Cyber Security Technical Advisor (GRC) - AVP

MUFG Bank, Ltd.$90K — $153K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in risk management, information security, and IT roles; audit experience a plus.
  • Deep understanding of cloud security practices for major providers.
  • Proficient in writing process documentation and executing control test scripts.
  • Knowledgeable in banking regulations (Basel II, GDPR, etc.) and compliance oversight activities.
  • Familiar with technology risk regulations and expectations from OCC and FRB.
  • Holds relevant certifications such as CISA, CISSP, or CRISC.
  • Strong analytical, organizational, and communication skills.

Responsibilities

  • Maintain knowledge of security regulations and best practices.
  • Evaluate alignment of internal controls with standards and requirements.
  • Communicate cybersecurity topics clearly to business units.
  • Manage internal controls to mitigate cyber risks effectively.
  • Support governance through monitoring relevant KPIs and KRIs.
  • Address control gaps with timely remediation plans.
  • Drive the implementation and sustainability of the security control framework.

Benefits

  • Comprehensive health and wellness benefits.
  • Retirement plans with company contributions.
  • Educational assistance and training programs.
  • Paid maternity and parental bonding leave.
  • Paid vacation, sick days, and holidays.
Full Job Description
Cyber Security Technical GRC - AVP

Job Summary: This role is a member of the CISO of America's team and will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems and information assets are appropriately protected within the Cloud and on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of inherent, control, and residual risks.

Primary Responsibilities:
Regulatory and Compliance
  • Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological solutions to meet enterprise needs.
  • Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
Communication and Guidance
  • Provide clear and consistent communications to lines of business related to cybersecurity topics. Guide the lines of business through assessments, translating the technology/security questions so that they can be understood by the business; then guide them as to how to gather the required information.
Risk Management and Control
  • Ensure that internal controls designed to mitigate technology and cyber risks are managed, mitigated, and commensurate with the business risk.
  • Support Information Security oversight and governance by ensuring the control environment is monitored through relevant KRI/KPIs.
  • Ensure gaps are addressed via remediation plans with timely resolution which address root cause of control failures.
Reporting
  • Compile and distribute program level reporting to relevant stakeholders.
Implementation and Sustainability
  • Drive implementation, sustainability, and maturity of the firm's Information Security control framework.

Qualifications:
  • Experience: Minimum of 5-7 years' experience in a combination of risk management, information security, and IT roles. Prior audit experience a plus. High technical knowledge across Cybersecurity domains such as Identity Access Management, Data Security, Configuration Management, Log Generation, Incident Response, security risk assessment/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls; and identifying issues resulting from internal and/or external compliance examinations especially in cloud environments.
  • Cloud Security: In-depth knowledge of cloud security practices and technologies for major providers.
  • Documentation: Experience in writing process documentation and designing/executing control test scripts.
  • Regulatory Knowledge: Knowledge of domestic and international banking regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with enforcement agencies oversight activities (regulatory examinations, matters requiring attention (MRAs), consent orders, etc.) within a global systemically important financial institution's information technology and information security environments.
  • Technical Understanding: Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations.
  • Certifications: Professional certifications such as CCAK, CISA, CRISC, CISM, CGEIT, CSX, CISSP.
  • Collaboration: Ability to constructively work both independently and in collaborative environments involving all levels of management and employees.
  • Multitasking: Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality.
  • Education: Bachelor's degree in related IT or Information Security disciplines.
  • Skills: Excellent analytical, organizational, and conceptual skills. Excellent oral and written communication skills.

Education & Certifications:

Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience.

Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.

The typical base pay range for this role is as follows:

New York / New Jersey: $90k-153k

Non NY/NJ: $90k-141k
  • This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
  • MUFG Benefits Summary


The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.

About MUFG Bank, Ltd.

MUFG Bank, Ltd. Careers

There has never been a better time to join the global team at MUFG Bank, Ltd., a premier institution recognized for its leadership in the financial sector. MUFG Bank, Ltd. offers a plethora of job opportunities that cater to a variety of skills and interests, all while fostering professional growth and innovation.

Work You’ll Do

Join MUFG Bank, Ltd.'s distinguished team to assist some of the most sophisticated clients in navigating their financial landscapes. At MUFG Bank, Ltd., team members lead from a unique position in the marketplace, at the crossroads of financial expertise, industry knowledge, and digital innovation. Engage with a global team of business and financial advisors to help clients master their economic strategies and challenges. Collaborate with the largest group of finance professionals in the industry – a network that spans across continents offering unmatched opportunities for networking and professional development.

Introducing the MUFG Bank, Ltd. Business Advisory

The team is dedicated to building a leading Advisory group to guide some of the most renowned companies through their financial strategies using innovative solutions.

Do Innovative Work

Be part of a team that delivers targeted financial solutions through a depth and breadth of consulting experience and innovation that’s second to none.

Be Part of a Great Team

Work on a wide range of financial technologies and harness the unparalleled capabilities, global scale, and joint solution development that only MUFG Bank, Ltd. can offer.

Future-Proof Your Career

Advance your career as far as your ambition can take you with limitless opportunities supported by unmatched training, development, and certification support.

Explore

Discover how MUFG Bank, Ltd. is leading the way in financial innovation with cutting-edge projects like blockchain for secure transactions and AI for risk assessment.

The MUFG Bank, Ltd. Alliance

The combined service capabilities, global scale, and joint solution development enable clients to overcome challenges and lead transformation in their industries. Clients worldwide turn to MUFG Bank, Ltd. for new strategies and financial solutions to drive growth and success in the digital era.

Stay Connected

Join the Team

Search open positions that match your skills and interests. MUFG Bank, Ltd. seeks passionate, curious, creative, and solution-driven team players.

SEARCH MUFG JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at MUFG Bank, Ltd.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at MUFG Bank, Ltd.
Learn more about MUFG Bank, Ltd.

Similar Jobs

More Jobs at MUFG Bank, Ltd.

More Finance & Insurance Jobs

Find similar Cyber Security Technical Advisor (GRC) - AVP jobs: