Full Job Description
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
EDUCATION
• Degree or equivalent work experience equally preferable
CERTIFICATIONS
• [Include information as needed.]
WORK EXPERIENCE
• Must have previous experience in security architecture, demonstrating solutions delivery, principles, and emerging technologies, including continuous monitoring and making improvements to those solutions, working with an information security team.
• Experience consulting, engineering security best practices, and implementing security principles across the organization to meet business goals and regulatory requirements, including the security considerations of cloud computing (e.g., data breaches, broken authentication, hacking, account hijacking, malicious insiders, third parties, advanced persistent threats (APTs), data loss, and denial-of-service (DoS) attacks.
FUNCTIONAL SKILLS
• Experience using Visual Basic.NET (VB.NET), Java/J2EE, ColdFusion, Application Programming Interface (API)/web services, scripting languages, and a relational database management system (RDBMS), such as Microsoft SQL Server or Oracle
• Management of security tools such as: Tenable, Governance Risk Management and Compliance (GRC), Nessus, CrowdStrike Falcon, Protocol Analyzers, Data Loss Prevention (DLP), Network Access Control (NAC), Security Information and Event Management (SIEM), Intrusion Prevention System/Intrusion Detection System (IPS/IDS), etc.
• Knowledge of NIST 800-53, Control Objectives for Information and Related Technologies (COBIT), ISO 27001/02
FOUNDATIONAL SKILLS
• Demonstrates leadership
• Communicates effectively
• Identifies multiple paths to success using analytical and critical thinking as well as decision-making skills
• Operates strategically to support a culture of continuous improvement and systems thinking
• Makes sound business decisions in a complex work environment
• Collaborates with other business functions and divisions to advance business objectives
• Is flexible, decisive, and able to establish support from leadership
• Monitors industry trends and best practices and applies insights to advance the business
• Exhibits and fosters optimism, resilience, flexibility, and openness to others' ideas
• Inspires innovation and values learning as a lifelong professional objective
• Leads by example, engaging inclusively and with intent
• Always acts with integrity
• Excellent attention to detail
• Iterative problem-solving
• Serving as a trusted advisor
• Ability to prioritize work without management direction, and provide clear and documented status updates/metrics to management
• Exceptional organizational skills with ability to manage multiple priorities while adhering to established milestones and timelines
• Ability to troubleshoot complex problems with minimal guidance
• Ability to learn and adapt to new capabilities/tools based on business needs
RESPONSIBILITIES
• Conduct security analysis of current processes and platforms; generate ad-hoc reports for management
• Design security models, review and approve security configuration and install firewall, VPN, routers, IDS scanning technologies, and servers
• Design solutions and recommend the most suitable design packages to improve current software security levels and performance. Oversee security awareness programs; educate and communicate to staff about information security polices, procedures, and practices
• Define security-based architecture while adhering to development methodologies, engineering and coding standards. Monitor industry security updates, technologies and best practices to improve security management
• Provide detailed guidance to engineering team members on the development of system security components. Participate in the development of hardware/software/network security procedures and guidelines that support information security policies
• Details:
• Design, build, and implement enterprise security systems for a production environment to mitigate threats as they emerge
• Align standards, frameworks, and security with overall business and technology strategy
• Create solutions that balance business requirements with information and cyber security requirements
• Identify security design gaps in existing and proposed architectures and recommend changes or enhancements
• Use current programming language and technologies to write code, complete programming, and perform testing and debugging of applications
• Train users in implementation or conversion of systems
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.