Global Director of Autonomous Cyber Defense and Security Event Triage (SOC)

MUFG Bank, Ltd.$203K — $249K *
Tempe, AZ 85281In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience
  • 7+ years of experience in Cybersecurity Operations or Information Security
  • Preferred technical certifications such as CISSP, ISSMP, GCIA, CISM, or CEH
  • Experience in security domains like Security Governance, Risk Management, Network Security, or Incident Response
  • Experience with information security risk management and conducting audits or assessments

Responsibilities

  • Direct and mature a global cyber operations model for security event monitoring and response
  • Own functional strategy and roadmap for autonomous cyber defense and security event triage
  • Collaborate with the Global Head to define and execute Autonomous Cyber Defense vision
  • Manage budget planning, vendor oversight, and financial governance for cyber operations
  • Lead and mentor high-performing global teams while establishing operational rhythms
  • Serve as a senior escalation contact for incident resolution in 24/7 environment
  • Provide oversight for audit and regulatory engagements related to cyber operations
  • Deliver reporting on cyber operations health, emerging threats, and risk posture
  • Drive initiatives for AI/ML-enabled autonomous defenses and continuous learning
  • Establish governance for detection engineering and triage standardization
  • Oversee monitoring of third-party security service providers
  • Build a program for analytics to improve response accuracy and efficiency

Benefits

  • Comprehensive health and wellness benefits
  • Retirement plans
  • Educational assistance and training programs
  • Income replacement for qualified employees with disabilities
  • Paid maternity and parental bonding leave
  • Paid vacation, sick days, and holidays
Full Job Description
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

The Global Director of Autonomous Cyber Defense and Security Event Triage leads the strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function. This role is accountable for globally protecting enterprise assets and services by driving outcomes across detection engineering, automated response, incident triage, and threat hunting. The director oversees global cyber operations performance, operating rhythms, and service delivery across multiple environments and partners, while owning budget planning and financial stewardship for the function. Additionally, the role advances autonomous defense capabilities by applying AI/ML and LLM-enabled workflows to improve alert quality, reduce time to detect/respond, and standardize decisioning, documentation, and remediation at scale. The director also ensures continuous validation of controls and detections through purple team execution aligned to adversary behaviors.

Major Responsibilities
  • Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments
  • Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage (e.g., MTTD/MTTR, false-positive reduction, containment SLAs)
  • Work with the Global Head to define the vision for Autonomous Cyber Defense and Security Event Triage, and execute against that vision in alignment with the strategic design
  • Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance
  • Lead, mentor, and scale high-performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on-call expectations
  • Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution
  • Provide executive-level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements
  • Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions
  • Drive AI/ML/LLM-enabled autonomous defense initiatives, including alert enrichment, case summarization, analyst co-pilots, automated containment, and continuous learning to improve signal-to-noise
  • Establish governance for detection engineering, triage decisioning, playbooks, and automation (SOAR/EDR/SIEM) to standardize response, reduce gaps, and improve response times
  • Lead critical incident triage and escalation governance; partner with incident response, infrastructure, identity, and application teams to coordinate containment and recovery
  • Oversee monitoring of third-party security service providers and managed tooling to ensure coverage, quality, and alignment to enterprise standards and SLAs
  • Build an operations analytics program to measure and continuously improve triage accuracy, response efficiency, backlog health, and automation effectiveness across regions and shifts
  • Sponsor and execute a purple team program (red/blue collaboration) to validate detections and response through adversary emulation aligned to MITRE ATT&CK; track gaps to closure
  • Oversee proactive threat hunting and continuous control validation to identify adversary behaviors, reduce dwell time, and harden critical services
  • Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones
  • Integrate threat intelligence, vulnerability insights, and attacker TTP research into detection logic, triage guidance, and autonomous response workflows
  • Produce and govern recurring and ad-hoc reporting on threats, trends, and program performance; ensure consistent narratives and decision support for stakeholders
  • Champion innovation and modernization of cyber defense tooling and techniques, including evaluation and adoption of new capabilities that measurably reduce risk
  • Partner with technology, product, and business leaders to align cyber operations priorities, drive remediation ownership, and embed security-by-design practices


Qualifications
  • Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience
  • 7+ years of experience working in the Cybersecurity Operations or Information Security
  • Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred
  • Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics preferred
  • Experience with information security risk management, including information security audits, reviews, and risk assessments


Desired Skills
  • Experience with security data collection, analysis and correlation
  • Well-developed analytic, qualitative, and quantitative reasoning skills
  • Demonstrated creative problem-solving abilities
  • Security event monitoring, investigation, and overall incident response process
  • Strong time management skills to balance multiple activities and lead junior analysts as needed
  • Understanding of offensive security to include common attack methods
  • Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event
  • A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures.
  • Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.)
  • Ability to guide and mentor junior analysts in investigations
  • Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tools, etc.)
  • Experienced with Endpoint Detection & Response, email security, web application firewall, and cloud security tooling.
  • Ability to perform risk analysis utilizing logs and other information compiled from various sources
  • Understanding of network protocols, operating systems (Windows, Unix, Linux, MacOS, databases), and mobile device security
  • Knowledge of the various types of cyber-attacks and their implementations
  • A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Ability to document and explain technical details in a concise, understandable manner
  • Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.
  • Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, and ELK
  • Scripting/programming experience preferred

Education
• Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience

"Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position."

The typical base pay range for this role is as follows:

  • New York / New Jersey: $182k-227k
  • Non-New York / New Jersey: $203k-249k


depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.

Our hybrid work schedule is four days on-site and work remotely one day per week.

About MUFG Bank, Ltd.

MUFG Bank, Ltd. Careers

There has never been a better time to join the global team at MUFG Bank, Ltd., a premier institution recognized for its leadership in the financial sector. MUFG Bank, Ltd. offers a plethora of job opportunities that cater to a variety of skills and interests, all while fostering professional growth and innovation.

Work You’ll Do

Join MUFG Bank, Ltd.'s distinguished team to assist some of the most sophisticated clients in navigating their financial landscapes. At MUFG Bank, Ltd., team members lead from a unique position in the marketplace, at the crossroads of financial expertise, industry knowledge, and digital innovation. Engage with a global team of business and financial advisors to help clients master their economic strategies and challenges. Collaborate with the largest group of finance professionals in the industry – a network that spans across continents offering unmatched opportunities for networking and professional development.

Introducing the MUFG Bank, Ltd. Business Advisory

The team is dedicated to building a leading Advisory group to guide some of the most renowned companies through their financial strategies using innovative solutions.

Do Innovative Work

Be part of a team that delivers targeted financial solutions through a depth and breadth of consulting experience and innovation that’s second to none.

Be Part of a Great Team

Work on a wide range of financial technologies and harness the unparalleled capabilities, global scale, and joint solution development that only MUFG Bank, Ltd. can offer.

Future-Proof Your Career

Advance your career as far as your ambition can take you with limitless opportunities supported by unmatched training, development, and certification support.

Explore

Discover how MUFG Bank, Ltd. is leading the way in financial innovation with cutting-edge projects like blockchain for secure transactions and AI for risk assessment.

The MUFG Bank, Ltd. Alliance

The combined service capabilities, global scale, and joint solution development enable clients to overcome challenges and lead transformation in their industries. Clients worldwide turn to MUFG Bank, Ltd. for new strategies and financial solutions to drive growth and success in the digital era.

Stay Connected

Join the Team

Search open positions that match your skills and interests. MUFG Bank, Ltd. seeks passionate, curious, creative, and solution-driven team players.

SEARCH MUFG JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at MUFG Bank, Ltd.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at MUFG Bank, Ltd.
Learn more about MUFG Bank, Ltd.

Similar Jobs

More Jobs at MUFG Bank, Ltd.

More Information Technology Jobs

Find similar Global Director of Autonomous Cyber Defense and Security Event Triage (SOC) jobs: