Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.Job Summary:
The Identity and Access Management (IAM) Linux Engineering role supports MUFG Bank’s governance, safety, and soundness objectives by maintaining secure, compliant Linux access controls. This engineering position helps ensure IAM Linux capabilities align with regulatory requirements, industry standards, internal policies, and established risk tolerances.
The ideal candidate has strong Linux engineering experience, can operate at an AVP level, and is interested in broadening their IAM skillset across Identity Governance and Administration (IGA), Microsoft Entra ID, and privileged access technologies. This role requires close collaboration with global security, business, and technology teams.
Responsibilities:
- Implement and maintain Centrify least-privilege access controls and role-based access models
- Automate operational and control processes using scripting
- Enforce IAM policies across Linux, Active Directory, and cloud-integrated environments
- Support Centrify upgrades, patching, troubleshooting, and disaster recovery activities
- Resolve escalations related to Active Directory bridging and Linux authentication issues
- Maintain clear documentation for Centrify processes, procedures, and operating standards
- Support audits and compliance reviews by providing accurate evidence and documentation
Required Skills:
- 5+ years of Linux system administration or engineering experience, including Name Service Switch (NSS), Pluggable Authentication Modules (PAM), and SUDO policy management
- 5+ years supporting Active Directory or cloud bridging solutions such as Centrify or CyberArk Endpoint Privilege Manager (EPM)
- 5+ years automating tasks with PowerShell, Python, Bash, or similar scripting languages
- Self-motivated and able to take ownership of assigned work, independently drive tasks to completion, identify gaps or risks, and proactively learn new Identity and Access Management (IAM) technologies with limited day-to-day direction
Desired Skills:
- Experience with Privileged Access Management (PAM) platforms such as CyberArk, CA ePAM, or similar tools
- Experience with Active Directory authentication, Kerberos, LDAP, and related security protocols
- Knowledge of IAM and PAM industry standards and best practices
- Experience integrating with cloud service providers such as AWS, Microsoft Azure, or Google Cloud Platform
- Experience managing Microsoft Entra ID capabilities such as Single Sign-On (SSO), Conditional Access, and Access Packages
- Experience operating in a financial services company
- Excellent verbal and written communication skills
Education:
- Bachelor’s degree in a related field or equivalent work experience
The typical base pay range for this role is as follows:
- New York / New Jersey: $134k - $168k
- Non-New York / New Jersey: $126k - $150k
depending on job-related knowledge, skills, experience, and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.
