Cyber Security Threat Modeler focusing on integrating effective threat modeling processes in MUFG's security risk management. Collaborating with technology teams to ensure robust security controls.
Responsibilities
Monitor information security issues related to MUFG systems and workflows to ensure internal security controls are appropriate and operating as intended
Manage threat modeling process to help our technology teams, control partners, and business stakeholders understand the state of our technology and data control suite, while working together to prioritize and remediate identified gaps
Generate security trend analyses and vulnerability reports
Utilize the MITRE ATT&CK framework to identify and mitigate threats effectively
Identify and implement controls to mitigate identified threats
Cross-train other teams on threat modeling techniques and best practices
Requirements
6+ years of experience in secure coding, application security, or similar disciplines
Knowledge of information security standards, rules and regulations related to information security and data confidentiality
Experience with performing Threat Modeling on web applications
Conducting research into real-world threat actor tactics, techniques, and procedures
Solid knowledge and understanding of development life cycle (SSDLC), CI/CD pipelines and Agile methodologies
Understanding of common software security issues and remediation techniques (OWASP Top 10, SANS 25, Mitre’s ATT&CK)
Excellent knowledge of Windows/AD/Linux systems administration and vulnerabilities
Experience in the banking or finance industries preferred
Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), or other security certifications desired
Experience working in a highly-regulated environment desired
Benefits
comprehensive health and wellness benefits
retirement plans
educational assistance and training programs
income replacement for qualified employees with disabilities
Lead Information Security Engineer focused on phishing mitigation in Cybersecurity at Wells Fargo. Engaging in threat detection and incident response across various teams.
Principal Engineer implementing generative AI for cybersecurity at Wells Fargo. Act as a strategic advisor to leadership while overseeing security and AI initiatives.
IT & Cybersecurity Manager leading IT infrastructure and cybersecurity efforts at knok. Ensuring secure, scalable systems to support the digital transformation of healthcare.
Security Systems Technician maintaining physical security technologies and supporting enterprise security operations. Ensuring system integrity and compliance through troubleshooting and vendor collaboration.
IT Security Expert creating and managing SIEM solutions to strengthen Europe's defence capabilities. Collaborating in a small elite team to solve significant security challenges rapidly.
Senior Manager in Regulatory Compliance ensuring effective risk management within the Information Security Group. Overseeing regulatory compliance and governance while leading automation efforts.
Information Security Engineer overseeing security tasks, ensuring implementation of security controls. Collaborating with legal and technical teams in a professional office environment.
Security Administrator managing security across cloud and on - premises environments at Homecare Homebase. Collaborating with teams for patient care systems security and compliance.
Principal Security Engineer shaping security strategy for enterprise IT systems and software products at RedCloud. Leading a team to ensure robust security practices for business growth.
Security Lead at Qargo overseeing security strategy and implementation for a cloud - native transport platform. Collaborating with engineering to ensure compliance and resiliency across Europe.