Cyber Security Technical GRC – VP
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Data Security, Information Security
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long‑term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job SummaryThis role is a member of the CISO of America’s team, with primary focus on the Enterprise Information Systems (EIS) Governance, Risk, and Compliance (GRC) team. The position requires a deep understanding of how cloud environments are well architected and identifying risks associated with the services utilized and challenging the architecture(s) and implementation.
As an individual contributor, you will act within the first line of defense, contributing to complex, critical disciplines including Cloud Security Governance, Policy Management, Cybersecurity Controls & Reporting, and Cyber Risk Quantification across hybrid (cloud and on premise) environments. The role emphasizes comprehensive risk management—identifying, assessing, and managing inherent, control, and residual risks—while auditing cloud technologies, wearing multiple hats, writing executive-ready reports, and relaying risk clearly to senior leaders.
ResponsibilitiesCloud & Cyber Risk Management
Drive risk management initiatives for multicloud environments; ensure alignment with enterprise security standards and regulatory expectations.
Understand the technical architecture and operational setup of cloud servers and provider integrations to evaluate exposure, control effectiveness, and residual
Support internal projects addressing cloud cybersecurity threats; assess the effectiveness and comprehensiveness of first‑line cybersecurity controls
Review and challenge risk assessments, scenario analyses, control testing, and remediation plans; assist with issue oversight and escalations.
Monitor and analyze risk trends (internal and external) to proactively mitigate potential issues impacting cloud security posture.
Promote actions to address root causes of risks
Cybersecurity Controls & Reporting
Represent EIS GRC in working groups focused on cloud security and multi levels of reporting
Translate complex cloud and cybersecurity concepts into clear business terms for non‑technical stakeholders and senior management across the Combined U.S. Operations.
Prepare concise, executive‑level reports on risk management activities, control outcomes, and emerging issues for senior leadership.
Cyber Risk Quantification
Collaborate on initiatives that strengthen the enterprise cybersecurity program; ensure projects align with the cloud security governance model.
Regularly review and update risk frameworks to reflect changes in the cloud threat landscape, including Oracle‑specific risks.
Lead discussions at all levels to incorporate cloud security risk elements into business strategies and decision‑making.
Guidelines of business through cloud security assessments, translating technical/security questions into business impact and prioritization.
Auditing & Compliance
Conduct and/or oversee audits and other assessments of cloud technologies and on‑prem technologies, ensuring effectiveness, sustainability, and maturity controls.
Ensure adherence to regulatory requirements and internal policies, including coordination on remediation of identified gaps.
Support oversight activities related to enforcement agencies, regulatory examinations, and related obligations.
Emerging Security Trends
Stay…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).