Jobs and Careers
MU

Sr. Security Engineer, Tanium/AWS/Qualys - AVP

MUFG
United Statesfull_timeVerifiedPosted 20 Mar 2024
💰 $125,000/yr($100,000/yr$125,000/yr)

About the role

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 7th largest financial group in the world. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

RESPONSIBILITIES

•Develop guidelines for the usage, control, maintenance and audit-readiness of information and computer resources that are used in the distributed processing environment.

•Analyze and addressing security gaps for technologies within the Bank’s infrastructure

•Identify distributed systems security issues as they arise and coordinate with the technology owners to ensure that issues are addressed and resolved in a timely basis.

•Execute technical risk assessment activities for scoped environments

•Perform reporting of findings, issue resolution and management of findings

•Support FLOD/SLOD assessments, audits and external exams

•Provide effective, accurate and timely reporting

•Perform Information Security remote/table-top assessments

•Identify high risks finding and lead risk findings to resolution

•Identifying control deficiencies by analyzing and identifying underlying root causes

•Designing, implementing, and collaborating on a range of information security metrics and performance reports

•Assisting stakeholders in identifying, initiating, and tracking corrective actions to address anomalies

•Analyze control results in an objective and quantifiable manner

•Produce detailed documentation of assessments and perform threat analysis of gaps identified

•Communicate vendor information security issues to stakeholders, ensuring their understanding of associated risks and actions needed to remediate those risks

•Validate evidence from vendors, before remediation plans are closed

FUNCTIONAL SKILLS

•  Understanding of one or more compliance frameworks: CIS, NIST, FFIEC, GLBA, SOX, PCI, etc

Extensive experience with core vulnerability management tools (e.g. Tanium, Tenable, Rapid7, Qualys, etc.).

• Familiarity with one or more of the following technology areas is highly desirable:

  • Cloud services, (AWS, Azure, etc.)

  • Containers

  • Network infrastructure (technologies, architectures, operations)

  • Various network and host-based security products and services

  • Active Directory, servers, services, desktops and mobile devices

  • Unix, Linux, AIX

  • SQL, Oracle, DB2 Databases

•  Ability to perform technical risk assessments and synthesize observations at a macro level, identifying indicators of changing risk and/or symptoms of process or control deficiencies

• Ability to identify and propose process and technology controls in dynamic environments

•  Working knowledge and experience applying Information Assurance techniques to the implementation of complex networked systems environments and enterprise-wide systems

• In-depth knowledge of applying network switching, TCP/IP, IP Addressing and Routing, WAN Technologies, Operating and Configuring networked Devices, and Managing Network Environments, extending Switched Networks with VLANS, Determining IP Routes, Managing IP traffic with Access Lists, Establishing Point-to-Point connections, and Establishing Frame

• Demonstrate in-depth knowledge of concepts, best practices and controls in a breadth of information security areas/domains; these information security areas include risk management, access control, cryptography, physical security, security architecture and design, network security, application and operations security and compliance/incident management.

• Proficient working knowledge within the following risk domains/technologies:

  • Database and application security

  • Firewall technologies

  • Network Architecture

  • Database/Application/Network Layer Secure Protocols

  • Change Management

  • Vulnerability Management

  • System Configuration

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

MUFG

View company profile →