ForgeApply
Try it free

ForgeApply · Job listing

Cyber Security Technical GRC – VP

MUFG

Jersey City, NJ | Tempe, US$151k – $203khybrid

Tailor your resume to this posting in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for MUFG's site. Free trial, no card required.

About this role

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

Job Summary :

This role is a member of the CISO of America’s team, with primary focus on the Enterprise Information Systems (EIS) Governance, Risk, and Compliance (GRC) team.  The  position requires a  deep understanding of how cloud environments are  well  architected and  identifying  risks associated with the services  utilized  and challenging the architecture(s) and implementation.

As an individual contributor,  y ou will act within the  first line of defense , contributing to complex, critical disciplines including  Cloud Security Governance, Policy Management, Cybersecurity Controls & Reporting, and Cyber Risk Quantification  across hybrid (cloud and  on premise ) environments. The role emphasizes comprehensive risk management— identifying , assessing, and managing inherent, control, and residual risks—while  auditing cloud technologies, wearing multiple hats ,  writing  executive-ready reports, and  relaying risk clearly to senior leaders .     Responsibilities :   Cloud & Cyber Risk Management  

• Drive risk management initiatives for  multi cloud environments ; ensure alignment with enterprise security standards and regulatory expectations.  

• Understand the  technical  architecture and operational setup of cloud servers and provider integrations to evaluate exposure, control effectiveness, and  residual

• Support internal projects addressing cloud cybersecurity threats; assess the effectiveness and comprehensiveness of first-line  cyb ersecurity  controls

• Review and challenge risk assessments, scenario analyses, control testing, and remediation plans;  assist  with issue oversight and escalations.  

• Monitor and analyze risk trends (internal and external) to proactively mitigate potential issues  impacting  cloud security posture.  

• Promote actions to address root causes of risks

Cybersecurity Controls & Reporting  

• Represent EIS GRC in working groups focused on cloud security and  multi levels of reporting

• Translate complex cloud and cybersecurity concepts into clear  business terms  for non-technical stakeholders and senior management across the Combined U.S. Operations.  

• Prepare  concise, executive-level reports  on risk management activities, control outcomes, and emerging issues for senior leadership.  

Cyber Risk Quantification   • Collaborate on initiatives that strengthen the enterprise cybersecurity program; ensure projects align with the cloud security governance model.  

• Regularly review and update risk frameworks to reflect changes in the  cloud threat landscape , including Oracle-specific risks.  

• Lead discussions at all levels to incorporate  cloud security risk elements  into business strategies and decision-making.  

• Guidelines  of business  through cloud security assessments, translating technical/security questions into  business impact and prioritization .  

Auditing & Compliance  

• Conduct and/or oversee  audits and  other  assessments of cloud technologies and  on-prem technologies , ensuring  effectiveness, sustainability, and maturity  con trols.  

• Ensure adherence to regulatory requirements and internal policies, including coordination on remediation of identified gaps.  

• Support oversight activities related to enforcement agencies, regulatory examinations,  and related obligations.  

Emerging Security Trends  

• Stay current with  multiple   Cloud  platforms for  best    practices , emerging technologies, and regulatory changes  impacting  cloud environments.  

• Leverage insights to enhance the security posture and influence strategic roadmaps across business and technology teams.  

  KRIs & Metrics  

• Influence comprehensive and consistent practices to  identify , measure, monitor, report, and manage  information risks.  

• Ensure metric quality and relevance (e.g., control efficacy, incident trends, misconfiguration rates, vulnerability aging, and remediation timeliness).  

  Qualifications :

• 6–10+ years  of experience across risk management, cloud information security governance, and/or IT audit; prior  a udit experience is a plus.  

• Strong understanding of  cloud architecture and provider integrations , including how enterprise servers and services interface with cloud providers

• Experience  auditing cloud technologies , wearing multiple hats in GRC contexts,  writing   executive-ready reports , and  relaying risk to executives .  

• High technical knowledge across cybersecurity domains (IAM, Data Security, Configuration Management, Log Generation, Incident Response,  S ecurity risk  A ssessment/ T esting  M ethodologies, Secure SDLC), with specific experience evaluating the adequacy and efficiency of  C loud  C ontrols .  

• Knowledge of domestic and international banking regulations (e.g.,  Reg W, Basel II, FFIEC, GDPR ) and experience with enforcement agency oversight activities (e.g.,  MRAs, consent orders ), especially within systemically important financial institutions.  

• Understanding of  the

Salary insight

The midpoint of this range ($177k) is right around the median disclosed salary for New York roles listed on ForgeApply ($175k across 5,170 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Ready to apply to MUFG?

Tailor my resume for this role

Similar jobs

More like this: More jobs at MUFG · Browse all jobs