MUFG

Director, Threat and Vulnerability Management

MUFG  •  $203k - $249k/yr  •  United States (Remote)  •  2 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

The Director of Threat & Vulnerability Management is responsible for leading the enterprise-wide strategy, execution, and continuous maturity of Threat Intelligence, Threat Hunting, and Vulnerability Management programs. This role provides strategic direction and operational leadership to proactively identify, prioritize, and mitigate cyber threats and vulnerabilities using a risk-based approach aligned to business impact.

The Director partners closely with engineering, infrastructure, application security, incident response, and risk teams to ensure security controls are effective, measurable, and continuously improved. The role reports outcomes to senior leadership and plays a critical role in reducing organizational cyber risk.

RESPONSIBILITIES:

Strategic Leadership

  • Lead and continuously evolve the enterprise Threat Intelligence, Threat Hunting, and Vulnerability Management programs.
  • Define and execute a multi-year Threat & Vulnerability Management strategy aligned to organizational risk appetite and business priorities.
  • Establish measurable security KPIs and maturity metrics; regularly present program effectiveness and risk posture to senior management.

Threat Intelligence & Hunting

  • Build and mature a Cyber Threat Intelligence (CTI) program that aggregates strategic, operational, and tactical intelligence from internal and external sources.
  • Lead proactive threat hunting initiatives across enterprise and compute environments to identify dormant threats, advanced adversaries, and supply chain compromises.
  • Map threat actor TTPs (Tactics, Techniques, and Procedures) to the MITRE ATT&CK framework to identify gaps in detection and prevention coverage.

Vulnerability Management

  • Establish and drive a risk-based vulnerability management model that prioritizes remediation based on exploitability, asset criticality, and business impact.
  • Ensure timely remediation, validation, and reporting of identified vulnerabilities and security gaps across infrastructure, applications, and cloud environments.
  • Partner with technology and business teams to embed vulnerability remediation into operational and engineering workflows.

Technology & Innovation

  • Evaluate and implement AI-driven and automation technologies to improve efficiency, scale, and effectiveness of threat and vulnerability operations.
  • Continuously assess current security processes and tools to identify opportunities for optimization and enhanced risk reduction.

Collaboration & Communication

  • Serve as a trusted advisor to engineering, architecture, risk, and incident response teams on threat and vulnerability matters.
  • Communicate complex security topics clearly to both technical and non-technical stakeholders, including executives and regulators.
  • Build strong relationships with internal partners and relevant external security communities and vendors.

People Leadership

  • Lead, mentor, and develop a high-performing team of security professionals; foster a security-aware and accountability-driven culture.

WORK EXPERIENCE:

  • 10+ years of progressive experience in cybersecurity, including threat intelligence, threat hunting, vulnerability management, or detection engineering
  • Proven experience leading enterprise-scale security programs and teams
  • Deep understanding of threat actor behaviors, MITRE ATT&CK, vulnerability exploitation, and modern attack techniques
  • Strong experience with risk-based security frameworks and metrics
  • Familiarity with AI/ML applications in security operations
  • Experience with scripting in languages such as Python
  • Ability to influence senior leadership and drive cross-functional execution


FUNCTIONAL SKILLS:


• Deep knowledge of cyber threat actors and their tactics, techniques and procedures

• Knowledge of scripting to enhance hunting capabilities

• Knowledge of AI capabilities and how to use them to build efficiencies and automation

• Strong knowledge of vulnerability management identification, analysis and treatment capabilities

• Thorough understanding and familiarity with relevant standards including National Institute of Standards and Technology (NIST) and Federal Financial Institutions Examination Council (FFIEC)
• A technical background in systems or network administration, engineering, or operations

FOUNDATIONAL SKILLS


• Communicates effectively
• Anticipates changing business needs, adjusts priorities accordingly, and allocates necessary resources and budget to achieve objectives
• Equips the business to become an effective competitor in an highly dynamic landscape
• Considers stakeholder needs and input as well as best practices and insights from industry trends when making strategic decisions
• Is flexible, decisive, and serves as a trusted advisor to senior leaders within the organization
• Demonstrates effective negotiation and influencing skills
• Prioritizes and facilitates an culture of continuous improvement and systems thinking
• Sets the tone for successful collaboration with other business units and corporate entities
• Creates an environment that fosters communication, transparency, and collaboration
• Cultivates innovation and values learning as a lifelong professional objective
• Leads by example, engaging inclusively and with intent
• Always acts with integrity
• Analytical thinking
• Iterative problem-solving
• Manage relationship with external vendors to support the TVM Team

• Serve as a lead escalation contact in a 24/7 environment; and guide appropriate resources to resolution
• Maintain knowledge of industry trends and threats

CERTIFICATIONS


• Industry certifications (e.g., CISSP, CISM, GIAC, or equivalent)


Education:

•Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience

Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.”

The typical base pay range for this role is as follows:

  • New York / New Jersey: $203k – $249k

depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.

Our hybrid work schedule is four days on-site and work remotely one day per week.

MUFG Benefits Summary

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.

MUFG

About MUFG

MUFG (Mitsubishi UFJ Financial Group) is one of the world's leading financial groups. Headquartered in Tokyo and with over 360 years of history, MUFG has a global network with over 2,100 locations in more than 40 markets including the Americas, Europe, the Middle East and Africa, Asia and Oceania. The Group has over 120,000 employees and offers services including commercial banking, trust banking, securities, credit cards, consumer finance, asset management, and leasing. Through close partnerships among our group companies, the Group aims to be the world's most trusted financial group, flexibly responding to all of the financial needs of its customers, serving society, and fostering shared and sustainable growth for a better world. MUFG's shares trade on the Tokyo, Nagoya, and New York stock exchanges. Watch our profile video: https://youtu.be/htyOjA1H6bQ Details of MUFG's Group companies can be found at the following websites: http://www.bk.mufg.jp/global http://www.tr.mufg.jp/english https://mufgamericas.com https://www.mufgemea.com http://www.hd.sc.mufg.jp/english

©2024Mitsubishi UFJ Financial Group, Inc. All rights reserved. The MUFG logo and name is a service mark of Mitsubishi UFJ Financial Group, Inc.

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Chiyoda-ku, JP
Year Founded
Unknown
Website
mufg.jp
Social Media