368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$182k – $227k per year
Location
Remote/Hybrid (Scottsdale, Jersey City, United States)
Seniority
Architect · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Mitsubishi UFJ Financial Group (MUFG) is one of Japan's largest financial services holding companies and one of the premier global banking groups. The enterprise provides a broad range of services, including commercial banking, trust banking, securities, credit cards, and asset management to retail, corporate, and institutional clients.

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

The Global Director of Autonomous Cyber Defense and Security Event Triage leads the strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function. This role is accountable for globally protecting enterprise assets and services by driving outcomes across detection engineering, automated response, incident triage, and threat hunting. The director oversees global cyber operations performance, operating rhythms, and service delivery across multiple environments and partners, while owning budget planning and financial stewardship for the function. Additionally, the role advances autonomous defense capabilities by applying AI/ML and LLM-enabled workflows to improve alert quality, reduce time to detect/respond, and standardize decisioning, documentation, and remediation at scale. The director also ensures continuous validation of controls and detections through purple team execution aligned to adversary behaviors.

Major Responsibilities

  • Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments
  • Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage (e.g., MTTD/MTTR, false-positive reduction, containment SLAs)
  • Work with the Global Head to define the vision for Autonomous Cyber Defense and Security Event Triage, and execute against that vision in alignment with the strategic design
  • Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance
  • Lead, mentor, and scale high-performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on-call expectations
  • Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution
  • Provide executive-level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements
  • Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions
  • Drive AI/ML/LLM-enabled autonomous defense initiatives, including alert enrichment, case summarization, analyst co-pilots, automated containment, and continuous learning to improve signal-to-noise
  • Establish governance for detection engineering, triage decisioning, playbooks, and automation (SOAR/EDR/SIEM) to standardize response, reduce gaps, and improve response times
  • Lead critical incident triage and escalation governance; partner with incident response, infrastructure, identity, and application teams to coordinate containment and recovery
  • Oversee monitoring of third-party security service providers and managed tooling to ensure coverage, quality, and alignment to enterprise standards and SLAs
  • Build an operations analytics program to measure and continuously improve triage accuracy, response efficiency, backlog health, and automation effectiveness across regions and shifts
  • Sponsor and execute a purple team program (red/blue collaboration) to validate detections and response through adversary emulation aligned to MITRE ATT&CK; track gaps to closure
  • Oversee proactive threat hunting and continuous control validation to identify adversary behaviors, reduce dwell time, and harden critical services
  • Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones
  • Integrate threat intelligence, vulnerability insights, and attacker TTP research into detection logic, triage guidance, and autonomous response workflows
  • Produce and govern recurring and ad-hoc reporting on threats, trends, and program performance; ensure consistent narratives and decision support for stakeholders
  • Champion innovation and modernization of cyber defense tooling and techniques, including evaluation and adoption of new capabilities that measurably reduce risk
  • Partner with technology, product, and business leaders to align cyber operations priorities, drive remediation ownership, and embed security-by-design practices

Qualifications

  • Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience
  • 7+ years of experience working in the Cybersecurity Operations or Information Security
  • Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred
  • Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics preferred
  • Experience with information security risk management, including information security audits, reviews, and risk assessments

Desired Skills

  • Experience with security data collection, analysis and correlation
  • Well-developed analytic, qualitative, and quantitative reasoning skills
  • Demonstrated creative problem-solving abilities
  • Security event monitoring, investigation, and overall incident response process
  • Strong time management skills to balance multiple activities and lead junior analysts as needed
  • Understanding of offensive security to include common attack methods
  • Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event
  • A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures.
  • Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.)
  • Ability to guide and mentor junior analysts in investigations
  • Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tools, etc.)
  • Experienced with Endpoint Detection & Response, email security, web application firewall, and cloud security tooling.
  • Ability to perform risk analysis utilizing logs and other information compiled from various sources
  • Understanding of network protocols, operating systems (Windows, Unix, Linux, MacOS, databases), and mobile device security
  • Knowledge of the various types of cyber-attacks and their implementations
  • A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Ability to document and explain technical details in a concise, understandable manner
  • Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.
  • Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, and ELK
  • Scripting/programming experience preferred

Education

  • Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience

Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.”

The typical base pay range for this role is as follows:

  • New York / New Jersey: $182k-227k
  • Non-New York / New Jersey: $203k-249k

depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.

Our hybrid work schedule is four days on-site and work remotely one day per week.

MUFG Benefits Summary

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Scottsdale
Full Stack Engineer 10 hours ago
$47k – $102k per year (Estimated) • In office • Full-Time • 15+ years exp • Bachelor's Degree • Hyderabad • Gurgaon
Java
Java
Spring Boot
Databases
Apache Kafka
Azure Cosmos DB
PostgreSQL
Redis
AI/ML
AI Agents
LLM
OpenAI
RAG
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Kubernetes
Platform Engineering
Apply
LLM Model Developer 3 hours ago
$28k – $77k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
AI/ML
AI Agents
Fine-tuning
LLM
Apply
$47k – $106k per year (Estimated) • In office • Full-Time • Moscow
Python
SQL
Python
pySpark
AI/ML
LangChain
LangGraph
LLM
RAG
Spark
Apply
$7k – $21k per year • Remote • Contractor • Yekaterinburg
Python
AI/ML
ChatGPT
Claude
LLM
Midjourney
Management
n8n
Zapier
Apply
$36k per year (gross) • In office • Full-Time • 3+ years exp • Moscow
Python
SQL
Python
SQLAlchemy
Databases
MongoDB
PostgreSQL
AI/ML
LLM
Mobile
PWA
DevOps
CI/CD
Docker
Gitflow
Jenkins
kubectl
Git
Kubernetes
Management
Confluence
Jira
QA
Pytest
Apply
In office • Full-Time • 5+ years exp • Seoul
SQL
Visual Basic
C#
C#
.NET
Apply
$118k – $252k per year (Estimated) • In office • Full-Time • 8+ years exp • Singapore
Python
SQL
Analytics
Power BI
Tableau
Apply
$40k – $91k per year (Estimated) • In office • Full-Time • 1+ year exp • Singapore
Python
AI/ML
Copilot
Prompt Engineering
Apply
$94k – $158k per year • Remote • Full-Time • 1+ year exp • Bachelor's Degree • New York
Management
ServiceNow
Apply
$90k – $153k per year • Remote/Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Jersey City
Bash
JavaScript
PowerShell
Python
AI/ML
LLM
LLM Guardrails
Red Teaming
Function Calling
Cybersecurity
MITRE ATT&CK
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$92k – $186k per year (Estimated) • In office • 7+ years exp • Scottsdale
AI/ML
AI Agents
Copilot
LLM
Model Context Protocol
DevOps
Azure
Azure DevOps
Analytics
Power BI
Management
Power Apps
Power Automate
Marketing
Salesforce
Apply
$174k – $330k per year (Estimated) • Equity • In office • Contractor • Scottsdale
AI/ML
Agentforce
LLM
DevOps
AWS
Azure
Incident Management
Marketing
Salesforce
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.