At a Glance
- Tasks: Lead a team in penetration testing and manage information security across MUFG's banking and securities sectors.
- Company: Join Mitsubishi UFJ Financial Group, a global leader in finance with 120,000 colleagues making a difference.
- Benefits: Enjoy a hybrid work policy, career development opportunities, and a culture that values diversity and innovation.
- Why this job: Make a meaningful impact in cybersecurity while collaborating with diverse teams in a supportive environment.
- Qualifications: 3+ years of experience in penetration testing and strong knowledge of offensive security technologies required.
- Other info: Opportunity for out-of-hours support and involvement in high-stakes security assessments.
The predicted salary is between 48000 - 84000 £ per year.
Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career. Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
Main Purpose of the Role: To ensure effective management and control of information security, IT and information risk for MUSI by ensuring all appropriate Security, IT and common-sense controls are in place, that these controls are being followed and that this is evidenced across the whole business and IT department. The role will involve liaising with the other information security functions within the MUS international business and MUFG group to ensure a consistent approach to all controls, standards and policies is adopted across the organisation. To ensure all necessary Information Security controls are in place and that an appropriate strategy to protect the firm from all Cyber, external and internal threats is defined and being implemented. To develop, implement and manage compliance with appropriate IS and IT Security policies, standards and procedures. To support the relationship and associated reporting requirements between Technology and internal and external bodies e.g. auditors, management committees, Tokyo head office, regulators (via Compliance), Operational Risk.
Key Responsibilities:
- In this role, you will be responsible for information/cyber security across MUFG’s banking arm and securities business under a dual-hat arrangement.
- Develop and maintain governance structure of red team operations and train, and mentor other members of the Red Team.
- Develop and execute penetration testing plans, including network, web application, and social engineering assessments.
- Collaborate with SOC team and selected vendor to plan and execute annual purple team testing.
- Identify security risks and vulnerabilities through simulated attacks, and help the organization understand the potential impact.
- Manage Red Team tools and the Security Testing & Validation Platform.
- Lead and manage a team of security professionals and vendor resources to conduct regular risk assessments to identify and exploit vulnerabilities, mis-configurations within EMEA internal & external infrastructure.
- Implement and maintain governance of any assessments finding remediation progress and create regular reporting for tech and executives.
- Collaborate with other technology teams (i.e. infra, app etc.) to develop and improve defensive strategies and security measures to prevent real-world attacks.
- Stay up-to-date with the latest cybersecurity threats, trends, and technologies to ensure the team’s methods and tools are current and effective.
- Strong understanding of blue team detection use cases.
- Create executive report from technical assessment report.
- Maintain an up to date, working knowledge of current laws, regulations and best practices relating to information security.
- Support Information Security incidents where requested.
- Support Operational Security duties where requested.
- Manage grey and black box testing solution including identified threats and vulnerabilities.
- Availability for out-of-hours support when necessary.
Skills and Experience:
- Minimum of 3 years’ experience as a pen tester.
- Skilled in developing implants and able to obtain and maintain persistence within corporate systems, while avoiding detection from common security tools.
- Demonstrated knowledge of tactics related to malicious insider activity, organized crime/fraud groups, and threat actors, both state and non-state sponsored.
- Solid understanding of offensive and pentest technologies.
- Ability to provide remediations recommendation based on test and automated security testing result.
- Deep understanding of how an advance persistent threat and their tactics, procedure and techniques.
- Solid understanding of Enterprise Backend to Frontend system architecture.
- Familiarity with defender techniques, security monitoring and SIEM tools.
- Strong ability to analyse and distil complex issues and present succinct updates to management and associated committees.
- The ability to create clear documentation relating to Operational Processes and Procedures.
Please note MUFG operate a hybrid work policy with 3 days per week in the office. MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count.
Penetration Testing Team Lead - AVP employer: MUFG Bank, Ltd
Contact Detail:
MUFG Bank, Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Testing Team Lead - AVP
✨Tip Number 1
Network with professionals in the cybersecurity field, especially those who work in penetration testing. Attend industry conferences, webinars, or local meetups to connect with potential colleagues and learn about the latest trends and challenges in the field.
✨Tip Number 2
Stay updated on the latest cybersecurity threats and technologies. Follow relevant blogs, podcasts, and forums to ensure you are knowledgeable about current issues, which will help you stand out during interviews.
✨Tip Number 3
Consider obtaining relevant certifications such as OSCP, CEH, or CISSP. These credentials not only enhance your skills but also demonstrate your commitment to the field, making you a more attractive candidate for the role.
✨Tip Number 4
Prepare for technical interviews by practising common penetration testing scenarios and methodologies. Familiarise yourself with tools and techniques used in red teaming, as well as how to communicate your findings effectively to both technical and non-technical stakeholders.
We think you need these skills to ace Penetration Testing Team Lead - AVP
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in penetration testing and information security. Focus on specific projects or roles that demonstrate your skills in managing teams and executing security assessments.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and how your background aligns with the responsibilities of the Penetration Testing Team Lead role. Mention any leadership experience and your approach to mentoring team members.
Showcase Relevant Skills: Clearly outline your technical skills related to penetration testing, such as familiarity with red team operations, knowledge of offensive security technologies, and experience with risk assessments. Use specific examples to illustrate your expertise.
Highlight Continuous Learning: Mention any recent certifications, training, or courses you have completed in cybersecurity. This shows your commitment to staying updated with the latest threats and technologies, which is crucial for this role.
How to prepare for a job interview at MUFG Bank, Ltd
✨Showcase Your Technical Skills
As a Penetration Testing Team Lead, it's crucial to demonstrate your technical expertise. Be prepared to discuss specific tools and techniques you've used in past penetration tests, and how you’ve successfully identified and mitigated vulnerabilities.
✨Emphasise Leadership Experience
Since this role involves leading a team, highlight your leadership experience. Share examples of how you've mentored others, managed projects, or collaborated with cross-functional teams to achieve security goals.
✨Stay Current with Cybersecurity Trends
The cybersecurity landscape is always evolving. Make sure to mention recent threats or trends you've been following, and how they might impact the organisation. This shows your commitment to staying informed and proactive.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills. Practice articulating your thought process when faced with hypothetical security incidents, including how you would lead your team in response.