Mizuho Financial

Cyber Defense, Adversary Emulation Director

Mizuho Financial$150K — $250K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in information security, with expertise in vulnerability management, threat intelligence, threat hunting, and red team operations.
  • Proven track record in leading red team and adversary emulation engagements with actionable remediation.
  • Hands-on experience in robust vulnerability management programs across infrastructure and cloud environments.
  • Strong knowledge in threat intelligence and operationalizing threat actor TTPs related to MITRE ATT&CK.
  • Demonstrated ability in threat hunting across multiple telemetry sources to uncover systemic security weaknesses.
  • Proficiency in scripting languages like Python or PowerShell for automation and analysis in security workflows.
  • Bachelor's or Master’s degree in a related field, or equivalent practical experience.

Responsibilities

  • Lead and mature the enterprise vulnerability management program focusing on risk-based remediation.
  • Direct threat intelligence operations to inform security priorities and proactive hunting initiatives.
  • Plan and execute threat hunting campaigns to identify malicious activities and misconfigurations.
  • Design and lead red team exercises simulating real-world attacks to assess organizational defenses.
  • Translate vulnerability findings into actionable remediation guidance tailored for stakeholders.
  • Collaborate with security operations and incident response teams for risk mitigation and posture improvement.
  • Establish metrics to measure the effectiveness of security programs and remediation efforts.

Benefits

  • Medical, Dental, and 401K plans.
  • Eligibility for discretionary bonuses based on performance.
  • Flexible hybrid work program with varying remote work opportunities.
Full Job Description

The Cyber Defense organization within Mizuho Americas Services (MAS) operates under the CISO and is responsible for identifying, analyzing, and mitigating cyber threats across the Mizuho enterprise. The Adversary Emulation function play a critical role in proactively improving the firm’s security posture by leveraging vulnerability intelligence of real‑world threats, identifying systemic weaknesses, and driving remediation across infrastructure, applications, and cloud environments.

The Adversary Emulation Director leads Mizuho's proactive security functions, with primary responsibility for vulnerability management, threat intelligence, threat hunting, and red team operations across the enterprise. This role focuses on identifying, prioritizing, and driving remediation of real-world threats and across the enterprise, thinking like an attacker to emulating adversary tactics to continuously test and strengthen the firm's defenses.

The role combines deep hands-on offensive and threat expertise with strategic leadership, partnering with security engineering, incident response, and technology teams to translate threat insight into measurable risk reduction. Automation, AI-enabled tooling, and workflow orchestration are applied to scale these capabilities and improve analyst efficiency, but they supplement — rather than define — the core mission of vulnerability management, threat intelligence, threat hunting, and adversary emulation.

Key Responsibilities

  • Lead and mature the enterprise vulnerability management program, including discovery, risk-based prioritization, remediation tracking, and reporting across infrastructure, applications, and cloud environments.
  • Direct threat intelligence operations, collecting and analyzing intelligence on threat actors, tactics, techniques, and procedures (TTPs), and emerging vulnerabilities to inform defensive priorities and proactive hunting.
  • Plan and lead threat hunting campaigns that proactively identify malicious activity, misconfigurations, and systemic weaknesses across endpoint, network, and cloud environments.
  • Design and lead red team and adversary emulation exercises that replicate real-world attacker tactics to test detection, response, and control effectiveness across the enterprise.
  • Translate findings from vulnerability management, threat intelligence, hunting, and red team activity into clear, prioritized, and actionable remediation guidance for engineering and business stakeholders.
  • Partner with Security Operations, incident response, and infrastructure teams to drive closure of identified weaknesses and continuously improve the firm's security posture.
  • Establish metrics, reporting, and governance that measure risk reduction, remediation timeliness, and the effectiveness of the firm's offensive and proactive security programs.
  • Develop and mentor a team of analysts and engineers across vulnerability management, threat intelligence, threat hunting, and red team functions, fostering a collaborative, learning-driven culture.
  • Leverage automation, AI-enabled tooling, and workflow orchestration to scale vulnerability triage, threat analysis, and hunting, reducing manual effort while maintaining accuracy, auditability, and control.
  • Contribute to standards, playbooks, documentation, and controls that promote consistency, repeatability, and shared ownership across the firm's proactive and offensive security functions.

Qualifications

  • 10+ years of experience in information security, with deep expertise across vulnerability management, threat intelligence, threat hunting, red team, or offensive security, preferably within financial services or another regulated enterprise environment.
  • Proven experience leading or executing red team and adversary emulation engagements, including planning, execution, and translating findings into actionable remediation.
  • Hands-on experience running vulnerability management programs and platforms, including discovery, risk-based prioritization, and remediation tracking across infrastructure, applications, and cloud, preferably for a global organization.
  • Strong threat intelligence experience — collecting, analyzing, and operationalizing threat actor TTPs and emerging vulnerabilities, mapped to frameworks such as MITRE ATT&CK.
  • Demonstrated threat hunting experience across endpoint, network, and cloud telemetry to proactively detect malicious activity and systemic weaknesses.
  • Strong hands-on scripting skills (Python, PowerShell, or similar) to support testing, analysis, and automation of offensive and proactive security workflows.
  • Strong understanding of offensive security tooling and techniques, such as command-and-control (C2) frameworks, exploitation, penetration testing methodologies, and adversary TTP emulation.
  • Strong understanding of cybersecurity operations, threat detection, incident response, vulnerability management, cloud security, and security monitoring concepts.
  • Familiarity with governance models, control requirements, auditability, and risk management practices applicable to automation in a regulated environment.
  • Ability to collaborate with security engineers, analysts, architects, and business stakeholders to drive prioritized remediation and risk reduction aligned to operational priorities.
  • Strong written and verbal communication skills, with the ability to explain technical concepts, threats, risks, and remediation priorities to both technical and non-technical audiences.
  • Educational background with a BS/MS in Information Technology, Computer Science, Engineering, Cybersecurity, or a related field, or equivalent practical experience.

Additional Qualifications

  • Hands-on experience with vulnerability management platforms, SIEM, EDR/XDR, threat intelligence platforms, and offensive security tooling (e.g., Cobalt Strike, Metasploit, BloodHound, Nmap, Burp Suite).
  • Experience applying AI or LLM-based tooling to security workflows — such as automated triage, enrichment, or human-in-the-loop analysis — as a supplement to core offensive and threat capabilities.
  • Experience assessing cloud security, containerization, and infrastructure as code from an offensive or adversarial perspective.
  • Relevant certifications such as OSCP, OSEP, GXPN, GPEN, GCIH, GCTI, GREM, CISSP, or CISM.
  • Experience working in financial services, banking, or another highly regulated environment.
  • Demonstrated ability to build playbooks, documentation, standards, and shared practices across proactive and offensive security teams.

The expected base salary ranges from $150,000 - $250,000. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, including Medical, Dental and 401K plans, successful candidates are also eligible to receive a discretionary bonus.

#LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.

About Mizuho Financial

Mizuho Financial Group, Inc. is a Japanese banking holding company headquartered in the ?temachi district of Chiyoda, Tokyo, Japan. The name "mizuho" literally means "abundant rice" in Japanese. It holds assets in excess of $1.8 trillion US dollars through its control of Mizuho Bank, Mizuho Corporate Bank, and other operating subsidiaries. The company's combined holdings form the second largest financial services group in Japan. Its banking businesses rank third in Japan after Mitsubishi UFJ Financial Group and Sumitomo Mitsui Financial Group. It is the 15th largest banking institution in the world by total assets as of December 2018.
Learn more about Mizuho Financial
Size
54,492 employees
Market Cap
$35 billion
Industry
Net Income
$84.4 billion
5 Year Trend
-0.6%
NASDAQ

Similar Jobs

More Jobs at Mizuho Financial

More Information Technology Jobs

Find similar Cyber Defense, Adversary Emulation Director jobs: