Insider Threat Security Engineer, AVP
MUFGAbout the role
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 7th largest financial group in the world. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.MUFG is seeking an Insider Threat Engineer to utilize scientific methodologies using predictive analytics to help identify and convey insider risk and risk management activities to our business operations. Works closely with Data Loss Prevention and Global Security Operations teams and serves as the subject matter expert for the data analytics discipline. Provides recommendations and contributes to the overall strategic direction of the Insider Threat program. Will support the Insider Threat Operations Team and be responsible for maintaining systems to facilitate the analysis of insider threat alerts and events, integrating available data sources from a variety of internal and external sources into the Insider Threat Management workflow, cleaning data as necessary, and developing associated analytical models.
RESPONSIBILITIES
Generally Monday through Friday 8:00 am – 5:00 pm, but frequent work outside of normal operating hours is expected
Ability to work overnight weekends (Saturday, Sunday) but not limited to shift work (morning, afternoon, and evening)
This role requires a highly curious and skilled practitioner to identify and respond to high-risk activity and anamalous behaviors that may be indicative of harmful insider threat activity
This includes intellectual property theft, espionage, fraud, sabotage, and unauthorized data disclosure
Must possess the ability to document findings including timelines, evidence and artifacts relating to each event
Ability to coordinate meetings with device owners, managers, and forensics teams as needed to verify evidence
Understand data loss prevention, data classification, SIEM a plus
Manages various analytical tools and information systems to identify and follow trends in order to provide actionable intelligence
Experience with server administration in both on-premises and cloud environments. Knowledge of contemporary SIEM/UEBA platforms and their application to cyber threat analysis
Experience with writing small bash, Splunk scripts, SQL queries and java programs
Knowledge of networking protocols, encryption, firewalls, host and network intrusion detection systems, data loss prevention systems, Windows and Linux
Understanding of latest security trends, especially those associated with insider threat detection, response, and mitigation
Security and IT metrics experience a plus; report creation abilities strongly desired
Evaluate / Build SIEM queries, reports, and dashboards to make recommendations on changes of events being monitored
Exceptional ability to execute and drive change while never losing site of the basics
Produce documentation that will help to educate and socialize program updates to our key stakeholders
Zero tolerance for operational, design, and strategy-oriented gaps
QUALIFICATIONS
Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience
Nice to have: Carnegie Mellon University Certified Insider Threat Program Manager (ITPM), CEH, Security+ or related SANS certification
Extensive technical experience in either reverse engineering/malware analysis, insider threat, threat intelligence, incident response, security operations, or related information security field.
Ability to demonstrate analytical expertise, attention to detail, excellent critical thinking, logic, and solution orientation to learn and adapt quickly
Practical knowledge of recent or emerging cyber threats
Comfortable working in a fast-paced environment
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s