Experience:

Exec

Do you want your voice heard and your actions to count Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG) one of the worlds leading financial groups. Across the globe were 150000 colleagues striving to make a difference for every client organization and community we serve. We stand...
View more view more

Key Skills

  • B2C
  • ABAP
  • Fpga
  • Front Office
  • Body Care
  • Insurance Sales

About Company

Company Logo

MUFG is a leading global financial group backed by 2,700 locations in over 50 countries and regions, offering comprehensive and tailored financial solutions to our clients worldwide.

View Profile View Profile