About Us
MUFG Bank, Ltd. is Japan’s premier bank, with a global network spanning in more than 40 markets. Outside of Japan, the bank offers an extensive scope of commercial and investment banking products and services to businesses, governments, and individuals worldwide. MUFG Bank’s parent, Mitsubishi UFJ Financial Group, Inc. (MUFG) is one of the world’s leading financial groups. Headquartered in Tokyo and with over 360 years of history, the Group has about 120,000 employees and offers services including commercial banking, trust banking, securities, credit cards, consumer finance, asset management, and leasing.
The Group aims to be the world’s most trusted financial group through close collaboration among our operating companies and flexibly respond to all of the financial needs of our customers, serving society, and fostering shared and sustainable growth for a better world. MUFG’s shares trade on the Tokyo, Nagoya, and New York stock exchanges.
MUFG Global Service Private Limited
Established in 2020, MUFG Global Service Private Limited (MGS) is 100% subsidiary of MUFG having offices in Bengaluru and Mumbai. MGS India has been set up as a Global Capability Centre / Centre of Excellence to provide support services across various functions such as IT, KYC / AML, Credit, Operations etc. to MUFG Bank offices globally. MGS India has plans to significantly ramp-up its growth over the next 18-24 months while servicing MUFG’s global network across Americas, EMEA and Asia Pacific
Equal Opportunity Employer
The MUFG Group is committed to providing equal employment opportunities to all applicants and employees and does not discriminate on the basis of race, colour, national origin, physical appearance, religion, gender expression, gender identity, sex, age, ancestry, marital status, disability, medical condition, sexual orientation, genetic information, or any other protected status of an individual or that individual's associates or relatives, or any other classification protected by the applicable laws.
About the Role
Position Title : Cloud Security - Senior Analyst
Reporting to : Vice President – Cyber Security Operations
Location : Bengaluru
Job Profile
Position Details :
Roles and Responsibility :
In this role, you will be responsible for Cloud Security (as part of Cyber Security) across MUFG’s banking arm and securities business under a dual-hat arrangement. Under this arrangement, you will act and make decisions on behalf of both the bank and the securities business, subject to the same remit and level of authority, and irrespective of the entity which employs you.
- To ensure effective management and control of Cyber Security, IT and information risk for MUFG EMEA entities by ensuring all appropriate Security, IT and common sense controls are in place, that these controls are being followed and that this is evidenced across the whole business and IT department.
- The role will involve liaising with the other Cyber Security and IT functions within the MUFG EMEA business entities and MUFG group to ensure a consistent approach to all controls, standards and policies is adopted across the organisation.
- To ensure all necessary Cyber Security controls are in place and that an appropriate strategy to protect the firm from all Cyber, external and internal threats is defined and being implemented.
- To develop, implement and manage compliance with appropriate IS and Cyber Security policies, standards, procedures.
- To support the relationship and associated reporting requirements between Technology and internal and external bodies e.g. auditors, management committees, Tokyo head office, regulators (via Compliance), Operational Risk.
- Ensure NIST, ISO27002 and CIS aligned risk controls are covered, including but not limited to Cyber Security Policies & Standards.
- Ensure MUFG EMEA operates under comprehensive and relevant Cyber Security policies and standards with appropriate staff awareness, compliance monitoring and reporting.
- Monitor and proactively manage all Cloud Security toolsets that includes : (Should be proficient in few technologies)
- Cloud Security Posture Management (CSPM) (CloudGuard, Wiz, MS Defender for Cloud)
- Cloud Workload Protection Platforms (CWPP) (CloudGuard, Wiz, CrowdStrike Falcon)
- Hands on experience in managing and overseeing cloud security solutions across multi-cloud environments like Azure, OCI and AWS.
- Manage and oversee Kubernetes security controls for containerised workloads in AKS, OKE, EKS and On-Prem Kubernetes environment.
- Review and assess enterprise cloud architectures for security gaps and recommend mitigations.
- Monitor, investigate, and track cloud security alerts using integrated ticketing workflows in ServiceNow.
- Develop, improve and enforce cloud security standards, policies, and procedures.
- Conduct Cyber Security reviews for existing and new, on-prem, cloud and 3rd party systems, solutions, firewall rules, architecture, network designs to ensure these are consistent with MUFG’s risk appetite, policy & standard requirements.
Monitor and proactively support all Cyber Security team members & toolsets that includes :
Web Access & Monitoring Systems (ZScaler, Bluecoat, Menlo Security, CASB, etc.)Network Security Monitoring Systems (RSA SecurID, FireEye ETP, Tufin Aurora, Proofpoint, etc.)Endpoint Security Monitoring Systems (Sophos, CrowdStrike, Defender, etc.)Ensure adequate technical safeguards are in place and are being actively managed by the support teams to provide appropriate protection to MUFG’s information assets across various environments such as :Windows & Unix operating systemsDatabases (Oracle, SQL, Sybase, etc.)Networks & its componentsMiddleware systemsCloud & its various services (IaaS, PaaS, SaaS)Be seen as the Cloud Security (as part of Cyber Security) centre of excellence for MUFG EMEA and ensure MUFG adopts an appropriate and professional response on any Cyber Security issues raised by the organisation’s business activities.Liaise and collaborate with IT teams to ensure Cyber Security alerts, threats and vulnerabilities across the IT estate are highlighted, managed and mitigated within appropriate timescales.Liaise with Technology and Business teams as necessary to ensure all MUFG systems meet security standards and / or agree appropriate measures to mitigate the risk where they don’t.Maintain an up to date, working knowledge of current laws, regulations and best practices relating to Cyber Security.Support Cyber Security incidents and annual penetration testing activities.Support Operational Risk management & Operational Security duties where requested.Support MUFG EMEA Cyber Security risk profile and associated operational risk reporting.Support Audit & Regulatory liaison and ensure consistent and timely answers to information requests.Support any issues and remedial actions resulting from Cyber Security incidents and audits within agreed timelines.Provide Cyber Security awareness and / or training to MUFG staff as necessary.Essential :
Degree or equivalent in IT related discipline with some programming knowledge or understanding.Strong Cloud, Information or Cyber Security background with over 5 years of experience.Strong ability to implement security solutions that enable business activity rather than close opportunities.Strong knowledge of cyber security frameworks, standards, and regulations such as ISO27001, NIST, CIS, GDPR, etc.Strong ability to analyse and distil complex issues and present succinct updates to management.Active involvement in internal and external audits and experience of managing Audit relationships.Relevant professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Cloud Security Professional (CCSP), Azure Security Engineer Associate, Microsoft Cybersecurity Architect, AWS Certified Security - Specialty or Certified Ethical Hacker (CEH) are preferred, as is exposure to GRC frameworks including (but not limited to) ISO27001; NIST, CIS benchmarks & Cyber Essentials / Plus.Excellent communication and interpersonal skillsA structured, logical and proactive approach to workResults driven, with a strong sense of accountabilityThe ability to operate with urgency and prioritise work accordinglyA calm approach, with the ability to perform well in a pressurised environmentStrong decision making skills and the ability to demonstrate sound judgementComfortable in taking ownership of workstreams and seeing them through to completionSelf-awareness and confidence to challenge business requirements and deliver difficult messagesPassion for Cyber Security and a proactive approach to identifying and mitigating risksCommitment to continuous learning and improvement in the rapidly evolving field of Cyber Security