Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
EDUCATION- Degree or equivalent work experience equally preferable.
- Degree in computer science, technology, or related field.
CERTIFICATIONS
- [Include information as needed.]
WORK EXPERIENCE
- • Proven experience in IAM work including access control (role-based and discretionary), authentication, authorization, provisioning, approvals, and workflows
- • Hands on experience developing and supporting security solutions for identity management and access control
- • Strong understanding of information security risk analysis, Identity Access Management and access control methodologies with working knowledge of business applications
- • Successful experience working in global, complex, matrix-managed organization
- • Experience in the financial services or banking industry preferred
FUNCTIONAL SKILLS
- Deep understanding of IAM principals, methodology, and solutions
- Programming/debugging skills: Unix Shell, Perl, Java, JavaScript
- Solid understanding of web-based technologies including multi-tier applications and security standards (Secure Sockets Layer (SSL), Hyper Text Transfer Protocol (HTTP), cookie handling, Security Assertion Markup Language (SAML), WS-Security)
- Solid understanding of relational database management systems (RDBMS) and directory services Lightweight Directory Access Protocol (LDAP), in particular active directory) including system architecture, configuration, and monitoring
- Understanding of security issues, application-level security, encryption, and vulnerabilities
- Excellent Excel skills (for example, macros, formulas, query from backend database)
- Control knowledge around access management and ability to articulate risk and impact
- Knowledge in industry and government security standards (National Institute of Standards and Technology (NIST), Center for Information Security (CIS), etc.)
- Solid understanding of system logical access and audit controls are desirable.
- Programming and scripting abilities; specifically in Pentaho (PDI), JavaScript, Perl, PowerShell
- Experience with presentation applications such as Tableau or QlikView preferred
- Strong database, operating system (OS), software engineering skills
- Strong background in use of ASP.Net, JScript, c#, RDBMS, Office Suite, Win2k8, AIX, RHL 5, xml, php, IIS, PowerShell
- Strong structured query language (SQL) background, ability to write complex SQL queries, stored procedures.
- Knowledge of RSA Identity Access life cycle governance is required
- Strong understanding of information security risk analysis, Identity Access Management and access control methodologies with working knowledge of business applications
- Single Sign On (SSO), Lightweight Directory Access Protocol (LDAP), and federation experience including system architecture, configuration, monitoring, and ongoing compliance
- Practical experience with application integrations including: SSO architecture, configuration, monitoring, and compliance
- Experience with the following web servers: Internet Information Systems (IIS), Apache, or IBM
- Experience with the following application servers: WebSphere, JBoss, or WebLogic
- Experience working with leading IAM tools and services
- Knowledge of privileged or elevated access tools
- Control knowledge around access management and ability to articulate risk and impact
- Programming and scripting abilities; specifically in Pentaho (PDI), JavaScript, Perl, PowerShell
- Strong database, operating system (OS), software engineering skills. Azure/AWS experience is a plus
- Strong structured query language (SQL) background, ability to write complex SQL queries, stored procedures
- Ability to document and explain technical details in a concise, understandable manner
FOUNDATIONAL SKILLS
- Communicates effectively
- Identifies multiple paths to success using analytical and critical thinking as well as decision-making skills
- Exercises sound judgement, prioritizes effectively, and strives for continuous improvement
- Effectively collaborates with colleagues
- Leverages available technology to drive efficiency and results
- Understands and applies industry trends and best practices
- Exhibits optimism, resilience, flexibility, and openness to others' ideas
- Values learning as a lifelong professional objective
- Engages inclusively and with intent
- Always acts with integrity
- Iterative problem-solving
- Serving as a trusted advisor
- Ability to establish and maintain business relationships
- Solid organizational skills with the ability to multi-task various initiatives and activities
RESPONSIBILITIES
- High level responsibilities include::
- Educate, train, and support end-users and MIS (Management Information System) staff members on information security best practices, policies, and procedures such as hard copy materials containing sensitive information. Perform user provisioning, authentication, and access governance adhering to established guidelines. Publish, monitor, and mandate information and computer security policies and security awareness information and programs. Provide recommendations on mitigating or removing vulnerabilities within IT systems, while administering firewall components and implementing daily network support. Assist in the configuration and implementation of IAM systems and applications. Schedule and supervise periodic network security assessments across multiple platforms and/or distributed networks. Conduct vulnerability assessments to improve security standards and procedures within the organization that support strategic, tactical and operational objectives on a cost-effective basis. Conduct regular reviews on user access authorization, through working with other department such as Human Resource, Legal functions. Perform complex security resource and access rule maintenance; develop and implement security monitoring and violation reports that identify any attempt to access unauthorized materials. Develop guidelines and reports on the usage, control, maintenance and auditing of information and computer resources. Troubleshoot technical and operational problems about IAM system and access control processes. Provide security support in a distributed environment; participate in technical evaluations of enterprise security access control products.
- Details:
- • Develop password requirements and deploy to major systems and applications
- • Protect the transmission and storage of passwords, personal identification numbers (PINs), digital certificates, and other credentials using encryption
- • Develop standards and manage multi-factor authentication, including tokens and/or biometrics for systems that contain sensitive data
- • Ensure SSO and password synchronization systems meet organizational standards and baselines
- • Analyze, design, and implement a cohesive ecosystem that includes active directory, identity federation, multi-factor authentication, privileged access and identity management
- • Troubleshoot network connectivity issues as they pertain to authentication and authorization
- • Research evolving IAM techniques and tools in support of future IAM efforts
- • Stay current with information security program developments, industry frameworks, and changes in the bank that may impact the group
- • Review IAM production systems systematically for compliance with security policies and standards
- • Own and resolve application/solution issues
- • Contribute to teams’ continuous improvement by providing training and guidance of process to other team members
- • Prepare and disseminate reports, status, or help desk metrics
- • Supervise the employee/contractor standard enrollment process and confirm new account and access requests are correctly fulfilled via the UAR process
- • Review the UAR process regularly to confirm it is operating as designed. Identify areas of improvement and implement recommendations in conjunction with IAM analysts, engineers, and management
- • Manage certification campaigns and evaluate criteria leveraged within the process
- • Oversee periodic account re-certification activities by analysts
- • Make recommendations to improve the UAC process. Revise the process for certification to be compliant with changes to company policies
- • Develop user access/activity reports at the request of management to support access recertification, business unit, and regulatory requests
- • Work with system owners to create system accounts inventory database for recertification.
- • Identify the privileged accounts associated with each major system component or application
- • Manage the assignment of privileges to unique user IDs and remove shared privileged access by multiple users
- • Manage training/education of business users for the recertification processes
- • Update IAM-related process documentation to reflect current state of account enrollment processes
- • Provide system support for IAM products
- • Review IT tickets submitted by IAM administration analysts
• • Provide technical support to resolve issue or escalate to senior members of IAM if needed
Mitsubishi UFJ Financial Group (MUFG) is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organsational fit, regardless of race, religion or gender.

