Cyber Security Technical GRC – VP
MUFGAbout the role
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.Job Summary:
This role is a senior member of the CISO of America’s team, with a primary focus on the Enterprise Information System’s Governance, Risk, and Compliance (EIS GRC) function. The position demands deep technical expertise in cybersecurity, particularly in cloud and hybrid environments, as well as a sophisticated understanding of GRC frameworks and methodologies.
The successful candidate will be responsible for evaluating, and enhancing technical cybersecurity controls, conducting in-depth review and challenges, and cyber risk quantification initiatives. This role goes beyond general controls and requires hands-on experience with complex security technologies, risk management, secure system design, and regulatory compliance.
The candidate must demonstrate advanced knowledge of risk governance, control frameworks (e.g., NIST 800 series), regulatory requirements, and the ability to translate technical risks into enterprise-level risk management strategies. The role also involves driving the development and implementation of GRC tools, metrics, and reporting mechanisms to ensure continuous improvement of the cybersecurity risk posture.
Responsibilities:
Cyber Risk Management:
- Support internal projects on cybersecurity threat concerns, supporting various participants and stakeholders in measuring the effectiveness and comprehensiveness of MUFG’s first line defenses.
- Review and challenge risk assessments and scenario analysis and assist on issue oversight and escalations.
- Monitor and analyze risk trends to proactively mitigate potential issues.
- Monitor and evaluate emerging risks, internal operational trends, and external risk events for potential impact on the cloud security environment.
- Promote actions to address root causes of risks that may lead to operational losses or regulatory breaches.
- Ensure alignment with regulatory requirements (e.g., OCC, FRB, GDPR, Basel II) and manage responses to audits and examinations.
Cybersecurity Controls and Reporting:
- Represent EIS GRC in various working groups relevant to the functional area.
- Effectively communicate complex cybersecurity concepts to non-technical stakeholders and senior management across the Combined U.S. Operations.
- Prepare detailed reports on risk management activities and outcomes for senior management.
- Lead technical working groups and represent EIS GRC in initiatives requiring expert-level input on cloud security architecture and secure software development lifecycle (SSDLC).
Cyber Risk Quantification:
- Collaborate with complex initiatives designed to improve the overall enterprise cybersecurity program, ensuring projects are executed as planned and align with the cybersecurity governance model.
- Regularly review and update the Cyber Risk Institute implementation to reflect changes in the cyber threat landscape, ensuring that risk management practices remain current and effective.
- Lead discussions at all levels of the organization to incorporate and manage cloud security risk elements as part of the overall business strategy.
- Provide clear and consistent communications to lines of business related to cloud security topics, guiding them through assessments and translating technical/security questions into business terms.
Emerging Security Trends:
- Lead technical working groups and represent EIS GRC in initiatives requiring expert-level input on cloud security architecture and secure software development lifecycle (SSDLC).
- Collaborate with various departments to ensure compliance with
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s