Cybersecurity Control Testing Lead, VP

MUFG Bank, Ltd.$147K — $194K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in technology risk, IT audit, cybersecurity, control testing, or related roles, including team leadership experience.
  • Strong understanding of cloud and hybrid control environments, including on-premises infrastructure.
  • Expertise in testing technical controls such as access management, change management, and network security.
  • Knowledge of secure software development lifecycle practices and production change governance.
  • Proven leadership skills to manage team performance and deliver quality outcomes across multiple testing activities.
  • Strong analytical skills to assess control design and operating effectiveness through evidence-based methods.
  • Effective communication skills to engage both technical and non-technical stakeholders.

Responsibilities

  • Lead and manage a team in control testing activities across various environments with a focus on cloud services.
  • Define testing strategy and oversee risk-based test plans while ensuring consistent documentation practices.
  • Set goals for direct reports, review their work, and provide ongoing coaching and development support.
  • Assess the effectiveness of controls through detailed reviews of system configurations and policies.
  • Promote continuous, automated control monitoring to reduce reliance on manual testing methods.
  • Evaluate technical controls across cloud and on-premises platforms for effective risk management.
  • Work collaboratively with Cybersecurity GRC and other stakeholders to ensure compliance and validation.

Benefits

  • Comprehensive health and wellness benefits.
  • Retirement plans with competitive options.
  • Educational assistance and training programs.
  • Income replacement support for employees with disabilities.
  • Paid maternity and parental bonding leave.
  • Generous paid vacation, sick days, and holidays.
Full Job Description


The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

The Control Testing Lead will be responsible for leading a team that plans, executes, documents, and reports results for technology control testing across cloud and on-premises environments. This role will manage direct reports, establish testing priorities, oversee quality of execution, and drive consistent control testing practices across technical domains. The role requires strong knowledge of cybersecurity, cloud security, technical controls, infrastructure control design, software development lifecycle practices, and risk-based assurance methodologies.

This position will serve as a team leader within a broader Cybersecurity GRC control assurance operating model, accountable for directing testing activities, developing team capability, influencing control quality, and providing insight to engineering, security architecture, application, infrastructure, audit, risk, and compliance stakeholders. The role will work extensively with Cybersecurity GRC to align testing priorities, evidence standards, issue rationale, reporting expectations, and remediation themes while helping ensure that controls are appropriately designed, operating effectively, supported by reliable evidence, and aligned to regulatory, internal policy, and industry framework requirements.
Key Responsibilities
  • Lead and manage a team responsible for control testing activities across cloud, hybrid, and on-premises environments, with emphasis on cloud services, infrastructure, identity, access, configuration, logging, monitoring, vulnerability management, and change management controls.
  • Set testing strategy, define annual and quarterly priorities, oversee risk-based test plans, and ensure test scripts, walkthrough procedures, evidence requests, sampling approaches, and testing documentation are consistent and defensible.
  • Manage direct reports by setting goals, assigning work, reviewing deliverables, providing coaching, supporting career development, and maintaining accountability for quality, timeliness, and risk-based judgment.
  • Assess control design and operating effectiveness by reviewing system configurations, architecture patterns, policies, procedures, tickets, logs, screenshots, reports, and other supporting evidence.
  • Drive continuous, automated control monitoring and assurance to reduce manual, point-in-time validation
  • Evaluate technical controls across cloud platforms, including identity and access management, network segmentation, encryption, key management, logging, monitoring, workload protection, vulnerability remediation, backup and recovery, and secure configuration baselines.
  • Evaluate on-premises technical controls across servers, databases, network devices, endpoints, applications, data centers, and supporting infrastructure.
  • Review software development lifecycle and secure delivery controls, including secure design, threat modeling, code review, testing, deployment pipeline controls, release management, change approvals, segregation of duties, and production deployment governance.
  • Identify control gaps, evidence deficiencies, design weaknesses, and operating issues, document clear observations, risk impacts, root causes, and practical remediation recommendations.
  • Work extensively with Cybersecurity GRC, compliance, audit, application, infrastructure, cloud engineering, and security architecture stakeholders to validate control performance, align on testing expectations, resolve control evidence questions, and support consistent issue treatment.
  • Provide leadership, coaching, and technical guidance to control testers, analysts, and stakeholders on testing methodology, evidence standards, technical control concepts, documentation quality, and audit-ready conclusions.
  • Own testing progress, issue status, remediation themes, management reporting, audit readiness, risk and control forums, assurance routines, and continuous improvement of the control testing function.
Required Qualifications
  • 10+ years of experience in technology risk, IT audit, cybersecurity, control testing, cloud security, infrastructure security, or related technical assurance roles, including experience leading teams or managing direct reports.
  • Strong understanding of cloud and hybrid control environments, with practical knowledge of on-premises infrastructure control concepts.
  • Strong understanding of AI models and ability to define and execute appropriate assessment strategy
  • Demonstrated experience testing technical controls, including access management, privileged access, change management, vulnerability management, logging and monitoring, encryption, backup and recovery, incident response, configuration management, and network security.
  • Strong understanding of software development lifecycle practices, secure delivery methods, deployment controls, release management, and production change governance.
  • Ability to lead testing teams, manage performance, review workpapers, develop talent, resolve execution blockers, and maintain consistent quality across concurrent testing activities.
  • Strong analytical judgment with the ability to assess control design and operating effectiveness using evidence-based testing.
  • Ability to interpret technical evidence and translate findings, risk themes, control gaps, and remediation trends into clear documentation, leadership messaging, and actionable management reporting.
  • Strong communication and stakeholder management skills, including the ability to engage technical and non-technical audiences, challenge control design constructively, and influence outcomes.
  • Ability to manage multiple testing workstreams, prioritize risk-based activities, escalate risks appropriately, and deliver high-quality outcomes within established timelines.
Education
  • Bachelor's degree in computer science or a closely related discipline, or an equivalent combination of formal education and experience

Other Details
  • The typical base pay range for this role for NY/NJ is between $147k - $194k depending on job-related knowledge, skills, experience, and location. Non NY/NJ is 144k-180k
  • This role may also be eligible for certain discretionary performance-based bonuses and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
  • VISA sponsorship is not available for this position


The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.

About MUFG Bank, Ltd.

MUFG Bank, Ltd. Careers

There has never been a better time to join the global team at MUFG Bank, Ltd., a premier institution recognized for its leadership in the financial sector. MUFG Bank, Ltd. offers a plethora of job opportunities that cater to a variety of skills and interests, all while fostering professional growth and innovation.

Work You’ll Do

Join MUFG Bank, Ltd.'s distinguished team to assist some of the most sophisticated clients in navigating their financial landscapes. At MUFG Bank, Ltd., team members lead from a unique position in the marketplace, at the crossroads of financial expertise, industry knowledge, and digital innovation. Engage with a global team of business and financial advisors to help clients master their economic strategies and challenges. Collaborate with the largest group of finance professionals in the industry – a network that spans across continents offering unmatched opportunities for networking and professional development.

Introducing the MUFG Bank, Ltd. Business Advisory

The team is dedicated to building a leading Advisory group to guide some of the most renowned companies through their financial strategies using innovative solutions.

Do Innovative Work

Be part of a team that delivers targeted financial solutions through a depth and breadth of consulting experience and innovation that’s second to none.

Be Part of a Great Team

Work on a wide range of financial technologies and harness the unparalleled capabilities, global scale, and joint solution development that only MUFG Bank, Ltd. can offer.

Future-Proof Your Career

Advance your career as far as your ambition can take you with limitless opportunities supported by unmatched training, development, and certification support.

Explore

Discover how MUFG Bank, Ltd. is leading the way in financial innovation with cutting-edge projects like blockchain for secure transactions and AI for risk assessment.

The MUFG Bank, Ltd. Alliance

The combined service capabilities, global scale, and joint solution development enable clients to overcome challenges and lead transformation in their industries. Clients worldwide turn to MUFG Bank, Ltd. for new strategies and financial solutions to drive growth and success in the digital era.

Stay Connected

Join the Team

Search open positions that match your skills and interests. MUFG Bank, Ltd. seeks passionate, curious, creative, and solution-driven team players.

SEARCH MUFG JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at MUFG Bank, Ltd.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at MUFG Bank, Ltd.
Learn more about MUFG Bank, Ltd.

Similar Jobs

More Jobs at MUFG Bank, Ltd.

More Information Technology Jobs

Find similar Cybersecurity Control Testing Lead, VP jobs: