ForgeApply · Job listing
Global Director of Autonomous Incident Response and Forensic Analysis
MUFG
Tailor your resume for this MUFG job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for MUFG's site. Free trial, no card required.
About this role
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
The Global Director of Autonomous Incident Response and Forensic Analysis leads the strategy, execution, and continuous improvement of a 24/7 global incident response (IR) and digital forensics function. This role is accountable for orchestrating rapid containment, eradication, and recovery for security incidents while ensuring high-quality investigative rigor, evidence handling, and executive-ready reporting. The director operates under the Global Head, helping shape the overarching vision and translating it into operating models, playbooks, and measurable outcomes; the role also partners closely with the SOC Director to ensure seamless handoffs from detection/triage into investigation and response and to drive feedback loops that improve detections and alert fidelity. Additionally, the role advances AI-assisted, human-in-the-loop forensics and response by applying AI/ML and LLM-enabled workflows (e.g., enrichment, case summarization, artifact correlation, and response recommendations) with appropriate governance, controls, and analyst validation to improve speed and consistency without sacrificing investigative integrity. The director owns budget planning and financial stewardship for the function and ensures service delivery across regions, environments, and partners.
Major Responsibilities • Direct and mature a 24/7 global incident response and digital forensics operating model, including intake, investigation, containment/eradication coordination, and recovery validation across multiple environments • Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for incident response and forensics (e.g., time to contain, time to remediate, investigation cycle time, repeat-incident reduction, and readiness metrics) • Work with the Global Head to define the vision for Autonomous Incident Response and Forensic Analysis, and execute against that vision in alignment with the strategic design • Partner with the SOC Director to define clear handoffs from detection/triage into investigation, establish escalation criteria, and implement feedback loops that improve detections, alert quality, and response playbooks • Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance • Lead, mentor, and scale high-performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on-call expectations • Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution • Provide executive-level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements • Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions • Drive AI-assisted, human-in-the-loop incident response and forensics initiatives, including evidence/artifact enrichment, timeline reconstruction, case summarization, correlation across telemetry sources, and response recommendations with analyst validation and governance • Establish governance for IR playbooks/runbooks, case management workflows, evidence handling and retention, and chain-of-custody practices to ensure investigations are consistent, defensible, and repeatable • Provide incident command leadership for high-severity events; coordinate containment and recovery execution with infrastructure, identity, endpoint, cloud, application, legal, privacy, and communications stakeholders • Oversee third-party IR/forensics capabilities and managed services (as applicable) to ensure coverage, quality, evidence standards, and alignment to enterprise policies and SLAs • Build an IR operations analytics program to measure and continuously improve containment speed, investigation throughput, backlog health, automation effectiveness, and quality of outcomes across regions and shifts • Lead incident readiness and validation exercises (e.g., tabletop exercises and technical simulations with relevant teams), and ensure post-incident reviews drive measurable improvements to controls, detections, and response procedures • Build and maintain forensic readiness capabilities, including standardized collection methods, artifact baselines, and investigative playbooks to accelerate triage-to-proof and reduce dwell time • Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones • Leverage threat intelligence and adversary TTP research to inform scoping, attribution hypotheses, containment prioritization, and investigative direction; translate insights into improved prevention and detection • Produce and govern recurring and ad-hoc reporting on threats, trends, and program performance; ensure consisten
Salary insight
The midpoint of this range ($226k) is about 31% above the median disclosed salary for New York roles listed on ForgeApply ($172k across 5,612 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this MUFG role before you apply.
Tailor my resume for this jobSimilar jobs
- Incident Response and Forensics Lead — Accenturefederalservices · Germantown, MD; Washington, DC
- Sr. Cyber Analyst, Digital Forensics Incident Response — Atbayjobs · Remote
- Cyber Analyst, Digital Forensics Incident Response — Atbayjobs · Remote
- Senior Associate/Cybersecurity & Incident Response (Forensic Services practice) — Charlesriverassociates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; Washington, DC, United States
- Associate Principal/Cybersecurity & Incident Response (Forensic Services practice) — Charlesriverassociates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; Washington, DC, United States
- Lead Analyst – Cyber Incident Response — Raymond James · Saint Petersburg, Florida - United States
- Associate/Cybersecurity & Incident Response (Forensic Services practice) — Charlesriverassociates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; New York, NY, United States; Oakland, CA, United States; Washington, DC, United States
- Incident Response Analyst — Cisco · Remote
More like this: More jobs at MUFG · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)